Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

hacker attack

Posted on 2004-10-07
6
784 Views
Last Modified: 2013-12-04
hello everyone...
im not sure if this is the right place.. but spare with me.
i have abroardband conncetion. and every time I turn on the pc. my netstat tool show a active connection. protocol tcp port 3660.. foreign address: 220.67.19.97.reverse.theplanet.com:http ESTABLISHED.
now! i have windows XP pro tcp filteriung on and allow only few ports... 3660 is not among them... still the connection is there,,, futhermore i have made a security policy blocking this addresss and port.. still.. its there,,,
i have also added the dns namepsace to the (restricted site) under internet security for iexplorer.. still connected. my question is : how do I block or stop this connection,, now I have made all this setting and blocking..

i hope someone can help me.. what did I miss ?

thanks ad avanced

manchild
0
Comment
Question by:manchild_dk
6 Comments
 
LVL 49

Expert Comment

by:sunray_2003
ID: 12253279
Hi manchild_dk,

When you say netstat , do you mean any seperate software or using netstat in command prompt ?

Do you have any firewall installed ? If not , install Zonealarm and see if you can block that port or check what is getting connected when  you turn on the PC.
There could be some exe file that might be connecting..

Have you checked your system for virus and spywares ?


SR..
0
 
LVL 2

Accepted Solution

by:
bacvain earned 250 total points
ID: 12253747
Sunray, no offense or anything but it sounds that manchild knows what he is talking about and i doubt he would allow a spyware or virus run on his pc...This a link refering to each port identification:

http://www.iana.org/assignments/port-numbers

..search for 3660 and you'll find what it does.

Now i read about 3660 port and this is what i got; this in fact is what uses the port 3660.... please read it:

MGCP

Media Gateway Control Protocol (MGCP) is used for controlling telephony gateways from external call control elements called media gateway controllers or call agents. A telephony gateway is a network element that provides conversion between the audio signals carried on telephone circuits and data packets carried over the Internet or over other packet networks.

MGCP assumes a call control architecture where the call control intelligence is outside the gateways and handled by external call control elements. The MGCP assumes that these call control elements, or Call Agents, will synchronize with each other to send coherent commands to the gateways under their control. MGCP is, in essence, a master/slave protocol, where the gateways are expected to execute commands sent by the Call Agents.
-------------
this brings me to the next point, are you on Cable or ADSL?
0
 
LVL 1

Expert Comment

by:jonathan6587
ID: 12254324
manchild_dk

port 3660 is your local port.  HTTP (80) is the port on the remote computer.

Filtering blocks incoming packets not outgoing.

>> dns namepsace to the (restricted site)
This is for Internet Explorer - IE is probably NOT making the connection.

Sounds like you probably have something installed on your computer.  Unfortunately, this little piece of software can be anywhere.

Check this site out and see if it helps.

http://www.neuber.com/taskmanager/process/winmgmt.exe.html

I suggest that you download SpyBot or something like it.

http://www.safer-networking.org/en/download/index.html

Jonathan
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 1

Assisted Solution

by:jonathan6587
jonathan6587 earned 250 total points
ID: 12254366

Something else you can try.

add this line into your hosts file:

127.0.0.1          reverse.theplanet.com

The hosts file is located here:
C:\windows\system32\drivers\etc\  

This file gets accessed before DNS resolution so it should send the packets back to your computer and not make the connection.  

This is just a little trick that should prevent the connection until you can remove the underlying problem.

Jonathan
0
 
LVL 11

Expert Comment

by:mwnnj
ID: 12255532
Hi folks,

cheers at  Jonathan ^_^ !
I have found more info about port 3660:
http://network.programming-in.net/articles/tcp-udp-port.asp?port=2850&udp=4300
Actually tcp/udp connection on 3660 local is fr ssl ;can-nds-ssl :candle directory services...
http://www.siterecon.com/TCP-Ports-3001-10000.aspx ,i didn't found enoug info about candle ssl but it's registered by IANA-i think troyan accesment ,so if i aam rigght:
1) get Hijack This! and make log file and post it here!!!
Shehar is one of the best detectives about HiJack This logs...
http://www.spychecker.com/program/hijackthis.html
2)Install pest patrol with theese restrictions:
Pest patrol > options > Where to Search :
 check : all files ;
 check : scanning method : thorough ,
 check : scan shell tree options > show hidden and show files .
Pest patrol > options > What to search for - and then check all the items-all!
Pest patrol > options > What to exclude : wtere must be only the recycle folder and system volume information nothing mere!
Pest patrol > options > Automatic scans !!!
 check : scan on boot --> your boot partition
 check : PPMemCheck Memory Scan > Invoke on boot
 check : CookiePatrol > Invoke on boot
 check : PPcontrol > Invoke on boot
 check : KeyPatrol > Invoke on boot
you can check also the right click option for folders too...
check in the main menue to scan all hard drives .... update the pest patrol.
http://www.pestpatrol.com/Products/PestPatrolHE/Single_User_Evaluation.asp
3)You need also at least a second programe to block startup malicious:
try winpatrol : http://www.winpatrol.com/winpatrol.html,
4) run stinger -it's a basic troyn removal tool:
http://vil.nai.com/vil/stinger/
5)you need a startup-manager,for example:
starter:http://members.lycos.co.uk/codestuff/
6)you need a good task manager:for example:
process explorer:http://www.sysinternals.com/ntw2k/freeware/procexp.shtml
7) if things are not getting better and you like posting:
Analyzer :http://jjhicks.com/ and please post all the logs here if pest patrol ,winpatrol,stinger can't help.But first paste the Hijack This log!!!VERY IMPORTAINT!
8) If you wisch try the Sygate Professional firewall;it has a blocking mechanism for all kind of connections before the firewall service is started!!!
Good Luck !
Till later
0
 

Author Comment

by:manchild_dk
ID: 12266109
wow. guys.. thanks for all thise hits'n respondese..
 i use ADSL, and i have housecall and spybot running every day. so clear of virus, etc... i did manage to reverse the ip adress connected to my ip to a main IP adress and  as a result, my  security polices work now..
however,, my netstat (command line tool :-) still show a time wait  status for the connecting ip. just it is searching for open port to use...

my firewall (in XP) have TCP filtering on. and yes.. it is for incoming only... as jonathan stated.. thanks for the trick in local hosts. it gave me the ip in netstat (when offline) and lead me to the source of the connection attempt..
bacvain.. you gave me the last clue to find the program that make this outgoing attempt.. (not the incoming as I thought at first) as i only have realplayer and media player to use the media control protocol it was easy to see my new realplayer is the cause so.
no hacker atttack, but me in lack of realplayer controll.. i learn :-)

i have to share the points to jonathan and bacvain. but thanks again for helping me to help myself :-)
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

838 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question