PDA

View Full Version : I need help with some intrusion attempts...



Nzdjh
2007-02-20, 21:40
(Before I say anything, I apologize if this is in the wrong forum... I tried to figure out which one it fit best into, and I think this is the right place to post it)

Alright, so a few days ago my computer had some spyware on it (RelevantKnowledge, to be exact). But thankfully I found it before it got out of hand and deleted it (as far as I know). That event caused me to go on a security overhaul and get all kinds of programs to help protect me, such as Spyware Blaster, Spy Sweeper, WinPatrol, and a new HOSTS file, which I all got from this (http://mvps.org/winhelp2002/) site.

For the last couple days everything has seemed fine. But about an hour ago (around 2:30 or so), I got an intrusion attempt alert from Norton Anti-Virus. It was blocked, and I didn't really get too hyped up about it. The risk level was high, however, so that put me a little on-edge. So I said OK. A minute later, another intrusion attempt, by the same intruder. Okay, fine. Then maybe 5 minutes later, another intrusion attempt, this time by something different. Then another, by a third intruder. So now I have three intruders trying to access my computer, and Norton keeps blocking them, thankfully. So now, about an hour later, I'm getting an intrusion attempt alert about once every couple seconds, from three different things accessing my internet. It's getting sickening. I don't know what to do. They haven't been able to get in, but at this rate, it seems like they'll just keep trying and trying and trying till they do. I'm getting sick of these constant pop-ups from Norton telling me it blocked an intrusion attempt. I want to tell it to stop alerting me every time it blocks an intrusion attempt from those three, but then that'd make me feel as if I don't know what's going on, and on the off chance they do gain access, then I'd be screwed because I wouldn't know about it. I want to just stop the attempts altogether. I tried deleting all my cookies, cache, history, etc. but none of it worked. I just tried changing my IP address but that didn't work either. Right now I'm doing a disk cleanup to try and delete any cookies that might be left on my harddrive that's allowing them to get in. I'm starting to get nervous, and I need all the help I can get.

Here's the info on all three of the intruders:

Intrusion: QuickSearch DNS Request
Intruder: HOME-HP (192.168.1.100) (1360)
Risk Level: Medium
Protocol: UDP
Attacked IP: 68.87.71.226
Attacked Port: domain(53)

Intrusion: ISearch DNS Request
Intruder: HOME-HP (192.168.1.100) (1505)
Risk Level: High
Protocol: UDP
Attacked IP: 68.87.71.226
Attacked Port: domain(53)

(^ That was the original intruder who first tried to access my computer... he's the one who worries me)

Intrusion: Goidr DNS Request
Intruder: HOME-HP(192.168.1.100) (1683)
Risk Level: Medium
Protocol: UDP
Attacked IP: 68.87.71.226
Attacked Port: domain(53)


Please, I need help. Try to reply to this message as soon as you possibly can. I need to find out how to stop these intrusion attempts. Even if they aren't really accessing my computer, I at least want to stop them. It makes me feel unsafe. I don't know why they keep trying. They're persistent as all heck, trying to get in every couple seconds. It really is getting annoying. I'm about to shut off my computer altogether, just to stop it. Eventually they'll have to give up... but then again, maybe not, as it could be just a program made to keep trying until it does access the victim's computer. In that case they'll never stop until I do something about it. Like I said, I could tell Norton to just shut up and block them without constantly bugging me and alerting me about it, but then I'd feel completely in the dark. I don't know what to do. I don't even know how it happened. My guess is from that spyware I had on my computer the other day. But I don't know. Any help would be greatly appreciated.

shelf life
2007-02-21, 12:32
hi Nzdjh,


those are originating from inside your computer, they arent external. some application on your computer is doing a DNS lookup, i would say you still have malware on your computer.

look in your add/remove programs panel for anything like isearch or any toolbar or "search helper" and uninstall it.

you can also post a hjt log if you want. like this:

* Downloads:
* Please make sure you have the latest version. HJT 1.99.1
* http://www.downloads.subratam.org/hijackthis.zip
* If you are unfamiliar with zip programs get HijackThis.exe here:
* http://www.merijn.org/files/HijackThis.exe

* First put hijackthis into a permanent folder.
* Do this first - go to C: and create a new permanent folder.
Example C:\AntiSpyWare or C:\hijackthis
* This is necessary to ensure you have backups should anything go wrong.
* Then put (or download - choose "save" not "run") the hijackthis.exe file in this folder.
If you downloaded a zipped HJT file unzip it to the permanent folder so you have C:\hijackthis\hijackthis.exe.
* Example of the wrong way:
C:\DOCUME~1\Name\LOCALS~1\Temp\Temporary Directory for hijackthis.zip\HijackThis.exe
* Running hjt from the wrong folder may delay assistance as your helper will have to ask for a new log.

If in doubt use this link to get HijackThis.
Save it to your desktop and then double-click to run it.
It will install the program in c:\program files\HijackThis.

* Double click HijackThis.exe.
* Hit None Of The Above, just start the program.
* Hit Scan.
* When the scan is finished, the "Scan" button will change into a "Save Log" button.
* Click that, save the log somewhere, and copy/paste the log back here.


all kinds of programs to help protect me
the best protection is knowing how malware gets on your computer, know this and you will be protected

tashi
2007-02-28, 07:21
This topic is closed due to lack of a response to helper,:spider: if you need it re-opened please send me a private message (pm) and provide a link to the thread.

Applies only to the original poster, anyone else with similar problems please start a new topic.