Results 1 to 9 of 9

Thread: Hacker or Stupid Computer?

  1. #1
    Marmoset Warrior
    Join Date
    Feb 2004
    Location
    Hastings
    Posts
    1,390
    Thanks
    3
    Thanked
    0 times in 0 posts

    Hacker or Stupid Computer?

    Just now, i was happily talking to my friends on MSN when my firewall crashed (which i have never know it to do) it told me it had had a runtime error in C++. Now im running the pro version of Zonealarm and its been pretty good to me. I looked into the logs after the said crash and all the the logs have gone, every single one. The logs are completley empty. usually they are filled with port blocking stuff.
    When i ran Netstat it had extra connections to ips i've never seen (i could see the ones going to msn, i wasnt on hexus or any other web page and i had a netbios session which is my network (i presume as its always there)
    Did I get hacked or am I being paranoid?

  2. #2
    Senior Member
    Join Date
    Jul 2003
    Location
    3rd Rock from the sun..
    Posts
    463
    Thanks
    15
    Thanked
    4 times in 3 posts
    • Dave_07's system
      • Motherboard:
      • MSI X99A Gaming 7
      • CPU:
      • Intel Core i7 5930k (6 core) @ 4.3Ghz
      • Memory:
      • 16Gb Corsair DDR4 2800Mhz
      • Storage:
      • 2x 500Gb SSD's (Raid 0)
      • Graphics card(s):
      • 2x SLI MSI GTX 980
      • PSU:
      • EVGA 1000w PSU
      • Case:
      • Corsair C70
      • Operating System:
      • Windows 7 Pro 64Bit
      • Monitor(s):
      • G-Sync AOC G2460PG 1080p and LG Flatron W2261VP
      • Internet:
      • 17.5Mb Broadband.
    ZA seems to have a break in it's armour somwhere, as people (i've noticed) have found a way to crash the Vsmon to weaken it and then bash away at you directly.
    peeps can use/go through MSN to can get ya ip and so then attack.

    Zone Labs won't admit theres a prob tho, or they don't know about it.
    The logs going bye bye, is classic of what ever it is they are doing to ZA.
    Intel Core i7 5930k @ 3.7Ghz Turbo
    MSI X99A Gaming 7
    16Gb Corsair DDR4 2667Mhz
    2x SLI MSI GTX 980
    2x 500Gb SSD's (Raid 0)
    EVGA 1000w PSU
    Windows 7 Pro 64Bit
    G-Sync AOC G2460PG 1080p
    LG Flatron W2261VP

  3. #3
    Sublime HEXUS.net
    Join Date
    Jul 2003
    Location
    The Void.. Floating
    Posts
    11,819
    Thanks
    213
    Thanked
    233 times in 160 posts
    • Stoo's system
      • Motherboard:
      • Mac Pro
      • CPU:
      • 2*Xeon 5450 @ 2.8GHz, 12MB Cache
      • Memory:
      • 32GB 1600MHz FBDIMM
      • Storage:
      • ~ 2.5TB + 4TB external array
      • Graphics card(s):
      • ATI Radeon HD 4870
      • Case:
      • Mac Pro
      • Operating System:
      • OS X 10.7
      • Monitor(s):
      • 24" Samsung 244T Black
      • Internet:
      • Zen Max Pro
    I binned ZA long ago and went with a hardware firewall..
    (\__/)
    (='.'=)
    (")_(")

  4. #4
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    What's your version of ZA Pro?
    Latest is 5.0.590.043.

    And all the logs in "C:\WINDOWS\Internet Logs" are gone?
    Did you get any message about a corrupt .RDB file at any point? (Or checked in your event log?)

    Might be worth trying to get hold of a freeware undeletion tool to see if the last log could be recovered, if they are indeed gone.

    What were the ports in question that you saw open using netstat?
    That should give a clue as to the direction and nature of the connections...
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  5. #5
    Sublime HEXUS.net
    Join Date
    Jul 2003
    Location
    The Void.. Floating
    Posts
    11,819
    Thanks
    213
    Thanked
    233 times in 160 posts
    • Stoo's system
      • Motherboard:
      • Mac Pro
      • CPU:
      • 2*Xeon 5450 @ 2.8GHz, 12MB Cache
      • Memory:
      • 32GB 1600MHz FBDIMM
      • Storage:
      • ~ 2.5TB + 4TB external array
      • Graphics card(s):
      • ATI Radeon HD 4870
      • Case:
      • Mac Pro
      • Operating System:
      • OS X 10.7
      • Monitor(s):
      • 24" Samsung 244T Black
      • Internet:
      • Zen Max Pro
    there's a netstat -b option which will list the application which opened the port too..
    (\__/)
    (='.'=)
    (")_(")

  6. #6
    Sublime HEXUS.net
    Join Date
    Jul 2003
    Location
    The Void.. Floating
    Posts
    11,819
    Thanks
    213
    Thanked
    233 times in 160 posts
    • Stoo's system
      • Motherboard:
      • Mac Pro
      • CPU:
      • 2*Xeon 5450 @ 2.8GHz, 12MB Cache
      • Memory:
      • 32GB 1600MHz FBDIMM
      • Storage:
      • ~ 2.5TB + 4TB external array
      • Graphics card(s):
      • ATI Radeon HD 4870
      • Case:
      • Mac Pro
      • Operating System:
      • OS X 10.7
      • Monitor(s):
      • 24" Samsung 244T Black
      • Internet:
      • Zen Max Pro
    just did that on this system..

