Someone hacked into my PC??? I think..

Someone hacked into my PC??? I think..

Author
Discussion

dave_s13

Original Poster:

13,816 posts

270 months

Saturday 17th March 2007
quotequote all
Just sat on my PC and all of a sudden the mouse starts doing it's own thing. It has remote desktop installed so I can mess about with it on the laptop downstairs.
So I turn it off, leave laptop on and go out.

Come back and the laptop is locked with the desktop picture showing but no icons. Press the off button and it says someone is logged into this computer, sure you want to shut down? Yes/No/Cancel etc.

Router has logged this lot:-

Sat, 2007-03-17 14:19:36 - TCP Packet - Source:66.234.37.34,48273 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:37 - TCP Packet - Source:141.213.220.242,59281 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:39 - TCP Packet - Source:154.20.38.70,2600 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:40 - TCP Packet - Source:84.1.202.140,3704 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:42 - TCP Packet - Source:154.20.38.70,2600 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:42 - TCP Packet - Source:85.255.180.66,1030 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:43 - TCP Packet - Source:62.80.224.240,1063 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:43 - TCP Packet - Source:141.213.220.242,59281 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:43 - TCP Packet - Source:202.89.189.207,2801 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:45 - TCP Packet - Source:85.255.180.66,1030 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:45 - TCP Packet - Source:82.17.166.254,62298 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:46 - TCP Packet - Source:74.110.244.212,3297 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:46 - TCP Packet - Source:80.47.110.64,4231 Destination:80.47.76.239,135 - [DOS]
Sat, 2007-03-17 14:19:46 - TCP Packet - Source:141.213.220.242,59281 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:47 - TCP Packet - Source:202.89.189.207,2801 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:48 - TCP Packet - Source:66.234.37.34,48273 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:48 - TCP Packet - Source:83.18.173.60,2326 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:49 - TCP Packet - Source:80.47.110.64,4231 Destination:80.47.76.239,135 - [DOS]
Sat, 2007-03-17 14:19:49 - TCP Packet - Source:141.213.220.242,59281 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:52 - TCP Packet - Source:212.139.193.105,3909 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:54 - TCP Packet - Source:66.234.37.34,48273 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:55 - TCP Packet - Source:141.213.220.242,59281 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:55 - TCP Packet - Source:212.139.193.105,3909 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:57 - TCP Packet - Source:82.9.30.224,62971 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:58 - TCP Packet - Source:89.241.180.51,4593 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:58 - TCP Packet - Source:194.125.54.237,24048 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:19:58 - TCP Packet - Source:88.104.130.164,3775 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:01 - TCP Packet - Source:83.248.67.2,2909 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:01 - TCP Packet - Source:194.125.54.237,24048 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:06 - TCP Packet - Source:86.136.102.225,50991 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:06 - TCP Packet - Source:83.30.25.62,1407 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:07 - TCP Packet - Source:194.125.54.237,24048 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:30 - TCP Packet - Source:212.139.195.194,4064 Destination:80.47.76.239,445 - [DOS]
Sat, 2007-03-17 14:20:31 - TCP Packet - Source:71.81.28.82,2292 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:31 - TCP Packet - Source:82.181.149.71,62941 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:33 - TCP Packet - Source:85.224.164.241,65383 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:34 - TCP Packet - Source:82.181.149.71,62941 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:34 - TCP Packet - Source:125.238.113.215,3942 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:36 - TCP Packet - Source:86.101.129.212,63541 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:37 - TCP Packet - Source:125.238.113.215,3942 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:40 - TCP Packet - Source:85.230.94.235,1265 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:41 - TCP Packet - Source:74.70.100.246,2438 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:41 - TCP Packet - Source:85.3.87.62,64216 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:43 - TCP Packet - Source:85.230.94.235,1265 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:44 - TCP Packet - Source:220.233.160.244,37819 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:45 - TCP Packet - Source:74.106.200.48,1425 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:46 - TCP Packet - Source:212.139.44.8,2414 Destination:80.47.76.239,445 - [DOS]
Sat, 2007-03-17 14:20:46 - TCP Packet - Source:217.88.1.122,61541 Destination:80.47.76.239,6348 - [DOS]
Sat, 2007-03-17 14:20:46 - TCP Packet - Source:70.11.232.149,2795 Destination:80.47.76.239,41201 - [DOS]
Sat, 2007-03-17 14:20:48 - TCP Packet - Source:220.233.160.244,37819 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:49 - TCP Packet - Source:69.158.108.41,3326 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:20:56 - TCP Packet - Source:68.83.114.56,14084 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:03 - TCP Packet - Source:80.192.180.76,4468 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:21:04 - TCP Packet - Source:82.9.30.224,63085 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:06 - TCP Packet - Source:80.192.180.76,4468 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:21:06 - TCP Packet - Source:80.192.180.76,4468 Destination:192.168.0.4,35628 - [DOS]
Sat, 2007-03-17 14:21:07 - TCP Packet - Source:90.193.241.41,3241 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:07 - TCP Packet - Source:218.212.226.194,3905 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:08 - TCP Packet - Source:87.254.64.216,3792 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:08 - TCP Packet - Source:67.55.26.165,64423 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:10 - TCP Packet - Source:218.212.226.194,3905 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:10 - TCP Packet - Source:87.194.76.255,59951 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:12 - TCP Packet - Source:80.192.180.76,4468 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:21:22 - TCP Packet - Source:86.39.111.40,64619 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:24 - TCP Packet - Source:83.4.75.108,3414 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:24 - TCP Packet - Source:84.1.202.140,3881 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:25 - TCP Packet - Source:86.39.111.40,61467 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:21:25 - TCP Packet - Source:86.136.155.171,52236 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:22:17 - TCP Packet - Source:203.214.54.135,2308 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:22:22 - TCP Packet - Source:86.20.238.136,1531 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:22:23 - TCP Packet - Source:83.100.138.219,2767 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:22:25 - TCP Packet - Source:86.20.238.136,1531 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:22:25 - TCP Packet - Source:82.17.166.254,61780 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:22:47 - TCP Packet - Source:80.47.158.136,3812 Destination:80.47.76.239,139 - [DOS]
