PDA

View Full Version : possible hacker??



Ext User(Kathy)
03-06-2007, 07:33 AM
when my system is booting up I'm getting my dos window C:\windows\webmsns.exc
with the following messages displayed:
DCOM disabled
FAILED TO START AV/FW KILLER THREAD ERROR
FAILED TO DELETE IPC $ SHARE
NETWORK SHARE DELETED
CONNECTED TO 207.21.218.159
JOINED CHANNEL #ROSE
SERVER STARTED on PORT 16213

Do the above messages indicate someone hacking into my computer? I've got
the Spywares/Firewalls etc loaded onto my system, how would that happen?

Thank you for your assistance

Kathy

Ext User(C A Upsdell)
03-06-2007, 07:33 AM
Kathy wrote:
> when my system is booting up I'm getting my dos window C:\windows\webmsns.exc
> with the following messages displayed:
> DCOM disabled
> FAILED TO START AV/FW KILLER THREAD ERROR
> FAILED TO DELETE IPC $ SHARE
> NETWORK SHARE DELETED
> CONNECTED TO 207.21.218.159
> JOINED CHANNEL #ROSE
> SERVER STARTED on PORT 16213
>
> Do the above messages indicate someone hacking into my computer? I've got
> the Spywares/Firewalls etc loaded onto my system, how would that happen?
>

Reverse DNS says 207.21.218.159 is InterLand, now Web.com, an IPP.

Ext User(nass)
03-06-2007, 07:33 AM
"Kathy" wrote:

> when my system is booting up I'm getting my dos window C:\windows\webmsns.exc
> with the following messages displayed:
> DCOM disabled
> FAILED TO START AV/FW KILLER THREAD ERROR
> FAILED TO DELETE IPC $ SHARE
> NETWORK SHARE DELETED
> CONNECTED TO 207.21.218.159
> JOINED CHANNEL #ROSE
> SERVER STARTED on PORT 16213
>
> Do the above messages indicate someone hacking into my computer? I've got
> the Spywares/Firewalls etc loaded onto my system, how would that happen?
>
> Thank you for your assistance
>
> Kathy

http://www.bleepingcomputer.com/forums/lofiversion/index.php/t26411.html

Your machine used as a "Zombie" and infected with Viruses that can remote
control your machine and send spam to other or spy on your Surfing habbits on
this machine, try to scan from the following links and try the
HijackThis forums.
Run a scan from here on-line:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner from here:
http://www.avast.com/eng/avast-virus-cleaner.html
Lots of tools to download and disinfect your machine:
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/
For Malware download both these software:
http://www.lavasoft.com/products/ad-aware_se_personal.php
http://www.safer-networking.org ; for Spybot S&D

Then Download the Hijackthis and send the report to one of
many
forums for analysis and troubleshooting:
When all else fails, HijackThis v1.99.1
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. Post
your log to http://aumha.net/viewforum.php?f=30,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7, or other appropriate
forums for expert analysis, not here.
HTH.
Let us know.
Regards,
nass
----------
www.nasstec.co.uk

Hosted by: Eyo Technologies Pty Ltd. Sponsored by: Actiontec Pty Ltd