keep getting hacked-help?

blade2

Member
Jun 28, 2002
191
0
0
ok the title is a bit exaggerative but ive had 3 attempts to hack my comp in 2 days, luckily and the only reason i know is because of Norton Firewall thing which i just recently started using.
anyway, 2 of 3 attempts was the trojan "Sub-Seven" whose client software or something must be installed on my comp so i am need of advice or a proggie to check in i am infected with subseven?someone?
 

EagleKeeper

Discussion Club Moderator<br>Elite Member
Staff member
Oct 30, 2000
42,589
5
0
IF you install ZoneAlarm, it will tell you who is trying to get out from your system.
 

aircooled

Lifer
Oct 10, 2000
15,965
1
0
Update your virus definitions and run a full system scan. Then download and run this. It's called trojan remover, it specifically targets known trojans.

Then I would run AdAware just to rule out and elimate ad related spyware.

Thats my recommendation....


edit: as EagleKeeper mentioned, zonealarm will let you block any outgoing communications. I'm sure your Norton personal firewall has the same ability. Your goal should be to elimate the trojan that is attempting the outbound communication. Most any updated virus definition or trojan scanner should cure this for you.



 

Codewiz

Diamond Member
Jan 23, 2002
5,758
0
76
People just randomly scan people for subseven. It doesn't mean you are infected. You will see MANY attacks all day log. When I look at my router log, I see people trying all day long to try and get in on ports that of course closed.
 

Strwois

Junior Member
Oct 6, 2002
12
0
0
download sub7 see how it works, hell you can even scan your own IP and see if you have it. youll be fine as long as you dont click ont eh server.exe or whatever. it is most likely a scan.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Its a sweep of whichever port sub7 sits on (forget the exact one offhand 31337 is BO2k I think...). Children sit on the net scanning large networks on specific ports (0day of the week) to see what is listening. Its nothing to worry about. Personally, I would be worried if your firewall was not telling you someone attempted something.
 

Staver

Senior member
Oct 10, 1999
909
0
76
You aren't infected with SubSeven (TCP 27XXX), since if you were the first thing they'd do is disable your firewall. To be honest, three probes in two days isn't bad at all.
 

PowerMacG5

Diamond Member
Apr 14, 2002
7,701
0
0
blade2, I have NPF installed also. It will turn on an alert whenever someone unauthorized scans your ports. Don't worry about 3 times in 2 days. It doesn't mean your infected. According to Gibsons Research Sheilds Up test, my computer is fully stealthed, and all that I am using is NPF, without any hardware firewall. Full Stealth means that although your computer is connected to the internet, nobody can tell because the computer will not allow another unauthorized person to see your computer across the internet.
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
Full Stealth means that although your computer is connected to the internet, nobody can tell because the computer will not allow another unauthorized person to see your computer across the internet.

That statement is completely untrue; propagation of such disinformation is typical of GRC.

I guess from an end-user standpoint, it doesn't really matter whether or not his information is technically accurate...
 

blade2

Member
Jun 28, 2002
191
0
0
hey thanks for the advice guys,i'll download that trojan remover just to be safe, already done the full virus scan and ad-aware. now i wont be panickin when i get that little message at the side of my screen blabberin about being hacked.

damn b@stard kids!! no wait, i tried BO2K once-was gonna install it on my friend comp without him knowing and randomly shut it down heh! but then i decided way too dodgy!!

been cruising the net for about 4 years and never used a firewall until now :Q , im not even gonna think how many attempted attacks on my comp during that period!

oh yeah, Norton Firewall tells me the IP of the "hacker" , ive tried using an IP scanner to attempt to find out who the ISP is but my results have been fruitless; should i email my ISP with the IP of the hacker or is it just pointless??

anyway Norton Firewall and the Internet Security package is great in general!

thanks again all!
 

bozo1

Diamond Member
May 21, 2001
6,364
0
0
Often times it is not really a 'hacker'. It's just someone else on the net that is infected and their infection is searching for other machines to infect. They aren't doing it intentionally and are unaware of it.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
i tried BO2K once-was gonna install it on my friend comp without him knowing and randomly shut it down

Yea, nothing is more funny than comitting a felony... ;)

anyway Norton Firewall and the Internet Security package is great in general!

Thanks :)

Bill

edit: Smiley added
 

blade2

Member
Jun 28, 2002
191
0
0
Originally posted by: bsobel
i tried BO2K once-was gonna install it on my friend comp without him knowing and randomly shut it down

Yea, nothing is more funny that comitting a felony...

Bill

what the hecks a felony?:confused: :confused: :confused:

is it like the american version of breaking the law here in the UK??? why didnt u just say that...gee people nowadays
rolleye.gif



:)
 

LeStEr

Diamond Member
Dec 28, 1999
3,412
0
0
Sub7 is a b|itch if you ever get infected with it. My friends installed it on me twice thinking it was some sort of a joke back in the day, Not knowing that others could get in aswell as themselves (idiots). Anyways both times resulted in a format as no tools would remove it properly.