Re: I've been hacked

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: George Hester (hesterloli_at_hotmail.com)
Date: 05/26/04


Date: Wed, 26 May 2004 16:34:53 -0400

Some processes you cannot stop even as Administrator. It is because they are either necessary for Windows to run or they are locked by some other process which you have to find first kill and then kill the one you want to kill.

The fact that the "hacker" comes back so fast but not instantly makes me wonder what your evidence is based on. Can you identify the IP address of what is changing these files? What if you change the permissions on them to say System and Admin only? There is a utility from Microsoft called Port Query. They even have a Service by a similar name. It is called Port Reporter. I believe you let this start automatically and you can monitor your ports over time. I have it but don't use it often.

-- 
George Hester
__________________________________
"Marcus Smaby" <mrsmaby@@@msn.com> wrote in message news:uKujEz1QEHA.964@TK2MSFTNGP10.phx.gbl...
> I am having a continuing problem that I can't seem to get a handle on.
> Recently, someone hacked into one of our servers. Now, one or twice a day I
> see either the file system.exe or netstats.exe appearing in the system32
> folder and in the tasks list. At this point the network is brought to its
> knees and it can take me 15 minutes to log into the affected server.  I have
> checked for references to these two files and I get a hit on system.exe as a
> Trojan, but the only hits I get on netstats.exe is as a utility.  I have
> firewalls. I am at current patch levels on everything. I have Norton
> Corporate AV running on all systems but still this continues. I cannot kill
> these processes as they come back 'access denied'. My only recourse has been
> to rename these files from a CMD prompt, clean out any references from the
> registry and reboot.  But within the hour, they are back!
> 
> 1. Is there anyway to force a process to die?  If I am domain admin, why
> would I be denied access?
> 
> 2. Is there any utility that would lock out a given program from starting?
> 
> 3. How can I determine where this is coming from?
> 
> Thanks in Advance.
> 
> Marcus
> 
> 


Relevant Pages

  • Re: [Hamster/Xnews] Regex help on killing via References
    ... standard headers on which you could score; ... although he isn't the only person whose posts I want to kill ... scoring on References. ... Agent posts aren't the only bug-bear as it turns out. ...
    (news.software.readers)
  • Re: [FAQ] Moderation and Posting to Talk.Origins
    ... from the original post vanish into the mist as well - I don't only kill ... the original poster, I kill any replies. ... But TBird doesn't offer References filtering. ... I loved MacSOUP, but it stopped working at some point in the OS upgrade series... ...
    (talk.origins)
  • Re: [PATCH 07/11] Removing dead ARCH_PNX010X
    ... references for it from the source code. ... If you are going to kill this off, ... -writeword(unsigned long base_addr, int portno, u16 value) ...
    (Linux-Kernel)
  • Re: [FAQ] Moderation and Posting to Talk.Origins
    ... It's the References: header though - replying to a tagged message means ... the original poster, I kill any replies. ...
    (talk.origins)
  • Re: RFC: remove CONFIG_EXPERIMENTAL
    ... Feel free to kill any references to experimental for sdhci. ... (I also support the general sentiment) ...
    (Linux-Kernel)