HELP! Someone Is trying To Hack Into My Computer!

ok i was in the middle of trying to load this page in my main browser and it wouldnt load was taking over 3 or 4 minutes ( because it wont let me edit in my Opera browser the one thats still active now) and as soon as i turned the Windows firewall off i lost the connection to it totally .. i get this

 

 

 

The page cannot be displayed The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings. -------------------------------------------------------------------------------- Please try the following: Click the Refresh button, or try again later. If you typed the page address in the Address bar, make sure that it is spelled correctly. To check your connection settings, click the Tools menu, and then click Internet Options. On the Connections tab, click Settings. The settings should match those provided by your local area network (LAN) administrator or Internet service provider (ISP). See if your Internet connection settings are being detected. You can set Microsoft Windows to examine your network and automatically discover network connection settings (if your network administrator has enabled this setting). Click the Tools menu, and then click Internet Options. On the Connections tab, click LAN Settings. Select Automatically detect settings, and then click OK. Some sites require 128-bit connection security. Click the Help menu and then click About Internet Explorer to determine what strength security you have installed. If you are trying to reach a secure site, make sure your Security settings can support it. Click the Tools menu, and then click Internet Options. On the Advanced tab, scroll to the Security section and check settings for SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0. Click the Back button to try another link. Cannot find server or DNS Error Internet Explorer

 

 

I noticed once i had the Windows firewall on I was having a LIL less problems with connections and as soon as i turned it off like [MDTRUNER] suggested i have connection problems again.... but you say NOT TO run both firewalls? what exactly happens when you run 2 firewalls at the same time?

 

(FOR SOME REASON WHEN I POST MY REPLIES IN MY OPERA BROWSER IT DOESNT FORMAT IT IN THE PARAGRAPHS I WRITE IT IN ... IT JUST BUNCHES ALL THE WORDS TOGETHER PLUS IT WONT ALLOW ME TO EDIT IT THERE.. SO I HAVE TO COME BACK TO MY MAIN BROWSER WHERE ITS TAKING OVER 3 OR 4 MINUTES TO FINALLY LOAD SO I CAN FORMAT IT LIKE I POSTED IT)

This article from Microsoft explains firewalls and has the question about 2 firewalls answered.

 

http://www.microsoft.com/security/firewalls/faq.aspx

[BJM]

 

QOUTE: "@ iitsLexiis

iitsLexiis wrote > bjm let me know if thats the same I.P

 

Yes.... same IP ,  reverse IP lookup ~ China , same time period

So, "he" as you describe the Intrusion Attempt is not only after you..."he" is also probing my box...

 

"he" and "they" are always trying to find a hole to crawl through... hence the need for Firewalls and Norton ~ IMO"

 

yea when you said you thought you were having the same problems with the same I.P i started thinking its probably a group of ppl....  so are you still having problems or did you block them?

 

 

 

 

 

 

ugh!! my computer is getting on my nerves right now its taking over 4 or 5 minutes just to reply to a post i dont usually have this problem... i came on to reply to everyones posts but cant... ill try later on

Hi iitsLexiis,

 

I am also currently experiencing slow page load times at the Norton site.  There is still a lot of tinkering going on here behind the scenes and occassional odd behaviors crop up from time to time.  I sometimes use Opera on a Mac and have had issues similar to what you describe:  horrendously slow page loading, text editor issues and other scripting errors.  Are you able to visit other sites without these sorts of problems?  Can you use this site with Internet Explorer or Firefox?

 


reactivate wrote:
Also Note: If you decide to update, use the Norton removal tool to remove your Norton Product properly from your computer, as Norton 2010 will use a different engine. You should run it two or three times, restarting your computer after each run, then it will be o.k to install NIS 2010, or if you prefer Norton 360 v4

 

This raises a question I always wondered about.  If you run the Norton removal tool, won't you be vulnerable to any virus or hacking attempt until you get the new version installed? I think if I knew that I were subject to frequent attacks from a Chinese site, I'd be worried about even having a few minutes of total vulnerability.

 


randysea wrote:

 

This raises a question I always wondered about.  If you run the Norton removal tool, won't you be vulnerable to any virus or hacking attempt until you get the new version installed? I think if I knew that I were subject to frequent attacks from a Chinese site, I'd be worried about even having a few minutes of total vulnerability.

 


HI randysea

 

You would indeed be vulnerable if you stayed connected to the internet with a firewall disabled. If you look closely at posts where advice has been given to use the Norton Removal Tool it has also been strongly advised that users should disconnect from the internet until their product is installed/reinstalled and/or enable the Windows Firewall which would subsequently be disabled once the Norton install was completed.

Hello iitsLexiis

iitsLexiis wrote > yea when you said you thought you were having the same problems with the same I.P i started thinking its probably a group of ppl....  so are you still having problems or did you block them?

 

I did not block "them" ~ IP / Port > Please see this Topic

http://community.norton.com/t5/Norton-Internet-Security-Norton/Attacking-Computer-Intrusion-Protection/td-p/125892

Source address:  122.227.164.96 (different IP)

Traffic description:  TCP, Port 12200 (same)

No Action Required   (same)

Medium Severity    (same)

Floating_Red offered info > How to Block the Port Number & dbrisendine offered info > The rule that Floating_Red had you make will only block the IP address listed.  You are protected by NIS2009 automatically (as indicated in the history logs) so you should not anything to worry about.  You can not stop the outside source from scanning your system; the rule will stop the logging if that is what was bothering you.  All portscan probes were blocked.  You are secure.

I considered creating a rule...then just followed info from dbrisendine.  

delphinium (this thread) offered > TCP is a directed communication attempt rather than a UDP general broadcast.  It could be that prior infections have used those ports, or that they have been used for self-generated forms of communication.  That should be checked for your own piece of mind.

 

Maybe, I should re-think ?  IDK   at this time IDK ~ how to act on delphinium advice > That should be checked for your own piece of mind.


 


mdturner wrote:

 

HI randysea

 

You would indeed be vulnerable if you stayed connected to the internet with a firewall disabled. If you look closely at posts where advice has been given to use the Norton Removal Tool it has also been strongly advised that users should disconnect from the internet until their product is installed/reinstalled and/or enable the Windows Firewall which would subsequently be disabled once the Norton install was completed.


 

What you say makes sense. Turning on Windows firewall is a particularly good idea. It had not occurred to me.  However, I don't think the advice about disconnecting is given as often as you think. In this thread, for example, it was not given.

 

Possibly even worse, Symantec itself may fail to give that advice. A few weeks ago one of my machines started up with a message that intrusion protection had failed to load. I was directed to run the Norton Removal Tool and reinstall NIS. There was no mention of disconnecting from the Internet. Now, I can't say for sure if the tool itself might have given me that warning. Before I went through the annoyance of removal and reinstallation, I did the more obvious thing. I rebooted. This time NIS started up normally, and there have been no problems since.

 

I can see another bad scenario. If I remember correctly, this thread started with someone using Norton 2005. Supposing he had run the removal tool, for whatever reason, including disconnecting from the internet. At some point in the reinstallation he would have to reconnect. For however long it took, his protection (signatures and program files) would be five years out of date. Even if he was upgrading to NIS 2010, the installation files would be up to a year out of date and thus he'd still have a window of vulnerability. For most people, this window of a few minutes would be a very low risk. But for someone who is regularly being attacked, it is a much higher risk.

 

Seems like the Norton installation routines should have a test for an inadequately protected computer. Then it should close all internet traffic during installation, except for brief openings limited to Symantec validation and update downloads.

