Network Hacking/Taking Control of a PC

stu_zone

New Member
I've started a new job and one of the guys in my office has started to gain entry to my pc where he closes programs, turns the volume off and up and down and basically does loads of things to my pc. This isn't a serious problem i should add as we're mates and he is just doing it for fun but i'd like to go into work and stop him gaining entry to my pc just to get back at him.

I installed ZoneAlarm firewall which hasn't stopped him from gaining entry but it has recorded the source of his access attempts, therefore having his ip address and host name. Think we're running on windows 2000 by the way.

Anyone tell me what to do to stop him taking over my pc?
 
When he is connected to you (while he is messing with you) Run
netstat -b

look for established connections, means that that application has someone/something connected to it

Active Connections

Proto Local Address Foreign Address State PID
TCP PC:1077 localhost:2002 ESTABLISHED 2868
[LogMeInSystray.exe]

TCP PC:2002 localhost:1077 ESTABLISHED 912
Can not obtain ownership information
TCP PC:1072 dc2.server.com:netbios-ssn ESTABLISHED 4
Can not obtain ownership information
TCP PC:1107 dc1.server.com:5060 ESTABLISHED 3488
[msmsgs.exe]

TCP PC:1304 64.233.179.104:http ESTABLISHED 2112
[iexplore.exe]

TCP PC:1340 207.68.178.16:http ESTABLISHED 2112
[iexplore.exe]

TCP PC:1347 72.14.219.104:http ESTABLISHED 3660
[iexplore.exe]

TCP PC:1348 72.14.219.104:http ESTABLISHED 3660
[iexplore.exe]

TCP PC:1386 dc1.server.com:1025 ESTABLISHED 3280
[OUTLOOK.EXE]

TCP PC:1388 dc1.server.com:1444 ESTABLISHED 3280
[OUTLOOK.EXE]

TCP PC:2577 app06.logmein.com:http ESTABLISHED 912
Can not obtain ownership information
TCP PC:3605 baym-cs330.msgr.hotmail.com:1863 ESTABLISHED
3488
[msmsgs.exe]

TCP PC:3990 dc1.server.com:microsoft-ds ESTABLISHED 4

Can not obtain ownership information
TCP PC:1048 dc1.server.com:ldap CLOSE_WAIT 1300
Can not obtain ownership information
TCP PC:1110 62.93.192.29.insoft.fra2.de.mfnx.net:http CLOSE
_WAIT 3232
[NeroMediaHome.exe]

TCP PC:1335 207.138.126.169:http CLOSE_WAIT 2112
[iexplore.exe]

TCP PC:1336 207.138.126.169:http CLOSE_WAIT 2112
[iexplore.exe]

TCP PC:1338 207.138.126.169:http CLOSE_WAIT 2112
[iexplore.exe]
 
Back
Top