Sat, 2007-03-17 14:22:49 - TCP Packet - Source:85.24.236.30,1826 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:22:52 - TCP Packet - Source:88.218.52.114,4758 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:02 - TCP Packet - Source:85.207.190.42,4530 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:02 - TCP Packet - Source:80.47.133.138,3629 Destination:80.47.76.239,135 - [DOS]
Sat, 2007-03-17 14:23:02 - TCP Packet - Source:90.193.225.180,4989 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:03 - TCP Packet - Source:82.17.166.254,63430 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:03 - TCP Packet - Source:71.79.43.161,3466 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:04 - TCP Packet - Source:83.6.102.196,1434 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:06 - TCP Packet - Source:82.17.166.254,63430 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:08 - TCP Packet - Source:212.54.217.161,1402 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:08 - TCP Packet - Source:90.193.225.180,4989 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:09 - TCP Packet - Source:88.104.167.34,4326 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:09 - TCP Packet - Source:81.56.157.100,3268 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:12 - TCP Packet - Source:71.79.43.161,3466 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:12 - TCP Packet - Source:172.215.104.11,1400 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:16 - TCP Packet - Source:86.136.155.171,52419 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:18 - TCP Packet - Source:72.38.228.214,61557 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:21 - TCP Packet - Source:67.55.26.165,64891 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:27 - TCP Packet - Source:193.77.178.66,4612 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:23:29 - TCP Packet - Source:80.47.167.77,4031 Destination:80.47.76.239,135 - [DOS]
Sat, 2007-03-17 14:23:29 - TCP Packet - Source:85.91.133.46,4673 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:30 - TCP Packet - Source:193.77.178.66,4612 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:23:32 - TCP Packet - Source:80.143.159.157,2009 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:35 - TCP Packet - Source:85.91.133.46,4673 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:23:36 - TCP Packet - Source:193.77.178.66,4612 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:24:14 - TCP Packet - Source:80.192.180.76,4682 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:24:19 - TCP Packet - Source:88.104.130.164,3909 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:24:23 - TCP Packet - Source:80.192.180.76,4682 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:24:54 - TCP Packet - Source:82.29.45.225,64427 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:02 - TCP Packet - Source:91.95.221.42,54514 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:03 - TCP Packet - Source:75.118.1.176,61194 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:03 - TCP Packet - Source:69.158.108.41,3385 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:05 - TCP Packet - Source:212.139.193.105,1291 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:06 - TCP Packet - Source:80.98.225.194,4486 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:08 - TCP Packet - Source:212.139.193.105,1291 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:08 - TCP Packet - Source:86.155.14.134,51646 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:09 - TCP Packet - Source:71.81.28.82,2351 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:10 - TCP Packet - Source:82.181.149.71,63334 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:11 - TCP Packet - Source:80.47.181.242,4946 Destination:80.47.76.239,135 - [DOS]
Sat, 2007-03-17 14:25:13 - TCP Packet - Source:82.181.149.71,63334 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:14 - TCP Packet - Source:74.70.100.246,2618 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:15 - TCP Packet - Source:85.164.121.57,62790 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:25:57 - TCP Packet - Source:86.133.65.72,3216 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:26:12 - TCP Packet - Source:71.231.219.208,3619 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:27:00 - TCP Packet - Source:193.77.178.66,4847 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:28:56 - TCP Packet - Source:74.99.54.197,1041 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:30:11 - TCP Packet - Source:194.125.54.237,25392 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:30:13 - TCP Packet - Source:121.45.213.48,3401 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:01 - TCP Packet - Source:83.29.26.229,2605 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:32:23 - TCP Packet - Source:193.151.115.13,49422 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:23 - TCP Packet - Source:83.21.86.136,3238 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:25 - TCP Packet - Source:220.233.160.244,35022 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:52 - TCP Packet - Source:85.210.39.84,4986 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:55 - TCP Packet - Source:69.158.108.41,3523 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:57 - TCP Packet - Source:80.47.18.49,3816 Destination:80.47.76.239,135 - [DOS]
Sat, 2007-03-17 14:32:57 - TCP Packet - Source:172.200.187.227,4275 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:32:58 - TCP Packet - Source:77.99.50.147,2924 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:33:01 - TCP Packet - Source:74.99.54.197,1420 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:33:51 - TCP Packet - Source:83.29.26.229,2727 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:36:19 - TCP Packet - Source:83.25.235.203,3686 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:37:51 - TCP Packet - Source:83.30.25.62,2492 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:37:52 - TCP Packet - Source:74.111.220.219,61659 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:37:54 - TCP Packet - Source:86.143.195.243,55453 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:37:54 - TCP Packet - Source:83.30.25.62,2492 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:38:37 - TCP Packet - Source:86.133.65.72,4067 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:39:36 - TCP Packet - Source:86.136.102.225,50022 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:39:36 - TCP Packet - Source:80.54.127.18,1381 Destination:80.47.76.239,46879 - [DOS]
Sat, 2007-03-17 14:41:03 - TCP Packet - Source:74.99.54.197,2127 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:42:26 - TCP Packet - Source:71.231.219.208,4770 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:48:22 - TCP Packet - Source:84.169.178.107,1720 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:48:41 - TCP Packet - Source:193.77.178.66,2191 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:57:04 - TCP Packet - Source:71.231.219.208,1840 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 14:59:16 - TCP Packet - Source:84.169.178.107,2373 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 15:06:54 - TCP Packet - Source:84.169.178.107,2893 Destination:192.168.0.4,35628 - [utor1 match]
Sat, 2007-03-17 16:27:42 - Administrator login successful - IP:192.168.0.3
Sat, 2007-03-17 16:33:03 - Administrator login successful - IP:192.168.0.3

I have no idea about internet security, windows firewall is switched on on both machines but that's all.

Router is a Netgear DG834GT.

Can someone explain what happened and how I stop it?

Cheers in advance.

Smiler.

11,752 posts

231 months

Saturday 17th March 2007
quotequote all
Is your router locked, i.e. do you have to enter a passwword to connect?

dave_s13

Original Poster:

13,816 posts

270 months

Saturday 17th March 2007
quotequote all
Yeah but it was set to the default admin/password.

Just changed the password.

Smiler.

11,752 posts

231 months

Saturday 17th March 2007
quotequote all
No, I meant the WEP access key.

With your mouse behaving odly, it sounds like remote assistance has been enabled.

Sounds like a hack.

What is your setup, PC, router connection, wireless etc.

dave_s13

Original Poster:

13,816 posts

270 months

Saturday 17th March 2007
quotequote all
I've got WPA-PSK enabled.

Router is a netgear dg834gt
PC with wired ethernet link (windows XP) this has remote assist enabled.
Laptop (win XP) wireless link this had remote assist on but just turned it off
xbox 360 wired ethernet
Pinnacle Stream Center wired ethernet.

SneakyNeil

9,243 posts

238 months

Saturday 17th March 2007
quotequote all
Seeing lots of stuff like that in the router logs is 100% normal, that in it's self doesn't mean anything. Also, not unusual for the mouse cursor to move by it's self with optical mice.

BliarOut

72,857 posts

240 months

Saturday 17th March 2007
quotequote all
DOS=Denial Of Service attack. Looks like a load of compromised machines were pointed at your router. Make sure remote (WAN) management is turned off on the router.