 

 

I too have had many port scans as well.  Some of them has been even medium: ((intrusion attack blocked )) then ip address  same as yours.  There should be some kind of extra protection or a way to scan your ports in norton to see what is going on.  I've had more then 15 in last 4 hours alone. I've emailed norton on this to find out what the heck is going on.  The port said 12200 as the target.

Hi Tomas01

FWIW

re> The port said 12200 as the target.

Same for me...always 12200

Source address:  1XX.2XX.3XX.4X (different IP's)

Traffic description:  TCP, Port 12200 (same)

No Action Required   (same)

Medium Severity    (same)

 

Interested to read your reply from Symantec

Thanks

 

It said something to that my isp is allowing access to those ip address on my network, and that is the reason those ip addresses are trying to access my computer.  They are being blocked and nothing to worry about. I will try to email my isp again and see what they say.  Still  so many probes.  Every once in a while they try to get thru and pop up a warning about it.  I am trying something that was posted in here about using rules to block a certain ip address or what ever,  I created two of them for two different ones.  Is there any way to trace it back to whom is doing it.  I mean thru what web site or what?  I had heard something like trace route I think I wounder if it would work.

This type of traffic is everywhere on the internet and there is not much you can do except block it.  That is what firewalls are for, and that is all you need.  If you research the topic on Google you will note that portscans from China using this port number (and many others) have been a constant on the internet for years.  Port 12200 is associated with Tenebril's GhostSurf, which is a web anonymizer, and many compromised systems will look for open proxy servers on this port.  That explains one reason why this port shows up so frequently in firewall logs.

 

If you go on the internet you are going to be exposed to lots of unsolicited traffic because that is the nature of the internet.  Firewalls protect you.  It's like a flu inoculation:  A flu shot will not stop the virus from circulating everywhere around you, but it will prevent the virus from entering your cells and infecting you. 

 

A good brief discussion of this internet background noise, as it is called, and the need to be behind some sort of firewall can be found here:

 

http://ask-leo.com/what_are_these_access_attempts_in_my_router_log.html

I made a rule to block the address with the port 12200 to see if that makes a difference.  I will look into the link below, if it is just noise why are some of us getting intrusion alerts for medium?  Is there some safe way of running a test to see if my ports are okay? 

I have broadband cable thru my isp.  (cable modem then connected to the computer).  Mine is not wireless also.  I  have vista 64 on my sys.

 

there was something else , do you have broadband as well?  I also have vista 64.  I will try to find something that will look at my ports to see if everything is okay,  waiting for a reply.  Are you still getting them now? how many?

*YAWN*

 

Thu, 2010-05-20 03:18:40 - Router start up
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8088 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,6588 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8089 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,2301 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,7212 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,3124 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8090 - [DOS]
Thu, 2010-05-20 19:54:25 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,3128 - [DOS]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,3246 - [DOS]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8085 - [DOS]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,2479 - [DOS]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8088 - [DOS]
Thu, 2010-05-20 19:54:26 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Fri, 2010-05-21 12:25:52 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,6588 - [DOS]
Fri, 2010-05-21 12:25:52 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,9090 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,2301 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,7212 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,3124 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8090 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,3128 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,9415 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,1080 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,6588 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8085 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,8000 - [DOS]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166 Destination:xx.xx.xx.xx - [PORT SCAN]
Fri, 2010-05-21 12:25:53 - TCP Packet - Source:125.45.109.166,12200 Destination:xx.xx.xx.xx,2301 - [DOS]
Fri, 2010-05-21 13:59:45 - Administrator login successful - IP:

Hello gabranth

 

That IP is from China

 

More information about that IP can be found here

 

http://www.ip-adress.com/ip_tracer/125.45.109.166

 

   
 
 
 
 
 
 
 
 

 

 

 

That IP seems to be getting around also.

yep says its from china at the top of google results and saw this thread and though i should post what ive been getting from it

How many of you are online RP games players?  I think I asked that question before but it was missed.

@ delphinium

re > How many of you are online RP games players?

 

"Not me"...