Tada, I've been hacked!

fury

Administrator
Staff member
For the second time within a month!

And the owner of the IP address, according to netstat at the time, 10.0.0.7 is to blame! Of course, seeing as how that's a private IP address, there is no doubt the guy spoofed it.

ZoneAlarm never detected a thing, but I sure did.

I noticed the tone of my computer's fan droning had changed, indicating a load shift. I checked Task Manager, and there was an odd process with no name (a space) eating up 80% CPU. So when I went to right click and kill it, my mouse pointer moved away from the task manager window! I immediately closed all my windows, ripped the phone cord out of the modem, and TADA, the process no longer took 80% CPU. I killed it with extreme prejudice.

It appears that they have screwed up my Explorer settings, for I do not see a boot.ini, ntldr, or ntdetect.com in C:\ when I browse with explorer, however they are there when viewing through cmd.exe.

They were pretty much pros at erasing their tracks, because I don't have an Event Viewer section under System Tools (My Computer\Manage...), and the files for AppEvent, SecurityEvent, SysEvent are all 0 bytes.

I did however, have a user account with a login, name, and description all reading "fury" who was a member of the following groups: Administrators, Backup Operators, Power Users, Replicator, User.

Now, I don't even recall adding a user account for fury (I log in as Administrator all the time), let alone do I lack as much common sense as to add myself to every group when I know very well just being in Administrators covers them all.

I have had all Service Pack, Critical Update, Intensive Care Update, Rollup, Rolldown, Rollingonthefloorlaughing, and Stopdropandroll packages installed that I could find for Win2k, so apparently there's still issues MS doesn't know about.

I cannot get to symantec.com, mcafee.com, networksolutions.com (they all resolve to the IP address 10.0.0.7 :rolleyes: ) but I did manage to get to PCPitstop.com but, expectedly, it did not find a thing, as it never does when I actually need it!

I checked services and found nothing out of the ordinary.

What else is there to check? Not that there'll be much point to it, since I'm going to install Linux as soon as I get a hardware modem... screw this being hacked all the time!

:mad: :mad: :mad: :mad: :mad: :mad: :mad:
 
S

s4

Guest
You should be able to find a good deal on a hardware modem. I once had a Newcom hardware modem installed, and it worked great, hence a USR or the most expensive is not necessarily your best bet.

If your phone line doesn't allow for a decent 56k connection as we talked about before, you might consider a hardware 33.6 modem. They are pretty inexpensive.

Pricewatch.com lists some pretty good deals on modems.
 

fury

Administrator
Staff member
Thanks for your response. The phone line does 56k, and I've heard that a quality hardware modem makes for the fastest and most stable connect speeds, and lowest CPU usage. Quality hardware modems generally fall under 3com or USR brand names.

So I guess what I'm really asking is does anyone know if getting a USR Model 2977 (Hardware-controller) modem would be a good choice? It can be had for $37 + shipping online, or if a 3com 5687 (also hardware-controlled) at $29 + shipping online would be just as good?

Or are there any other recommendations out there?
 
S

s4

Guest
Here is a link to a refurbished Zoom 56k external modem that connects to the serial port. Not a bad price at $24.95. I had one of these modems a couple of years ago. It was not bad.

http://www.softwareandstuff.com/h.zoom2949.html

I recommend the USR 5686 external if you can find a good deal on one. The other day I saw it for $38, but I think those are sold out now. I use this particular one every day and get good download speeds. This modem is not one I would recommend for gaming though.
 

fury

Administrator
Staff member
Gaming? On dialup? :rofl:

I'd rather not have to deal with refurbished products... bad memories... I think I'll take a look at pricewatch and see what that modem is as new...

Thanks bubba :)
 

Kruz

Moderator
Staff member
MusicCity Networks could not be contacted for comment.
It seems that the people at Morpheus are denying everything.
 

Attachments

  • morpheus.jpg
    morpheus.jpg
    104.2 KB · Views: 35

greenfreak

New Member
Fury, is your account with Morpheus under 'fury' also? Obviously they found that name from somewhere. Or is your computer name fury or something?
 

fury

Administrator
Staff member
My morpheus account is Flurffmeister since fury was already taken, but I have the name fury plastered all over my computer.
 
Top