New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1159
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

NT AUTHORITY is taking over the security settings etc.

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Security - Guests
View previous topic :: View next topic  
Author Message
Ben-hacked

Guest






PostPosted: Fri Mar 26, 2004 12:33 am    Post subject: NT AUTHORITY is taking over the security settings etc.
Reply with quote

anybody out there have any experience with packet sniffers, nt access, security settings being changed to lock out local logon. I think we were hacked by pros. This thing "nukes registry keys" like windows update does. It was running in our system invisibly for an unknown time. stumbled upon some odd things while configuring a raid controller. found hidden devices such as "virtual network controller"controlled by nt authority attempts at disabling these prompt the system to change access to nt authority,it disables admin account and eventually disables all local logons... one computer on this system is compromised to the point that it seems to beconstantly accessing the internet both downloading and uploading (undoubtably runnig either an ad server or spam) each computer has strange logs on notepad files in vey strange places I can give more specifics if anyone is interested or has any ideas thanks...
Back to top
Dan

Guest






PostPosted: Fri Jun 04, 2004 3:18 pm    Post subject:
Reply with quote

I have the same thing here
Back to top
John

Guest






PostPosted: Wed Jun 09, 2004 6:53 am    Post subject:
Reply with quote

Here is more info that may help you find the features you want .

Security Ports

http://grc.com/su-fixit.htm

http://grc.com/su-bondage.htm

http://grc.com/lt/leaktest.htm

http://grc.com/xpdite/xpdite.htm

http://www.ultratech-llc.com/KB/ASP/Fil...Listen.TXT

http://www.hsc.fr/ressources/breves/min...in.en.html

What can you do to protect yourself?
There is no better defense than knowledge. Acquiring the knowledge you need to defend yourself
against the bad guys on the Internet will not be instantaneous, but, thanks to this web site
. . . at least it's free!

http://lists.gpick.com/portlist/portlist.htm

http://www.iana.org/assignments/port-numbers

PORT NUMBERS
The port numbers are divided into three ranges: the Well Known Ports, the Registered Ports, and the Dynamic and/or Private Ports.

======================================

Qwik-Fix
http://www.all4you.dk/FreewareWorld/lin...=8&cat=006
http://www.pivx.com/qwikfix/
Qwik-Fix™ provides another layer of essential security by closing off the pathways that worms and viruses use to penetrate your PC.. It does not affect any of your virus programs, firewall or other programs. Had users installed Qwik-Fix™ on their PC’s, the recent LovSan/MS Blaster worm and the Sobig virus would have had no impact on them. And, it will close the doors that the next worm will try to enter thru to infect and spread its payload.
Qwik-Fix™ is a product of PivX LABS, and results from our work with some of the largest companies in the world. PivX is a premier security research company which has focused its security research efforts on Mocrosoft’s Windows® and its ubiquitous Internet browser, Internet Explorer. PivX and its worldwide network of security researchers has located, tested and verified hundreds of security vulnerabilities in Internet Explorer alone. As a public service, PivX has also maintained a FREE public online listing of the vulnerabilities that were patched and those that remained Unpatched. Now we have developed Qwik-Fix™, a tool which helps protect your PC from these risky vulnerabilities.
Qwik-Fix™ is designed to pro-actively prevent known software vulnerabilities in Windows and Internet Explorer from being exploited by malicious hackers, virus writers and worm writers. Qwik-Fix™ is simple to use, Qwik-Fix™ is easy to download and install. Qwik-Fix™ is dynamic in that it serves as a temporary fix to known vulnerabilities until Microsoft releases a periodic monthly cumulative patch or a new Service Pack. As we find new vulnerabilities our subscribers will be updated immediately, thus staying one step ahead of the bad guys.

==================================

Online - Audit My PC.com
http://www.all4you.dk/FreewareWorld/links.php?cat=024005
http://www.auditmypc.com/
Your free online security audit, firewall test and research center. Your security test and port scan starts here.
Audit your firewall with a free online Firewall Test, Port Scan and Privacy Test that provides immediate results designed to promote security awareness and help secure your firewall. Port Scan all 65,535 tcp ports or choose your port scan range!

==================================

DCOMbobulator
http://grc.com/dcom/
Effortlessly Tame Windows Dangerous DCOM Facility by Steve Gibson, Gibson Research Corporation.
Microsoft's DCOM security patch leaves DCOM running, open, and waiting for the next malicious exploit.
Our 29 kbyte "DCOMbobulator" allows any Windows user to quickly check their system's DCOM vulnerability, then simply shut down the unnecessary DCOM security risk.

========================================

Safe XP

http://free.hostdepartment.com/t/theorica/safexp.htm

http://free.hostdepartment.com/t/theorica/SafeXPHelp.htm

http://www.softcities.com/Safe-XP/download/10988.htm

http://freewebhosting.hostdepartment.co...wnload.htm
Back to top
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Security - Guests All times are GMT - 5 Hours
Page 1 of 1

 
 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops