|
Warning ! A fuckink hacker came into my system, scan your system ! know what to do ?
help me to protect myself from this fuckker if you can .. and to find him will be great !
What a surprise when i saw my mouse pointer moving alone..
Iam pretty sure to know who is he ..but i wont say a name at this point.. i will come back for detail about this hacker..
tips: search into your computer for dwmrcs.exe .. if you have this shit.. your infected... ask me what you have to do to remove this shit
This motherfucking ass hole .. take ''dameware mrcs'' to enter into my machine ...
i dont know what the fuck he be able to instal this shit into my system
here are the application log file ... i would like to punish him
Event Type: Information
Event Source: DWMRCS
Event Category: None
Event ID: 0
Date: 14/03/2003
Time: 3:48:17 PM
User: N/A
Computer: DESTRO
Description:
The description for Event ID ( 0 ) in Source ( DWMRCS ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event:
DameWare Mini Remote Control
, The following user has connected via remote control.
Date: 03/14/03 15:48:17
Computer Name: O0TROTTER0O
User ID: Alexandre
Logon As ID: TRI-MASTER
Domain:
OS Product ID: 55274-642-7769785-23706
OS Registered Owner: alex
OS Registered Organization:
Host Name from Peer: o0TroTTeR0o
IP Addresse(s) from Peer: 24.202.166.186
Host:
IP Address: 24.202.166.186
Protocol Version - DWRCC.EXE: 3.670000-0.000000
Protocol Version - DWRCS.EXE: 3.670000-0.000000
Product Version - DWRCS.EXE: 3.69.0.7
Authentication Type: NT Challenge/Response
Last Error Code: 0
Last Error Code (WSA): 0
Absolute timeout setting: 0 minutes
Connect/Logon timeout setting: 90000 miliseconds
Access Check: Administrators
-------------------------------------------------------------------------
I have a lot of theese log ..
he come 8 time .. since 12/03/2003
I have ip adresse log ..
Now removed the fucking program .. change my username/password , scan my system....etc ..
But he still try to come in .. i see him trying to enter with my firewall
Every 5 minutes .. he try to come in .. with a new port, a new protocole, a new ip ....
Here are the ip adresse tring to come
--- 204.202.145.59 --- is the most common , try to enter every 5 min.
24.202.179.113 port : 2199
24.201.36.178 port 4081
Can some one help me to protect myself from that ??
Can i find Who is doing that .. with the application log.. ?
Can i find who doing that with all theese ip adresse ?
Can i know whos the programme to hack (dameware) is registered to ?
tips: search into your computer for dwmrcs.exe .. if you have this .. your infected... and ask me what you have to do to remove this shit
thanks !
|