    Code:
    C:\Documents and Settings\Stoo>netstat -a -b
    
    Active Connections
    
      Proto  Local Address          Foreign Address        State           PID
      TCP    tangent:smtp           tangent:0              LISTENING       3324
      [adr.exe]
    
      TCP    tangent:http           tangent:0              LISTENING       1524
      [Apache.exe]
    
      TCP    tangent:http           tangent:0              LISTENING       1348
      [Apache.exe]
    
      TCP    tangent:epmap          tangent:0              LISTENING       892
      c:\windows\system32\WS2_32.dll
      C:\WINDOWS\system32\RPCRT4.dll
      c:\windows\system32\rpcss.dll
      C:\WINDOWS\system32\svchost.exe
      -- unknown component(s) --
      [svchost.exe]
    
      TCP    tangent:microsoft-ds   tangent:0              LISTENING       4
      [System]
    
      TCP    tangent:3280           tangent:0              LISTENING       1544
      [DUService.exe]
    
      TCP    tangent:3306           tangent:0              LISTENING       1840
      [mysqld-nt.exe]
    
      TCP    tangent:4002           tangent:0              LISTENING       1484
      [DCPFLICS.exe]
    
      TCP    tangent:4222           tangent:0              LISTENING       456
      [sfmgr.exe]
    
      TCP    tangent:5679           tangent:0              LISTENING       3188
      [WCESCOMM.EXE]
    
      TCP    tangent:40019          tangent:0              LISTENING       1544
      [DUService.exe]
    
      TCP    tangent:1029           tangent:0              LISTENING       2588
      [alg.exe]
    
      TCP    tangent:31595          tangent:0              LISTENING       3240
      [WebProxy.exe]
    
      TCP    tangent:netbios-ssn    tangent:0              LISTENING       4
      [System]
    
      TCP    tangent:1979           localhost:1980         ESTABLISHED     2124
      [firefox.exe]
    
      TCP    tangent:1980           localhost:1979         ESTABLISHED     2124
      [firefox.exe]
    
      TCP    tangent:2492           baym-cs153.msgr.hotmail.com:1863  ESTABLISHED
      3360
      [msnmsgr.exe]
    
      TCP    tangent:2834           localhost:http         CLOSE_WAIT      3360
      [msnmsgr.exe]
    
      TCP    tangent:3467           deepthought.34sp.com:http  TIME_WAIT       0
      UDP    tangent:isakmp         *:*                                    636
      [lsass.exe]
    
      UDP    tangent:1326           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:1175           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:4500           *:*                                    636
      [lsass.exe]
    
      UDP    tangent:1327           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:2498           *:*                                    3360
      [msnmsgr.exe]
    
      UDP    tangent:2988           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:1317           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:1025           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:4333           *:*                                    456
      [sfmgr.exe]
    
      UDP    tangent:1026           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:microsoft-ds   *:*                                    4
      [System]
    
      UDP    tangent:1328           *:*                                    1004
      C:\WINDOWS\system32\mswsock.dll
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\DNSAPI.dll
      c:\windows\system32\dnsrslvr.dll
      C:\WINDOWS\system32\RPCRT4.dll
      [svchost.exe]
    
      UDP    tangent:18001          *:*                                    3240
      [WebProxy.exe]
    
      UDP    tangent:ntp            *:*                                    968
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\w32time.dll
      ntdll.dll
      C:\WINDOWS\system32\kernel32.dll
      [svchost.exe]
    
      UDP    tangent:1900           *:*                                    1068
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\ssdpsrv.dll
      C:\WINDOWS\system32\ADVAPI32.dll
      C:\WINDOWS\system32\kernel32.dll
      [svchost.exe]
    
      UDP    tangent:1255           *:*                                    3360
      [msnmsgr.exe]
    
      UDP    tangent:1900           *:*                                    1068
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\ssdpsrv.dll
      C:\WINDOWS\system32\ADVAPI32.dll
      C:\WINDOWS\system32\kernel32.dll
      [svchost.exe]
    
      UDP    tangent:netbios-dgm    *:*                                    4
      [System]
    
      UDP    tangent:netbios-ns     *:*                                    4
      [System]
    
