<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: intruder in my network&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27839259</link>
<description></description>
<language>en</language>
<pubDate>Fri, 24 May 2013 23:27:28 EDT</pubDate>
<lastBuildDate>Fri, 24 May 2013 23:27:28 EDT</lastBuildDate>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27870503</link>
<description><![CDATA[HELLFIRE posted : <div class="bquote"><said>said by anarchoi2 :</said><p>i have been using Hamachi since almost 2 years and i have NEVER seen "PIMP" in my network. Hamachi is used by millions of users and is supposed to be clean and trojan-free. <br> </p></div>Forget clean and trojan free, I'm more worried about a) a misconfig in the Hamachi software itself, and b) how long "PIMP"<br>has been there, as from an operational perspective, "PIMP" was a computer on your LAN able to access your LAN resources<br>and WAN at will...<br><br>Keep off Hamachi for a week and see if "PIMP" pops back up or not... my 00000010bits<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27870503</guid>
<pubDate>Mon, 31 Dec 2012 23:53:52 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27863400</link>
<description><![CDATA[NetFixer posted : <div class="bquote"><said>said by anarchoi2 :</said><p>Ok there's something really weird... PIMP just showed up again in my network under ANARCHOI_LAPTOP...<br><br>So i did nbstat again. Here's the result.<br>25.176.120.102 is *NOT* my IP. It belongs to "Royal Signals and Radar Establishment".... WTF ???<br>Currently my IP is 206.80.243.*<br> </p></div>See my previous reply for an explanation: &raquo;<A HREF="/forum/r27848289-intruder-in-my-network">Re: intruder in my network</A><br><small>--<br><A HREF="http://nature-pics.com">We can never have enough of nature.</a><br>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27863400</guid>
<pubDate>Fri, 28 Dec 2012 21:23:32 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27863328</link>
<description><![CDATA[anon posted : OMG i think i just found the source of the problem.<br><br>If i go to my network connections and turn off HAMACHI, then PIMP goes away and diseappear from my network.<br><br>However, i have been using Hamachi since almost 2 years and i have NEVER seen "PIMP" in my network. Hamachi is used by millions of users and is supposed to be clean and trojan-free. I have ran multiple anti-viruses and anti-spywares and my computer was always clean.<br>Hamachi is used to play games in LAN<br><br>I suppose i should uninstall it now :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27863328</guid>
<pubDate>Fri, 28 Dec 2012 20:50:30 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27863321</link>
<description><![CDATA[anon posted : Ok there's something really weird... PIMP just showed up again in my network under ANARCHOI_LAPTOP<br><br>Problem is that ANARCHOI_LAPTOP was NOT open at this time (it wasn't even in sleep mode). There was no computer at all connected to my network except my main PC (ANARCHOI-PC). But "PIMP" is showing under "ANARCHOI_LAPTOP"<br><br>See screenshot:<br>&raquo;<A HREF="http://www.ni-dieu-ni-maitre.com/_uploads/pimpwtf.png" >www.ni-dieu-ni-maitre.com/_uploa&middot;&middot;&middot;pwtf.png</A><br><br>Note: DBTOA000 was my girlfriend's laptop<br><br>So i did nbstat again. Here's the result.<br>25.176.120.102 is *NOT* my IP. It belongs to "Royal Signals and Radar Establishment".... WTF ???<br>Currently my IP is 206.80.243.*<br><br>*********************************<br><br>Microsoft Windows [version 6.1.7601]<br>Copyright (c) 2009 Microsoft Corporation. Tous droits r&eacute;serv&eacute;s.<br><br>C:\Users\Anarchoi>nbtstat -c<br><br>ANARCHOI:<br>Adresse IP du noeud&nbsp;: [192.168.2.2] ID d'&eacute;tendue&nbsp;: []<br><br>    Aucun nom dans le cache<br><br>Hamachi:<br>Adresse IP du noeud&nbsp;: [25.162.23.89] ID d'&eacute;tendue&nbsp;: []<br><br>                  Table de nom de cache distant NetBIOS<br><br>        Nom               Type        Adresse d'h&ocirc;te   Vie [sec]<br>    ------------------------------------------------------------<br>    PIMP             UNIQUE          25.176.120.102      320<br><br>C:\Users\Anarchoi><br><br>***********************************<br><br>Microsoft Windows [version 6.1.7601]<br>Copyright (c) 2009 Microsoft Corporation. Tous droits r&eacute;serv&eacute;s.