Question

Hacked!

Asked by: drno007

Hi experts,

I found some strange programs running on my pc and started to investigate, this is what I found:

Small program for remote controlling the PC from http://www.dameware.com (72kb) dntus26.exe

Small program for ftp-server tasksrv.exe (22kb)

Question: How the heck did he get them there?

I am not running any servers on my pc. And no I have not surfed to the Nimda infected pages.

How did he start the telnet service remotely?

Below is from the eventlog.

Thanks in advance.

2002-05-11      05:39:00      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\wbk24A.tmp
is infected with the W32.Nimda.A@mm (dr) virus.; Access to the file was denied..
2002-05-11      05:39:00      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\wbk24A.tmp
is infected with the W32.Nimda.A@mm (dr) virus.; Unable to repair this file..
2002-05-11      05:39:00      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YJGFKXU3\readme[1].eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11      05:39:00      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YJGFKXU3\readme[1].eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11      04:20:53      TlntSvr      Information      None      1001      N/A      HOMEPC1      The MS Telnet Service has shut down successfully.
2002-05-11      04:20:07      TlntSvr      Information      None      1000      N/A      HOMEPC1      The MS Telnet Service has started successfully.
2002-05-11      04:14:03      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:14:02      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:14:02      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:14:02      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:14:01      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:14:01      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:14:00      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:13:59      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      04:13:56      TlntSvr      Error      None      4000      N/A      HOMEPC1      An error occurred while attempting to create shell process.
2002-05-11      03:31:22      FrontPage 4.0      Warning      None      1000      N/A      HOMEPC1      Microsoft FrontPage Server Extensions:
   error #50001 message: there is no environment variabel of type SERVER_PORT.
2002-05-11      03:27:55      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\FrontPageTempDir\_vti_inf.html
was infected with the W32.Nimda.A@mm(html) virus.; The file was repaired..
2002-05-11      03:22:58      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\FrontPageTempDir\_vti_inf.html
was infected with the W32.Nimda.A@mm(html) virus.; The file was repaired..
2002-05-11      01:37:54      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMH0YNG2\wbk19D.tmp
is infected with the W32.Nimda.A@mm (dr) virus.; Access to the file was denied..
2002-05-11      01:37:54      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CMH0YNG2\wbk19D.tmp
is infected with the W32.Nimda.A@mm (dr) virus.; Unable to repair this file..
2002-05-11      01:37:53      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\readme[1].eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11      01:37:53      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\readme[1].eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11      01:37:52      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\readme[1].eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11      01:37:52      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\readme[1].eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11      01:37:52      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\readme[1].eml
is infected with the W32.Nimda.enc virus.; Access to the file was denied..
2002-05-11      01:37:52      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\EXXPQOHR\readme[1].eml
is infected with the W32.Nimda.enc virus.; Unable to repair this file..
2002-05-11      01:37:45      Norton AntiVirus      Error      (1)      4097      NT AUTHORITY\SYSTEM      HOMEPC1      The description for Event ID ( 4097 ) in Source ( Norton AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: The file
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YJGFKXU3\170.143.172[1].htm
was infected with the W32.Nimda.A@mm(html) virus.; The file was repaired..

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2002-06-12 at 16:05:12ID20311007
Tags

computer

,

information

,

registry

Topic

Operating Systems Miscellaneous

Participating Experts
1
Points
100
Comments
9

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. FrontPage 97: what's all those _vti_stuff??
    if you save a website in ..wwwroot/mysite - frontpage editor/explorer(?) creates some funny subdirectories :- _vti_bin, _vti_adm, _vti_cnf, _vti_pvt, _vti_txt what are these & what do they do??
  2. What is '_vti_cnf'?
    I would like to know what '_vti_cnf' is and why I am getting a copy of everything automatically created here, Thanks, Alan.
  3. vti files corrupted?
    I have created a website with FrontPage 2002, and am having trouble uploading it properly to my webhost, Netfirms ~ a host that supports FrontPage extensions. My hover buttons are not working properly once uploaded, although they preview in IE fine when working from FrontPag...
  4. What are _vti_cnf, _vti_pvt,... carpets?
    Hi, In Inetpub/wwwroot/myWebProject/ I'm wondering what are these carpets: _vti_cnf _vti_pvt _vti_script _vti_txt I don't know when they were created. Are they temporal carpets? May I delete all of them withouth trouble? Thanks!
  5. Delete frontpage folders(_vti_cnf)
    I need a script jscript or vbs(perfered jscript) that once I click on it , it popups up a broswe popup to find a folder, once a pick a folder it then deletes all folders called (_vti_cnf) if they are hidden/system ANYTHING. So i can then upload the main folder/files to a webs...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: WakeupPosted on 2002-06-12 at 16:37:07ID: 7074198

drno007,

You dont need to have a server or anything to get Nimda.  You can be infected from just opening an email.  Do you need to get this Nimda Virus removed?
http://securityresponse.symantec.com/avcenter/venc/data/w32.nimda.a@mm.removal.tool.html

Go there and follow the instructions!
I would double tripple quadruple check to make sure it is gone.

 

by: drno007Posted on 2002-06-12 at 17:43:41ID: 7074311

Nimda has never been active on my pc.

These are the files caught by norton as indicated in the previous eventlog.

The file "C:\program files\norton antivirus\quarantine\incoming\ap0.htm" is infected with W32.Nimda.A@mm. The file is repaired.

The file "C:\program files\norton antivirus\quarantine\incoming\ap0.html" is infected with W32.Nimda.A@mm. The file is repaired.

The file "C:\program files\norton antivirus\quarantine\incoming\ap1.html" is infected with W32.Nimda.A@mm. The file is repaired.

W32.Nimda.A@mm has been successfully removed
from your computer!

The total number of the scanned files: 45008
The number of deleted files: 0
The number of repaired files: 3
The number of viral processes terminated: 0
The Guest account was removed from the administrators group: NO
The Guest account was disabled: YES
The number of shares found: 6
The number of shares secured for administrator use only: 6
The number of registry keys deleted: 0

 

by: WakeupPosted on 2002-06-12 at 19:08:09ID: 7074491

well then it was on your system and was removed by norton.... according to the event logs....they may not have been active, or memory resident....but they did reside on your puter at one point in time since 3 of the files on your machine have been repaired.

Also I do not understand what kind of help you need.  If the viruses have since been removed...My suggestion is to get a firewall up.  That may help as well...Like ZoneAlarm or Norton Internet Security.  There are lots of Backdoor Trojans and the like...that this so called hacker may have used to access your system.  And may have gotten Nimda onto your machine via those backdoor trojans.

 

by: WakeupPosted on 2002-06-12 at 19:09:24ID: 7074496

Here are some things to try:
trojan remover
http://www.simplysup.com/tremover/

www.zonealarm.com
free dowload personal use

 

by: drno007Posted on 2002-06-13 at 00:30:54ID: 7074858

I am accepting this comment and reinstalling my pc. Also going to install that firewall.

thanks for the help.

 

by: WakeupPosted on 2002-06-13 at 01:15:06ID: 7074929

Why a C grade?  Is there something that I did not answer?  Also you didn't give me any chance of getting a better grade.  I asked what you were asking.....

 

by: drno007Posted on 2002-06-13 at 06:25:00ID: 7075427

The question was: how did he manage to start the telnet server service remotely? he obviously tried to get it started a few times before he succeded, as indicated by the eventlog. once that is done it would only be a matter of seconds before he could tftp the small programs to my pc.

Also I hate firewalls. only a bunch of false alarms.
A huge marketing scam in my opinion.

The C grade may have been unfair, but I am very tired from staying up until 3:00am and getting up again 7:30am.

Sorry, make it up to next time, OK?

 

by: drno007Posted on 2002-06-13 at 06:43:01ID: 7075473

also a translation of this page would be fun to have.

http://ddjia.51.net/hebackwenzhan/page1/wenzhanmulu21.htm

 

by: drno007Posted on 2002-06-13 at 07:45:10ID: 7075658

also a translation of this page would be fun to have.

http://ddjia.51.net/hebackwenzhan/page1/wenzhanmulu21.htm

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...