|
Prev: New connection appeared, is it a virus
Next: WPA PSK
From: Sirtokalott on 12 Apr 2008 23:53 I use Live Messenger and a file sent to me was blocked. I have a wireless adapter and connect to my neighbours router (yes she gave me the access code) and I ussualy have a wireless connection logo in the system tray. When I started up the pc the other night I had an extra icon showing a cable connection to another computer. I also now have a modem installed in device manager. I think it is my neighbours computer which I am connecting to but aint to sure as neither of us is experts. The pc is also running much slower now. I'd love to know of anyway of identifying a deliberate attack from someone. Here's what the modem log says. 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\tapisrv.dll, Version 5.1.2600 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdm.tsp, Version 5.1.2600 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdmat.dll, Version 5.1.2600 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\uniplat.dll, Version 5.1.2600 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\drivers\modem.sys, Version 5.1.2600 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\modemui.dll, Version 5.1.2600 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\mdminst.dll, Version 5.1.2600 04-06-2008 21:59:19.421 - Modem type: Communications cable between two computers 04-06-2008 21:59:19.421 - Modem inf path: mdmhayes.inf 04-06-2008 21:59:19.421 - Modem inf section: M2700 04-06-2008 21:59:19.421 - Matching hardware ID: pnpc031 04-06-2008 21:59:19.453 - 19200,8,N,1, ctsfl=1, rtsctl=2 04-06-2008 21:59:19.453 - Initializing modem. 04-06-2008 21:59:19.453 - Waiting for a call. 04-06-2008 21:59:19.484 - 19200,8,N,1, ctsfl=1, rtsctl=2 04-06-2008 21:59:19.484 - Initializing modem. 04-06-2008 21:59:19.484 - Dialing. 04-06-2008 21:59:19.500 - Send: CLIENT 04-06-2008 21:59:21.500 - Timed out waiting for response from modem 04-06-2008 21:59:21.500 - Failed to send command because of WriteFile() Failure, Error=000003e3. 04-06-2008 21:59:21.515 - Send: CLIENT 04-06-2008 21:59:23.515 - Timed out waiting for response from modem 04-06-2008 21:59:23.515 - Failed to send command because of WriteFile() Failure, Error=000003e3. 04-06-2008 21:59:23.531 - Send: CLIENT 04-06-2008 21:59:25.531 - Timed out waiting for response from modem 04-06-2008 21:59:25.531 - Failed to send command because of WriteFile() Failure, Error=000003e3. 04-06-2008 21:59:25.546 - Send: CLIENT 04-06-2008 21:59:27.546 - Timed out waiting for response from modem 04-06-2008 21:59:27.546 - Failed to send command because of WriteFile() Failure, Error=000003e3. 04-06-2008 21:59:27.546 - Hanging up the modem. 04-06-2008 21:59:27.546 - Hardware hangup by lowering DTR. 04-06-2008 21:59:29.546 - A timeout has expired waiting to comm event to occour. 04-06-2008 21:59:29.546 - 19200,8,N,1, ctsfl=1, rtsctl=2 04-06-2008 21:59:29.546 - Initializing modem. 04-06-2008 21:59:29.546 - Waiting for a call. 04-06-2008 21:59:29.546 - Session Statistics: 04-06-2008 21:59:29.546 - Reads : 0 bytes 04-06-2008 21:59:29.546 - Writes: 0 bytes I certainly didn't set this up, please help
From: Joan Archer on 13 Apr 2008 08:04 Why do you feel the need to ask the same question three times within half an hour. You would be better helped by waiting until someone who has the knowledge to help sees your post and can answer, don't forget that we are all volunteers here from all parts of the globe so whoever can help with your problem may not even be out of bed yet or they may be enjoying the weekend. Just wait at least 24 hours before posting the same message again. -- Joan Archer http://www.freewebs.com/crossstitcher http://lachsoft.com/photogallery "Sirtokalott" <Sirtokalott(a)discussions.microsoft.com> wrote in message news:5885AFAA-D80A-4216-BD15-A3D34C7219B0(a)microsoft.com... > I use Live Messenger and a file sent to me was blocked. I have a wireless > adapter and connect to my neighbours router (yes she gave me the access > code) > and I ussualy have a wireless connection logo in the system tray. When I > started up the pc the other night I had an extra icon showing a cable > connection to another computer. I also now have a modem installed in > device > manager. I think it is my neighbours computer which I am connecting to > but > aint to sure as neither of us is experts. The pc is also running much > slower > now. I'd love to know of anyway of identifying a deliberate attack from > someone. Here's what the modem log says. > > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\tapisrv.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdm.tsp, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdmat.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\uniplat.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\drivers\modem.sys, > Version 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\modemui.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\mdminst.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - Modem type: Communications cable between two > computers > 04-06-2008 21:59:19.421 - Modem inf path: mdmhayes.inf > 04-06-2008 21:59:19.421 - Modem inf section: M2700 > 04-06-2008 21:59:19.421 - Matching hardware ID: pnpc031 > 04-06-2008 21:59:19.453 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:19.453 - Initializing modem. > 04-06-2008 21:59:19.453 - Waiting for a call. > 04-06-2008 21:59:19.484 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:19.484 - Initializing modem. > 04-06-2008 21:59:19.484 - Dialing. > 04-06-2008 21:59:19.500 - Send: CLIENT > 04-06-2008 21:59:21.500 - Timed out waiting for response from modem > 04-06-2008 21:59:21.500 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:21.515 - Send: CLIENT > 04-06-2008 21:59:23.515 - Timed out waiting for response from modem > 04-06-2008 21:59:23.515 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:23.531 - Send: CLIENT > 04-06-2008 21:59:25.531 - Timed out waiting for response from modem > 04-06-2008 21:59:25.531 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:25.546 - Send: CLIENT > 04-06-2008 21:59:27.546 - Timed out waiting for response from modem > 04-06-2008 21:59:27.546 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:27.546 - Hanging up the modem. > 04-06-2008 21:59:27.546 - Hardware hangup by lowering DTR. > 04-06-2008 21:59:29.546 - A timeout has expired waiting to comm event to > occour. > 04-06-2008 21:59:29.546 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:29.546 - Initializing modem. > 04-06-2008 21:59:29.546 - Waiting for a call. > 04-06-2008 21:59:29.546 - Session Statistics: > 04-06-2008 21:59:29.546 - Reads : 0 bytes > 04-06-2008 21:59:29.546 - Writes: 0 bytes > > I certainly didn't set this up, please help
From: Sooner Al [MVP] on 13 Apr 2008 08:19 First and foremost if you think you have been hacked disconnect from the internet and your network immediately. This FAQ from the BBR Security forum has steps you can take to help fix the issue. http://www.dslreports.com/faq/8428 Of course the fix of last resort is to do a clean install of your OS. Drastic but effective. Beyond all of that I suggest you install and run a good anti-virus program (AVG is free for personal use), Windows Defender (free anti-spyware software from MSFT) and certainly run a software firewall. The Windows Firewall is built-in to XP and is one option. http://free.grisoft.com/ http://www.microsoft.com/athome/security/spyware/software/default.mspx http://www.microsoft.com/windowsxp/using/networking/security/winfirewall.mspx I suggest configuring the Windows Firewall for "Don't allow exceptions". See the latter part of this page. http://theillustratednetwork.mvps.org/LAN/SoHoWirelessSecurity.html -- Al Jarvi (MS-MVP Windows – Desktop User Experience) Please post *ALL* questions and replies to the news group for the mutual benefit of all of us... The MS-MVP Program - http://mvp.support.microsoft.com This posting is provided "AS IS" with no warranties, and confers no rights... How to ask a question http://support.microsoft.com/KB/555375 "Sirtokalott" <Sirtokalott(a)discussions.microsoft.com> wrote in message news:5885AFAA-D80A-4216-BD15-A3D34C7219B0(a)microsoft.com... >I use Live Messenger and a file sent to me was blocked. I have a wireless > adapter and connect to my neighbours router (yes she gave me the access > code) > and I ussualy have a wireless connection logo in the system tray. When I > started up the pc the other night I had an extra icon showing a cable > connection to another computer. I also now have a modem installed in > device > manager. I think it is my neighbours computer which I am connecting to > but > aint to sure as neither of us is experts. The pc is also running much > slower > now. I'd love to know of anyway of identifying a deliberate attack from > someone. Here's what the modem log says. > > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\tapisrv.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdm.tsp, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdmat.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\uniplat.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\drivers\modem.sys, > Version 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\modemui.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\mdminst.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - Modem type: Communications cable between two > computers > 04-06-2008 21:59:19.421 - Modem inf path: mdmhayes.inf > 04-06-2008 21:59:19.421 - Modem inf section: M2700 > 04-06-2008 21:59:19.421 - Matching hardware ID: pnpc031 > 04-06-2008 21:59:19.453 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:19.453 - Initializing modem. > 04-06-2008 21:59:19.453 - Waiting for a call. > 04-06-2008 21:59:19.484 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:19.484 - Initializing modem. > 04-06-2008 21:59:19.484 - Dialing. > 04-06-2008 21:59:19.500 - Send: CLIENT > 04-06-2008 21:59:21.500 - Timed out waiting for response from modem > 04-06-2008 21:59:21.500 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:21.515 - Send: CLIENT > 04-06-2008 21:59:23.515 - Timed out waiting for response from modem > 04-06-2008 21:59:23.515 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:23.531 - Send: CLIENT > 04-06-2008 21:59:25.531 - Timed out waiting for response from modem > 04-06-2008 21:59:25.531 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:25.546 - Send: CLIENT > 04-06-2008 21:59:27.546 - Timed out waiting for response from modem > 04-06-2008 21:59:27.546 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:27.546 - Hanging up the modem. > 04-06-2008 21:59:27.546 - Hardware hangup by lowering DTR. > 04-06-2008 21:59:29.546 - A timeout has expired waiting to comm event to > occour. > 04-06-2008 21:59:29.546 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:29.546 - Initializing modem. > 04-06-2008 21:59:29.546 - Waiting for a call. > 04-06-2008 21:59:29.546 - Session Statistics: > 04-06-2008 21:59:29.546 - Reads : 0 bytes > 04-06-2008 21:59:29.546 - Writes: 0 bytes > > I certainly didn't set this up, please help
From: Sooner Al [MVP] on 13 Apr 2008 08:25 I forgot to add that you really should normally login as a "limited user" versus a user with administrator permissions. Only use an account with administrator permissions for system maintenance tasks, etc. I do that on my Vista Ultimate laptop and my wife does that on her XP Pro desktop. In fact she does even know the administrator account user password for her PC. Most maintenance, configuration, etc tasks can be run using "Run as..." on an XP box. With Vista its even easier because of the UAC popup. -- Al Jarvi (MS-MVP Windows – Desktop User Experience) Please post *ALL* questions and replies to the news group for the mutual benefit of all of us... The MS-MVP Program - http://mvp.support.microsoft.com This posting is provided "AS IS" with no warranties, and confers no rights... How to ask a question http://support.microsoft.com/KB/555375 "Sooner Al [MVP]" <SoonerAl(a)somewhere.net.invalid> wrote in message news:700C2913-638A-47E7-8419-26289CA42568(a)microsoft.com... > First