<br><br>C:\Users\Anarchoi>nbtstat -n<br><br>ANARCHOI:<br>Adresse IP du noeud&nbsp;: [192.168.2.2] ID d'&eacute;tendue&nbsp;: []<br><br>                Table nom local NetBIOS<br><br>       Nom                Type         Statut<br>    ---------------------------------------------<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br>    WORKGROUP        UNIQUE      Inscrit<br>    ..__MSBROWSE__.  Groupe      Inscrit<br><br>Hamachi:<br>Adresse IP du noeud&nbsp;: [25.162.23.89] ID d'&eacute;tendue&nbsp;: []<br><br>                Table nom local NetBIOS<br><br>       Nom                Type         Statut<br>    ---------------------------------------------<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br><br>C:\Users\Anarchoi><br><br>*******************************************<br><br>Microsoft Windows [version 6.1.7601]<br>Copyright (c) 2009 Microsoft Corporation. Tous droits r&eacute;serv&eacute;s.<br><br>C:\Users\Anarchoi>nbtstat -S<br><br>ANARCHOI:<br>Adresse IP du noeud&nbsp;: [192.168.2.2] ID d'&eacute;tendue&nbsp;: []<br><br>    Aucune connexion<br><br>Hamachi:<br>Adresse IP du noeud&nbsp;: [25.162.23.89] ID d'&eacute;tendue&nbsp;: []<br><br>    Aucune connexion<br><br>C:\Users\Anarchoi>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27863321</guid>
<pubDate>Fri, 28 Dec 2012 20:50:14 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27857695</link>
<description><![CDATA[HELLFIRE posted : So from your nbtstat output, doesn't look like PIMP is detected / resolivng from the CLI.  Was PIMP<br>still present in Windows Explorer at the time you pulled up this output?<br><br>My only question is what this host is<br><br><pre class="brush: text">DBTOA000 UNIQUE 192.168.2.5 215&#012; &#012;</pre><!--end code block--><br>Regards<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27857695</guid>
<pubDate>Wed, 26 Dec 2012 19:53:44 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848615</link>
<description><![CDATA[Lagz posted : The 5.x.x.x address block was reserved at one time. The 5.x.x.x block was used by Hamachi to avoid collisions with private IP networks that might be in use on the client side. Hamachi was wrong to hijack the range, but if IANA has it reserved, then one might as well utilize it. I hope IANA doesn't decide to simply allocate the 10.x.x.x range at some point in the future.  :)<br><small>--<br>When somebody tells you nothing is impossible, ask him to dribble a football.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848615</guid>
<pubDate>Sat, 22 Dec 2012 09:16:22 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848289</link>
<description><![CDATA[NetFixer posted : <div class="bquote"><said>said by <a href="/profile/195618" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=195618');">Lagz</a>:</said><p>Hamachi is a VPN. So you didn't entirely delete all the VPN software<br> </p></div>And the owner of the IP address used by that Himachi connection is somewhat interesting:<br><small><br><br><pre class="brush: text">% This is the RIPE Database query service.&#012;% The objects are in RPSL format.&#012;%&#012;% The RIPE Database is subject to Terms and Conditions.&#012;% See http://www.ripe.net/db/support/db-terms-conditions.pdf&#012;% Note: this output has been filtered.&#012;%       To receive output for a database update, use the "-B" flag.&#012;% Information related to '25.0.0.0 - 25.255.255.255'&#012;inetnum:        25.0.0.0 - 25.255.255.255&#012;netname:        UK-MOD-19850128&#012;descr:          DINSA, Ministry of Defence&#012;country:        GB&#012;org:            ORG-DMoD1-RIPE&#012;admin-c:        MN1891-RIPE&#012;tech-c:         MN1891-RIPE&#012;status:         ALLOCATED PA&#012;mnt-by:         RIPE-NCC-HM-MNT&#012;mnt-lower:      UK-MOD-MNT&#012;mnt-domains:    UK-MOD-MNT&#012;mnt-routes:     UK-MOD-MNT&#012;source:         RIPE # Filtered&#012;organisation:   ORG-DMoD1-RIPE&#012;org-name:       DINSA, Ministry of Defence&#012;org-type:       LIR&#012;address:        Not