View Full Version : Strange Windows!


Diode-Man
02-15-08, 09:46 AM
My computer won't let me install Windows Defender (internet tcp/ip security by microsoft) It says "The system administrator has set policies to prevent this installation." I AM the bloody system administrator and I have set no such policies!

Then using some port watching software (after searching through a whole bunch of crap software) I found one which observes the ports and can do a who-is search, strangely enough I found IP address' clear the f**k from China accessing this computer!? But sadly I got rid of that port watcher and can't find it again.... does anyone have some suggestions!?

On top of this, some how my system restore has been infected with shit as well, it doesn't fully restore as it should, data gets spilled over making the system restore completely worthless. I have a recovery partition which may have been accessed by hacker b*st*rds!

Diode-Man
02-15-08, 06:11 PM
No one has a damn thing to say on this then?

spidergoat
02-15-08, 06:14 PM
Call desktop support, press control-alt-delete, jiggle the cord...

tablariddim
02-15-08, 06:14 PM
maybe, your anti virus won't allow it...don't believewhat ms tells you.

Asguard
02-15-08, 06:15 PM
are you logged in as the admin or as a user?

Dr Mabuse
02-15-08, 06:28 PM
from what you describe... i can only go on your short description of course...

you may well be owned... actually rooted...

a zombie?... a botnet slave?... an amplifier?...

who knows...

from what data you provide here the most likely conclusion is you are owned...

What is a Zombie??? (http://www.google.com/search?hl=en&safe=off&sa=X&oi=spell&resnum=0&ct=result&cd=1&q=zombie+pc&spell=1)

What is a botnet??? (http://www.google.com/search?hl=en&safe=off&q=botnet+pc&btnG=Search)

to take back your system you would need to format the hard drive and re-install windows... with strong protection installed right away after doing this... windows defender performs so poorly in actual testing there are several testing groups that will not be testing it in the future...

i've said it several times here i think... these two are the best combination you can run... period...

Avira Antivir Personal Edition Premium...(i was specific for a reason)

Spyware Doctor...

decantemix
02-16-08, 11:26 AM
http://www.snort.org/

is one of the best at finding out whom is on your system. Has a bit of a learning curve, though.

Yeah, I've had trouble with the "Pacific Rim". It's a group of Communist hackers from China, with integrated factors from Japan, as well.

They're like the ferrets of the I-net. And, they love making their presence known to ISPs. Wonder how they operated with the Patriot Act in full swing? Hell, I can't order a pizza without gov't agencies knowing my toppings of choice, while a menagerie like this tramples all over the back-bone. Oh, well...

decantemix
02-16-08, 11:51 AM
Yeah, they're active.
About 2 minutes after I posted this, someone tried to activate my brother printer. And, it wasn't powered up, but was connected.

You know how they are about ports, and pictures. Found my damn printer. Lousy punks, hope they know their fun puts them in the light, and no Los Alamos datums for 'dem. Tried and true, they known now, bad for them.

You so anxious, you no know how to discipline. Watch 'more movies on maintaining 'yo chi...YO!.

draqon
02-16-08, 11:55 AM
dude format you hard-drive from dos...your system is infected

Dr Mabuse
02-16-08, 02:42 PM
Motherbrain you kind of post a little impatiently with a 'no answer' post... and now no follow up?...

my conclusion based on your first post is you were owned...

people who visit this forum every day are owned and don't have any idea...

it's a statistical certainty...

some estimate, not some yahoos making wild guesses, informed people in the Information Security industry, think as many as 25-30% of all PC's are owned...

the clowns do it in such a way that you realize it... just to practice and prove they can...

skilled attackers do it in such a way that you never know they are there, and your PC runs like a top...

both Mcafee and Symantec have publicly disclosed they have seen botnet and zombie attackers that could remove viruses and malware, that Mcafee or Symantec could only remove with manual steps from the user... the attackers also cleaned worms and tightened security settings on the PC's they owned...

they don't anyone calling tech support...

the fact that so many users... supposedly knowledgeable PC users... think 'Spybot' , 'AdAware' and free Anti Virus programs like 'AVG' keeps them protected... free of malware and viruses... hell in any way makes their PC secure... is a big part of the problem...

beyond that many people run nothing at all...

the combination of those two realities makes life SO easy for a skilled attacker...

i recommend good software in posts on several forums i post on...

and i watch the inevitable "all you need is AVG and Spybot/AdAware" posts that follow...

any person on an owned PC should assume every keystroke they have typed for months has been logged... meaning any banking... usernames and passwords... everything is compromized... and needs to be changed...

decantemix
02-17-08, 08:47 AM
Yeah, the above post is pretty stable in thought. Although, I'll further that probably as many as 80% are compromised, though not 100% of the time.

If you look at someone whose job it is to provide network security, say an analyst or security specialist. You'll see they're quite busy. Always, hoping.

Attacks can last from continuous control, to burst of only a few seconds. Where they get what they want, then leave no trace. And, they're off to the next victim.

Port sniffers/Packet Analyzers will tell you a lot. Let one run for a whole session in the background. Then, disconnect from the internet and look at it. Typical invasions are usually prominent this way, and unless you bothered to check, you'd never know.