Re: Hacker?

From: Brian Pugh (brianjp2472@cablelynx.com)
Date: 07/31/02


From: "Brian Pugh" <brianjp2472@cablelynx.com>
Date: Wed, 31 Jul 2002 11:54:25 -0500


There are several things you can try.

Go to RUN and type SFC /SCANNOW and have your XP disk ready.
That will take care of any corrupted DLL's.

You can also hold down F5 at boot to bring up the start up menu, and choose
"last known good configuration", which will restore a previous copy of the
registry. The System Restore tool in Windows also does the exact same thing.
Typing drwatson from RUN might also help.

Aside from software or hardware, if you think a hacker might be involved,
get you a 3rd party firewall , such as Sygate Personal Firewall Pro 5. The
software can perform traces which can possibly pinpoint the source of the
traffic. The Windows XP firewall also does a pretty good job of closing
uneccassary ports while connected, but cannot perform a trace. You also have
to enable it for it to work.

If you want to see all the TCP/IP connections open while connected, type
NETSTAT from a command prompt. It will show you all inbound and outbound
TCP/IP connections on your computer, along with the names of the addresses.

Brian
A+

"John Duchowski" <jduchows@optonline.net> wrote in message
news:MuI19.65185$qn5.2580130@news4.srv.hcvlny.cv.net...
> Hello,
>
> Here's a rather curious problem that I encountered yesterday that I've
> never encountered before (I've been using MS Windows since 2.0): my
computer
> 'refused' to recognize me. When it came out of stand-by mode, I tried to
> type in the password and noticed that with S always two characters came
out.
> Even when I deleted the second character manually, the computer would NOT
> recognize the password. I tried this several times, always with the same
> result. I am running XPPro with NTFS on a Gateway 700XL. I then did a warm
> reboot... AND it asked me whether I really want to shut down because there
> are OTHER people logged on. I have NO other accounts on this machine, just
> me, the Admin. I got exactly the same error after I rebooted. I then did a
> cold reboot and again the SAME thing. Just the double S thing this time,
no
> mention of others being logged in. I then shut down and turned power off
and
> waited the whole night. This morning everything worked like a charm. I
went
> to Network Neighborhood and turned off 'File and Printer Sharing for MS
> Networks'. I did not find any viruses either. Could this have been a
hacker
> who took a temporary control over my machine? If so, how can I track this
> down?
>
> Then today, when I booted up, the CPU was showing 100% activity (this
is
> a 2.54 GHz PIV with 1 gig of RAM!) and the machine was running painfully
> slow, even after I disconnected the modem and was running it as a
> standalone. Then finally it settled down. The only other thing that comes
to
> mind is the incessant heat. After I ran the A/C unit for a while, the poor
> thing finally calmed down. Any other suggestions or ideas? Thanks :-) !
>
> Concerned,
> John
>
>



Relevant Pages

  • Re: Problem with Windows? or software?
    ... The computer does not reboot; in fact, ... Also, everytime i reboot my computer, the firewall turns itself ... How do you know the Windows Firewall is getting shutoff? ... >> I assume that this is a virus because it also shuts down my Windows ...
    (microsoft.public.windowsxp.general)
  • Re: Internet gateway
    ... >>deter big enterprises or, for that matter, ordinary end users off windows. ... > do, is reboot. ... My firewall never gets rebooted, ... any extra security to such 'commonly configured' machines except to give ...
    (comp.os.linux.networking)
  • CANNOT ENABLE SP2 FIREWALL
    ... The windows xp firewall isn't active. ... Follow prompts and reboot. ... Check to see if the Internet Connection Firewall is not disabled: ...
    (microsoft.public.windowsxp.security_admin)
  • RE: CANNOT ENABLE SP2 FIREWALL
    ... The windows xp firewall isn't active. ... > Follow prompts and reboot. ... If you under the registry key ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Connection problems using TCP/IP sockets under Vista
    ... It has been fully tested under Windows XP, ... I've developed a server application that receives TCP/IP connections ... but under Windows Vista this TCP/IP ...
    (microsoft.public.win32.programmer.networks)