samrulez
Cyborg Agent
Hi guys,
From a few days...I am getting messages from Kaspersky that 'An attemp to hack has been made'......
From.....
1>Intrusion.Win.MSSQL.worm.Helkern! Attacker's IP: 61.187.200.10.
2>Intrusion.Win.DCOM.exploit! Attacker's IP: 59.182.52.187.
3>Intrusion.Win.LSASS.exploit! Attacker's IP: 59.182.40.30.
But the IP keeps changing ...each attack has its own IP.....
Are these viruses/worms etc...on my pc...or they are on some server...
Plz tell me how to remove them...I'm really scared...
This is the Kaspersky Report
--------x--------x---------x-------x------x--------x------x-------x-------x------x--------x---
Anti-Hacker
-----------
Attacks detected: 4
Time of last attack: 7/2/2006 7:53:01 PM
Start time: 7/2/2006 5:50:43 PM
Duration: 02:10:01
Network attacks
---------------
Time Attack description Source Protocol Local port
---- ------------------ ------ -------- ----------
7/2/2006 7:06:42 PM Intrusion.Win.MSSQL.worm.Helkern 4.155.63.147 UDP 1434
7/2/2006 7:24:39 PM Intrusion.Win.MSSQL.worm.Helkern 61.150.61.95 UDP 1434
7/2/2006 7:33:49 PM Intrusion.Win.LSASS.exploit 59.182.40.30 TCP 445
7/2/2006 7:53:01 PM Intrusion.Win.MSSQL.worm.Helkern 66.111.241.92 UDP 1434
Banned hosts
------------
Time Host
---- ----
7/2/2006 7:06:42 PM 4.155.63.147
7/2/2006 7:24:39 PM 61.150.61.95
7/2/2006 7:33:49 PM 59.182.40.30
7/2/2006 7:53:01 PM 66.111.241.92
Application activity
--------------------
Time Application name Command line Rule name Application PID Action Direction Protocol Remote address Remote port Local host Local port
---- ---------------- ------------ --------- --------------- ------ --------- -------- -------------- ----------- ---------- ----------
Packet filtering
----------------
Time Rule name Action Direction Protocol Remote address Remote port Local host Local port
---- --------- ------ --------- -------- -------------- ----------- ---------- ----------
From a few days...I am getting messages from Kaspersky that 'An attemp to hack has been made'......
From.....
1>Intrusion.Win.MSSQL.worm.Helkern! Attacker's IP: 61.187.200.10.
2>Intrusion.Win.DCOM.exploit! Attacker's IP: 59.182.52.187.
3>Intrusion.Win.LSASS.exploit! Attacker's IP: 59.182.40.30.
But the IP keeps changing ...each attack has its own IP.....
Are these viruses/worms etc...on my pc...or they are on some server...
Plz tell me how to remove them...I'm really scared...
This is the Kaspersky Report
--------x--------x---------x-------x------x--------x------x-------x-------x------x--------x---
Anti-Hacker
-----------
Attacks detected: 4
Time of last attack: 7/2/2006 7:53:01 PM
Start time: 7/2/2006 5:50:43 PM
Duration: 02:10:01
Network attacks
---------------
Time Attack description Source Protocol Local port
---- ------------------ ------ -------- ----------
7/2/2006 7:06:42 PM Intrusion.Win.MSSQL.worm.Helkern 4.155.63.147 UDP 1434
7/2/2006 7:24:39 PM Intrusion.Win.MSSQL.worm.Helkern 61.150.61.95 UDP 1434
7/2/2006 7:33:49 PM Intrusion.Win.LSASS.exploit 59.182.40.30 TCP 445
7/2/2006 7:53:01 PM Intrusion.Win.MSSQL.worm.Helkern 66.111.241.92 UDP 1434
Banned hosts
------------
Time Host
---- ----
7/2/2006 7:06:42 PM 4.155.63.147
7/2/2006 7:24:39 PM 61.150.61.95
7/2/2006 7:33:49 PM 59.182.40.30
7/2/2006 7:53:01 PM 66.111.241.92
Application activity
--------------------
Time Application name Command line Rule name Application PID Action Direction Protocol Remote address Remote port Local host Local port
---- ---------------- ------------ --------- --------------- ------ --------- -------- -------------- ----------- ---------- ----------
Packet filtering
----------------
Time Rule name Action Direction Protocol Remote address Remote port Local host Local port
---- --------- ------ --------- -------- -------------- ----------- ---------- ----------
Last edited: