hello all, my hacker problems are very serious indeed.need help big time! im going insane here! ,ip has been in my pc showed by active ports program.seems to hae installed devices on my pc.cant use my wirless mouse anymore for some reason.gonna uninstall o/s and start again grr!this is beyond a joke.cant seem to find who the is even to report this intrusion to their isp.please help.this is way beyond me and im getting very annoyed from the fact some 1 seems to have complete control over my pc!i put the mouse on my other pc works fine.please,please,please any of you can find out where this akami are and what isp then atleast i can contact them and ask them to stop this fool.please any need of it real bad.thanks!best wishes.
the underdog 0 Newbie Poster
Dani AI
Generated
Quick summary for future readers: noticed a recurring remote host in connection lists and feared a takeover; suggested contacting the host’s abuse contact and checking logs, and the OP later found the traffic was from legitimate update/CDN services. That outcome is common — many update and CDN endpoints will show up in connection tools and in netstat. Below is a short, practical checklist to tell “normal” from “bad” and what to do if you still suspect compromise.
TCP states in plain words: TIME_WAIT is normally just a socket waiting to finish a closed conversation — transient, not proof of remote control. LISTENING means a local program is accepting incoming connections. ESTABLISHED means an active two‑way session. To map connections to a process on Windows, run these commands (as admin):
netstat -ano
tasklist /FI "PID eq <pid>" Or use netstat -b/-bn (admin) to show the executable that opened the socket. If the PID belongs to a known updater, antivirus or messenger, that explains many “mystery” connections. If it points at an unknown EXE, investigate the file path and digital signature before trusting it.
Practical next steps: check reverse DNS/whois for the remote IP to see the owner, capture a short packet trace to inspect HTTP headers or TLS certs, scan the machine with current anti‑malware (use offline rescue media if needed), and review startup items with msconfig or Autoruns. If you find a confirmed malicious process, isolate the PC, collect logs, report to the host/ISP abuse contact, change critical passwords from a clean device, and reimage if remediation fails. Peripheral problems (drivers, radio interference) are usually unrelated to network connections — verify hardware on another machine before assuming an intrusion. Credit to for the reporting suggestion and to for the case that produced this checklist.
Recommended Answers
Jump to Post— D3m3nt3d 1The ISP is out of Great Britian. Even though a specific ISP is not listed, but instead it points to ADSL endpoints, if you suspect your PC has been compromised from the IP Address that you listed, you should email as well as …
Jump to Post— D3m3nt3d 1Are you from the UK by chance? Running ADSL endpoints for NAT connectivity is nothing unusual there. Are you on any specific sites when you get these alerts?
You can attach a HijackThis log and we can see if anything looks suspicious or not.
Jump to Post— D3m3nt3d 1No problem Mike :)
Glad I could help.
All 12 Replies
D3m3nt3d 1 Posting Whiz in Training
The ISP is out of Great Britian. Even though a specific ISP is not listed, but instead it points to ADSL endpoints, if you suspect your PC has been compromised from the IP Address that you listed, you should email as well as
the underdog 0 Newbie Poster
hi, thanks for the response! not sure if my pc been compromised or not.all i know is this is always on time wait state on ports 1000 to 1090 and ports 80 aswell.i recently did online ports check with shields ip and have stealthed only port closed,113 pc is now fully you think this ip in question is just trying to put my connection out of service?and could some one also explain the time wait status thing to me please.thanks very muchbbest wishes to everyone.try shields up site guys.good port scan site.
D3m3nt3d 1 Posting Whiz in Training
Are you from the UK by chance? Running ADSL endpoints for NAT connectivity is nothing unusual there. Are you on any specific sites when you get these alerts?
You can attach a HijackThis log and we can see if anything looks suspicious or not.
the underdog 0 Newbie Poster
hi, yes om in the uk.cant think of any specific sites i go on.i know i fell out with alot of modifiers on a game.they used to try to remotely connect to my pc alot.i believe may be one of them.ports 1000-2000 are commonly used trojan ports.need to know if time wait state in active ports programs means theyve mangaged to connect and also what listening state is.like i said my pc is fully stealthed including port 113 ident.many thanks man in advanvce.btw nice to meet ya and thanks for helping me out dude.what goes around comes around.best :) ke.
D3m3nt3d 1 Posting Whiz in Training
No problem Mike :)
Glad I could help.
the underdog 0 Newbie Poster
hi dude, ok major problemo, the ip a gave you belonging to has now been connecting through msn.exe! please help! all my drivers have seemed to beeen messed up.reported to his any my isp but need some you know how to terminate active connnections vis dos command.this idiot is even making terminating his connection via active ports program hard.thanks dude.sorry to be a pain,but im under siege!many thanks.wil post hijack this log file too.god knows how hes doing this ,like i said my pc is completley stealthed even though he has my ip.and even when i changed modem to usb from ethernet releasing the ip to a new one as soon as i started the pc again low and behold mr idiot was on time wait.cheers.best wishes to you again .mike.
the underdog 0 Newbie Poster
hi again! lol!,heres the hijack this file as promised.got 2 pcs so i will send you both.you wanted to help! lol.really appreciate man.by the way,where you from im from kent england we have a saying for the idiot who causing me these call them friggin muppets.sorry had to try to break my frustration with small talk.lol.thanks in advance.log file below.mike.
Logfile of HijackThis v1.99.1
Scan saved at 22:37:50, on 27/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /play
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
the underdog 0 Newbie Poster
hi dude,2nd pc hijack this file.cheers gonna go out get some food now.kinda worried i`ll break the steering mood given how stressed i am.lol.seeya.
Logfile of HijackThis v1.99.1
Scan saved at 22:46:48, on 27/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis\HijackThis.exe
F3 - REG:win.ini: run=
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
the underdog 0 Newbie Poster
ok i got somewhere!!! provides server functions for zone alarm pro,microsoft updates and other well known companies.thats why theyve been in my active ports program and netstat! great news! spoke to akamai myself today and got the info.i will post an additional thread in forum to explin about this company incase others as paranoid as me have been doing the same.the problem is with active port program it identifies then connections as unkown and doesnt put them in zone alarm processes,which it has in interface.well how about that.wohoo! not under attack after all.removed all blocks to the ips immediately and im 2 spring lighter today.just need to figure out who the rest of the ips that were connecting to me are.well have a nice day d ,thanks for the help.i know ill game that much easier online tonight.best wishes to y`all out there.and remember,better to be safe than sorry! lol man im relieved!! peace.
D3m3nt3d 1 Posting Whiz in Training
Oh man - for some reason I had no clue you replied after I told you glad I could help.
I'm glad you figured everything out though :)
Your logs dont show much for the record, PC # 2 you could fix this
F3 - REG:win.ini: run=
the underdog 0 Newbie Poster
lol hi d,ok but you must tell me how to fix hehe.best wishes dude.
D3m3nt3d 1 Posting Whiz in Training
Sorry about that! I thought we had previously fixed some lines in HijackThis :)
Scan with HijackThis and place a check in the box next to
F3 - REG:win.ini: run=
Then close ALL Browsers and click Fix Checked
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.