hi guys, got a big favour to ask the people in the know please.got major problems with people listening in to my pc.other day coudnt get in my belkin router as password kept changing,weird or what.spoke to belkin explained and also told them router was dropping dynamic connection,something as you well know it should never do as its always on.used to play a game called comanche 4 as i expliained in my introduction letter.i believe the idiots i used to play with a responsible for this,or atleast partiually.problems only startedoccuring after i went back to this game,silly me.coomon demoniator in this case is obviously the game.ive also got people listening in on my pc connection.got active ports and its reporting various ips being active and listening to my pc.none of the stemming form active programs or processes i know of.enclosed is my hijack this file.can some don have a look at it see whats going on and get back to me say situation is grave is an understatement.this ip keeps connecting to my pc!,among others.anyone recognise it? gonna tracert back to soource later and report as abuse to its isp.about all i can do.some please help.situation has become ridiculous and is totally beyond my pc skills to resolve.many many thanks to those that can help.and a big shout out to the rest of ya all.peace.log file attached.

Dani AI

Generated

A concise triage and action plan based on the thread: reports intermittent router/admin access issues and suspicious incoming connections; noted the HijackThis log looked clean, which helps but does not rule out router compromise, firmware/backdoor issues, or kernel/rootkit infection. Prioritize isolating the problem, collecting evidence, and securing the network before assuming other players are responsible.

  1. Immediate isolation and evidence capture
  • Disconnect the affected PC from the network (use an Ethernet unplug or disable the adapter) and preserve copies of logs (router event log, DHCP leases) and the system netstat/process lists.
  • From an unaffected machine, do a traceroute and note timestamps for any suspicious remote IPs before reporting to the ISP.
  1. Router hardening (do these offline if possible)
  • Factory-reset the router, then immediately change the admin password to a strong unique passphrase.
  • Disable remote/WAN administration, Telnet/SSH, UPnP and WPS.
  • Update router firmware from the vendor site, then reconfigure with WPA2/3 (AES) if wireless is used and a new WPA passphrase. If compromise is suspected and firmware can be OEM-compromised, consider replacing the unit.
  1. PC-level clean-up and verification
  • Boot into Safe Mode (or use a clean rescue USB) and run up-to-date antivirus and anti-malware scans (full disk + rootkit checks).
  • Collect running connections and binaries:
    netstat -anb > c:\netstat.txt
    tasklist /svc > c:\tasklist.txt
    tracert <suspicious-ip> > c:\tracert.txt
  • If malware or rootkits are found, plan a clean OS reinstall after backing up personal data.
  1. Reporting and next steps
  • If traceroute/whois places the remote host outside the LAN, contact the remote ISP/abuse desk with timestamps and logs. Preserve evidence and avoid reusing compromised credentials. If uncertainty remains, replacing the router and performing a clean OS install are the most reliable ways to eliminate hidden compromises.

Note: game traffic and P2P-style connections can explain some “active ports” — collect the logs above before drawing conclusions about targeted intrusion.

Recommended Answers

All 3 Replies

Hmm, I don't see anything wrong with the log.
Are ya still having problems?

Also, next time ya post a log, copy/paste it into the body of the message, don't enclose it as an attachment.

Thanks.

hi all, thanks jay for the reply.yes still having problems unforunately.did some reading on hacking on the net.seems with the right tools its very easy tobreak into someones router or pc and be able to view encrypted files and passwords.needless to say there is nothing i or i figure anyone can do about that.all this does is make me more determined to restart my msce engineering course.hopefully then ateast i will be better armed to prevent some hackers.good thing you replied as i deleted all replies in my hotmail without saving one and didnt know the adress for this site anyone can give me tips on how to stop this kind of hacking please do.but from scenarios ive read theres very little hope stopping someone telnetting my system and decodind passwords.like i said least its made me find out and read up more.have a good weekend all.damn missed the well gonna have to win it on wednesday instead.lmao.best wishes to every 1. :cool:

Haha ya better win the lottery,, but ya, I'm sorry I couldnt help ya.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.