and foremost if you think you have been hacked disconnect from the > internet and your network immediately. This FAQ from the BBR Security > forum has steps you can take to help fix the issue. > > http://www.dslreports.com/faq/8428 > > Of course the fix of last resort is to do a clean install of your OS. > Drastic but effective. > > Beyond all of that I suggest you install and run a good anti-virus program > (AVG is free for personal use), Windows Defender (free anti-spyware > software from MSFT) and certainly run a software firewall. The Windows > Firewall is built-in to XP and is one option. > > http://free.grisoft.com/ > > http://www.microsoft.com/athome/security/spyware/software/default.mspx > > http://www.microsoft.com/windowsxp/using/networking/security/winfirewall.mspx > > I suggest configuring the Windows Firewall for "Don't allow exceptions". > See the latter part of this page. > > http://theillustratednetwork.mvps.org/LAN/SoHoWirelessSecurity.html > > -- > > Al Jarvi (MS-MVP Windows – Desktop User Experience) > > Please post *ALL* questions and replies to the news group for the > mutual benefit of all of us... > The MS-MVP Program - http://mvp.support.microsoft.com > This posting is provided "AS IS" with no warranties, and confers no > rights... > How to ask a question > http://support.microsoft.com/KB/555375 > > "Sirtokalott" <Sirtokalott(a)discussions.microsoft.com> wrote in message > news:5885AFAA-D80A-4216-BD15-A3D34C7219B0(a)microsoft.com... >>I use Live Messenger and a file sent to me was blocked. I have a wireless >> adapter and connect to my neighbours router (yes she gave me the access >> code) >> and I ussualy have a wireless connection logo in the system tray. When I >> started up the pc the other night I had an extra icon showing a cable >> connection to another computer. I also now have a modem installed in >> device >> manager. I think it is my neighbours computer which I am connecting to >> but >> aint to sure as neither of us is experts. The pc is also running much >> slower >> now. I'd love to know of anyway of identifying a deliberate attack from >> someone. Here's what the modem log says. >> >> 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\tapisrv.dll, Version >> 5.1.2600 >> 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdm.tsp, Version >> 5.1.2600 >> 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdmat.dll, Version >> 5.1.2600 >> 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\uniplat.dll, Version >> 5.1.2600 >> 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\drivers\modem.sys, >> Version 5.1.2600 >> 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\modemui.dll, Version >> 5.1.2600 >> 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\mdminst.dll, Version >> 5.1.2600 >> 04-06-2008 21:59:19.421 - Modem type: Communications cable between two >> computers >> 04-06-2008 21:59:19.421 - Modem inf path: mdmhayes.inf >> 04-06-2008 21:59:19.421 - Modem inf section: M2700 >> 04-06-2008 21:59:19.421 - Matching hardware ID: pnpc031 >> 04-06-2008 21:59:19.453 - 19200,8,N,1, ctsfl=1, rtsctl=2 >> 04-06-2008 21:59:19.453 - Initializing modem. >> 04-06-2008 21:59:19.453 - Waiting for a call. >> 04-06-2008 21:59:19.484 - 19200,8,N,1, ctsfl=1, rtsctl=2 >> 04-06-2008 21:59:19.484 - Initializing modem. >> 04-06-2008 21:59:19.484 - Dialing. >> 04-06-2008 21:59:19.500 - Send: CLIENT >> 04-06-2008 21:59:21.500 - Timed out waiting for response from modem >> 04-06-2008 21:59:21.500 - Failed to send command because of WriteFile() >> Failure, Error=000003e3. >> 04-06-2008 21:59:21.515 - Send: CLIENT >> 04-06-2008 21:59:23.515 - Timed out waiting for response from modem >> 04-06-2008 21:59:23.515 - Failed to send command because of WriteFile() >> Failure, Error=000003e3. >> 04-06-2008 21:59:23.531 - Send: CLIENT >> 04-06-2008 21:59:25.531 - Timed out waiting for response from modem >> 04-06-2008 21:59:25.531 - Failed to send command because of WriteFile() >> Failure, Error=000003e3. >> 04-06-2008 21:59:25.546 - Send: CLIENT >> 04-06-2008 21:59:27.546 - Timed out waiting for response from modem >> 04-06-2008 21:59:27.546 - Failed to send command because of WriteFile() >> Failure, Error=000003e3. >> 04-06-2008 21:59:27.546 - Hanging up the modem. >> 04-06-2008 21:59:27.546 - Hardware hangup by lowering DTR. >> 04-06-2008 21:59:29.546 - A timeout has expired waiting to comm event to >> occour. >> 04-06-2008 21:59:29.546 - 19200,8,N,1, ctsfl=1, rtsctl=2 >> 04-06-2008 21:59:29.546 - Initializing modem. >> 04-06-2008 21:59:29.546 - Waiting for a call. >> 04-06-2008 21:59:29.546 - Session Statistics: >> 04-06-2008 21:59:29.546 - Reads : 0 bytes >> 04-06-2008 21:59:29.546 - Writes: 0 bytes >> >> I certainly didn't set this up, please help >
From: Lem on 13 Apr 2008 15:14
Sirtokalott wrote: > I use Live Messenger and a file sent to me was blocked. I have a wireless > adapter and connect to my neighbours router (yes she gave me the access code) > and I ussualy have a wireless connection logo in the system tray. When I > started up the pc the other night I had an extra icon showing a cable > connection to another computer. I also now have a modem installed in device > manager. I think it is my neighbours computer which I am connecting to but > aint to sure as neither of us is experts. The pc is also running much slower > now. I'd love to know of anyway of identifying a deliberate attack from > someone. Here's what the modem log says. > > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\tapisrv.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdm.tsp, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\unimdmat.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.375 - File: C:\WINDOWS\system32\uniplat.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\drivers\modem.sys, > Version 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\modemui.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - File: C:\WINDOWS\system32\mdminst.dll, Version > 5.1.2600 > 04-06-2008 21:59:19.421 - Modem type: Communications cable between two > computers > 04-06-2008 21:59:19.421 - Modem inf path: mdmhayes.inf > 04-06-2008 21:59:19.421 - Modem inf section: M2700 > 04-06-2008 21:59:19.421 - Matching hardware ID: pnpc031 > 04-06-2008 21:59:19.453 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:19.453 - Initializing modem. > 04-06-2008 21:59:19.453 - Waiting for a call. > 04-06-2008 21:59:19.484 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:19.484 - Initializing modem. > 04-06-2008 21:59:19.484 - Dialing. > 04-06-2008 21:59:19.500 - Send: CLIENT > 04-06-2008 21:59:21.500 - Timed out waiting for response from modem > 04-06-2008 21:59:21.500 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:21.515 - Send: CLIENT > 04-06-2008 21:59:23.515 - Timed out waiting for response from modem > 04-06-2008 21:59:23.515 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:23.531 - Send: CLIENT > 04-06-2008 21:59:25.531 - Timed out waiting for response from modem > 04-06-2008 21:59:25.531 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:25.546 - Send: CLIENT > 04-06-2008 21:59:27.546 - Timed out waiting for response from modem > 04-06-2008 21:59:27.546 - Failed to send command because of WriteFile() > Failure, Error=000003e3. > 04-06-2008 21:59:27.546 - Hanging up the modem. > 04-06-2008 21:59:27.546 - Hardware hangup by lowering DTR. > 04-06-2008 21:59:29.546 - A timeout has expired waiting to comm event to > occour. > 04-06-2008 21:59:29.546 - 19200,8,N,1, ctsfl=1, rtsctl=2 > 04-06-2008 21:59:29.546 - Initializing modem. > 04-06-2008 21:59:29.546 - Waiting for a call. > 04-06-2008 21:59:29.546 - Session Statistics: > 04-06-2008 21:59:29.546 - Reads : 0 bytes > 04-06-2008 21:59:29.546 - Writes: 0 bytes > > I certainly didn't set this up, please help How can you *not* know whether or not you have a wire connected to your computer? -- Lem -- MS-MVP To the moon and back with 2K words of RAM and 36K words of ROM. http://en.wikipedia.org/wiki/Apollo_Guidance_Computer http://history.nasa.gov/afj/compessay.htm |