      UDP    tangent:discard        *:*                                    3360
      [msnmsgr.exe]
    
      UDP    tangent:16265          *:*                                    3360
      [msnmsgr.exe]
    
      UDP    tangent:ntp            *:*                                    968
      c:\windows\system32\WS2_32.dll
      c:\windows\system32\w32time.dll
      ntdll.dll
      C:\WINDOWS\system32\kernel32.dll
      [svchost.exe]
    waaah! that's a lot of junk lol
    (\__/)
    (='.'=)
    (")_(")

  7. #7
    Senior Member
    Join Date
    Jul 2003
    Location
    3rd Rock from the sun..
    Posts
    463
    Thanks
    15
    Thanked
    4 times in 3 posts
    • Dave_07's system
      • Motherboard:
      • MSI X99A Gaming 7
      • CPU:
      • Intel Core i7 5930k (6 core) @ 4.3Ghz
      • Memory:
      • 16Gb Corsair DDR4 2800Mhz
      • Storage:
      • 2x 500Gb SSD's (Raid 0)
      • Graphics card(s):
      • 2x SLI MSI GTX 980
      • PSU:
      • EVGA 1000w PSU
      • Case:
      • Corsair C70
      • Operating System:
      • Windows 7 Pro 64Bit
      • Monitor(s):
      • G-Sync AOC G2460PG 1080p and LG Flatron W2261VP
      • Internet:
      • 17.5Mb Broadband.
    netstat ? Freeware proggy, or run command ?
    Intel Core i7 5930k @ 3.7Ghz Turbo
    MSI X99A Gaming 7
    16Gb Corsair DDR4 2667Mhz
    2x SLI MSI GTX 980
    2x 500Gb SSD's (Raid 0)
    EVGA 1000w PSU
    Windows 7 Pro 64Bit
    G-Sync AOC G2460PG 1080p
    LG Flatron W2261VP

  8. #8
    Sublime HEXUS.net
    Join Date
    Jul 2003
    Location
    The Void.. Floating
    Posts
    11,819
    Thanks
    213
    Thanked
    233 times in 160 posts
    • Stoo's system
      • Motherboard:
      • Mac Pro
      • CPU:
      • 2*Xeon 5450 @ 2.8GHz, 12MB Cache
      • Memory:
      • 32GB 1600MHz FBDIMM
      • Storage:
      • ~ 2.5TB + 4TB external array
      • Graphics card(s):
      • ATI Radeon HD 4870
      • Case:
      • Mac Pro
      • Operating System:
      • OS X 10.7
      • Monitor(s):
      • 24" Samsung 244T Black
      • Internet:
      • Zen Max Pro
    run command
    (\__/)
    (='.'=)
    (")_(")

  9. #9
    Senior Member
    Join Date
    Jul 2003
    Location
    3rd Rock from the sun..
    Posts
    463
    Thanks
    15
    Thanked
    4 times in 3 posts
    • Dave_07's system
      • Motherboard:
      • MSI X99A Gaming 7
      • CPU:
      • Intel Core i7 5930k (6 core) @ 4.3Ghz
      • Memory:
      • 16Gb Corsair DDR4 2800Mhz
      • Storage:
      • 2x 500Gb SSD's (Raid 0)
      • Graphics card(s):
      • 2x SLI MSI GTX 980
      • PSU:
      • EVGA 1000w PSU
      • Case:
      • Corsair C70
      • Operating System:
      • Windows 7 Pro 64Bit
      • Monitor(s):
      • G-Sync AOC G2460PG 1080p and LG Flatron W2261VP
      • Internet:
      • 17.5Mb Broadband.
    lol there's also a freeware proggy Googled.. :-)
    Intel Core i7 5930k @ 3.7Ghz Turbo
    MSI X99A Gaming 7
    16Gb Corsair DDR4 2667Mhz
    2x SLI MSI GTX 980
    2x 500Gb SSD's (Raid 0)
    EVGA 1000w PSU
    Windows 7 Pro 64Bit
    G-Sync AOC G2460PG 1080p
    LG Flatron W2261VP

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Mysterious noise coming from computer
    By Lunacy in forum PC Hardware and Components
    Replies: 8
    Last Post: 30-08-2007, 06:56 PM
  2. urgent problem with new computer
    By ives in forum PC Hardware and Components
    Replies: 23
    Last Post: 28-06-2004, 01:48 PM
  3. Building a computer
    By Rexoar in forum PC Hardware and Components
    Replies: 15
    Last Post: 04-02-2004, 04:56 PM
  4. stupid computer...
    By streetster in forum Software
    Replies: 0
    Last Post: 02-12-2003, 04:57 PM
  5. My Spooky computer...
    By paradidle in forum PC Hardware and Components
    Replies: 6
    Last Post: 09-11-2003, 08:04 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •