I am suspicious that someone is still trying to access my computer. The person doing this is known to me but I don't know how to stop it.
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.Unloicited Connection to Ports
#1
Posted 12 October 2009 - 03:48 PM
I am suspicious that someone is still trying to access my computer. The person doing this is known to me but I don't know how to stop it.
#2
Posted 12 October 2009 - 04:38 PM
Andrew Brown
A learning experience is one of those things that say, "You know that thing you just did? Don't do that." — Douglas Adams.
Why is the word abbreviation so long?
Follow BleepingComputer on: Facebook | Twitter | Google+
#3
Posted 12 October 2009 - 05:23 PM
#4
Posted 12 October 2009 - 07:04 PM
Use the following port list to see if the right applications are accessing their assigned ports. http://www.iana.org/assignments/port-numbers
Andrew Brown
A learning experience is one of those things that say, "You know that thing you just did? Don't do that." — Douglas Adams.
Why is the word abbreviation so long?
Follow BleepingComputer on: Facebook | Twitter | Google+
#5
Posted 12 October 2009 - 07:49 PM
I am posting some of my inbound events log. Attempted unsolicited connection to UDP port 56192 or port 57419, 64935 etc... all high numbers except the ones that say commonly used by icslap etc.
Also there is one log that says. A computer at 192.168.1.1 has pinged your computer. The source IP is "non-routable" IP
Thanks for the help
#6
Posted 12 October 2009 - 09:23 PM
#7
Posted 13 October 2009 - 12:47 PM
C:\DOCUME~1\OWNER~1.YOU\LOCALS~1\Temp\WER201a.dir00\svchost.exe.mdmp
C:\DOCUME~1\OWNER~1.YOU\LOCALS~1\Temp\WER201a.dir00\appcompat.txt
So I went to that directory to see what it is and couldn't find anything even when I made so I could see hidden files. Also when I try to open Owner Folder I get this message. " Owner is not accessible. Access is denied"
Am I just being paranoid or is could there be something on my computer I can't find? How much does a router, antivirus and firewall provide? As I am pretty sure who is cracking my email account and hacked my computer and they have left some traces my brother called them kiddie scripters. Not sure what that means. I do have some ips and email addresses but don't know if I can use that info to prove anything.
#8
Posted 13 October 2009 - 06:33 PM
#9
Posted 16 October 2009 - 01:52 PM
Does this mean I have a virus or something on my computer that is not being detected? Also when that happened I had 7 pages of logs on mcafee and now I have 17 and it is all attempted access by 192.168.0.1 to different ports and all the ports are high numers such as 51460, 64010 etc...
I am also having trouble connecting to websites.
What do I do about this? Please help if you can.
Thanks
This post has been edited by The weatherman: 16 October 2009 - 05:51 PM
Reason for edit: Merged topic.~Tw
#10
Posted 16 October 2009 - 10:38 PM
In the old days the communication was by UDP over local port 53 and remote (DNS server) port 53. That has changed. Currently remote is always 53, but random local high port numbers are where the replies come to into your box.
So you need to provide the complete information of source IP, source port, remote IP and remote port and UDP or TCP protocol and direction and what application is involved. Perhaps then people can stop guessing.
I don't know whether if the router is a DNS server the high ports are involved, but suspect they are, because it was a change Microsoft made to our systems.
Take a look at your ipconfig - Start, Run, type cmd, the type ipconfig /all and check what your DNS servers are. While you're there, confirm that your computer really is 192.168.0.1 since it sounds to me more like a typical router address and likely your PC is 192.168.0.2 or .100 or some other number. Then again the modem might be in the picture. I hope the modem's address and router's are different and that you don't have two DHCP servers conflicting.
This post has been edited by tos226: 16 October 2009 - 10:42 PM

Help

Back to top