Published&#012;                Not Published Not Published&#012;                United Kingdom&#012;phone:          +44 (0)30 677 00816&#012;admin-c:        MN1891-RIPE&#012;mnt-ref:        UK-MOD-MNT&#012;mnt-ref:        RIPE-NCC-HM-MNT&#012;mnt-by:         RIPE-NCC-HM-MNT&#012;source:         RIPE # Filtered&#012;person:         Mathew Newton&#012;address:        C4 Architecture&#012;address:        UK Ministry of Defence&#012;phone:          +44 (0)30 677 00816&#012;abuse-mailbox:  hostmaster@mod.uk&#012;nic-hdl:        MN1891-RIPE&#012;source:         RIPE # Filtered&#012;mnt-by:         UK-MOD-MNT&#012;% Information related to '25.0.0.0/8AS5378'&#012;route:          25.0.0.0/8&#012;descr:          INS-MOD-NET&#012;descr:          INSnet core/customer route&#012;descr:          Address Space owned by MOD&#012;descr:          see whois.arin.net&#012;member-of:      RS-AS5378&#012;origin:         AS5378&#012;mnt-by:         AS5378-MNT&#012;source:         RIPE # Filtered&#012;% This query was served by the RIPE Database Query Service version 1.47.5 (WHOIS1)&#012; &#012;</pre><!--end code block--><br></small><br><br>My assumption was that connection was probably "work related", but...<br><br>EDIT:<br>OK, the Himachi/UK MoD mystery is solved:<br><br>&raquo;<A HREF="http://b.logme.in/2012/11/07/changes-to-hamachi-on-november-19th/" >b.logme.in/2012/11/07/changes-to&middot;&middot;&middot;er-19th/</A><br><br><div class="bquote"><p>The first change concerns the use of the 5.x.x.x address space. As you may or may not be aware, this address space has been allocated by IANA to RIPE NCC two years ago. RIPE NCC has been handing out these addresses to their customers, and having Hamachi active on your computer means that you&#146;re not able to access a growing portion of the Internet. We&#146;ve added IPv6 support to Hamachi a while back, and you can simply turn off the use of the 5/8 space, but we realize that IPv4 is still very important to most of you. Therefore we&#146;ll be changing every Hamachi node&#146;s address to the 25/8 space...<br><br>Why 25/8? Well, it rhymes a bit with 5/8, and furthermore, it&#146;s a block that&#146;s been allocated to a foreign government agency for private use for almost two decades. We have no Hamachi users from this address space, and it&#146;s highly unlikely that the general public would need to access one of these IP addresses. However, our general recommendation is that if you can, please turn off IPv4 support in your Hamachi clients. The IPv6 space we&#146;re using has been registered to LogMeIn, and most modern software should function perfectly without needing an IPv4 address.<br> </p></div>So, it seems that LogMeIn/Himachi has simply hijacked the UK MoD's IPv4 address space. I can't believe that the UK MoD has not already nuked them.   <IMG SRC="http://i.dslr.net/v2/lite/eyesup.gif"> <br><br>OTOH, the phrase "plausible deniability" does come to mind, so maybe the UK MoD isn't really too upset about LogMeIn/Himachi spoofing their IP addresses.   <IMG SRC="http://i.dslr.net/v2/lite/wink.gif"> <br><small>--<br><A HREF="http://nature-pics.com">We can never have enough of nature.</a><br>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848289</guid>
<pubDate>Sat, 22 Dec 2012 01:07:14 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848273</link>
<description><![CDATA[Lagz posted : Hamachi is a VPN. So you didn't entirely delete all the VPN software]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848273</guid>
<pubDate>Sat, 22 Dec 2012 00:57:25 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848272</link>
<description><![CDATA[NetFixer posted : A .pbk file is just a text file, not an executable, so it is unlikely that anybody's malware scanner will tell you anything. The "pbk" file extension is an acronym for "phonebook", and the file contains text parameter entries used by Windows for making dialup and VPN connections.<br><br>FWIW, here is the relevant information for the "Ukraine" entries in the file you uploaded:<br><br><pre class="brush: text">&#91;EUROIP L2TP Ukraine&#93;&#012;Encoding=1&#012;Type=2&#012;AutoLogon=0&#012;UseRasCredentials=1&#012;LowDateTime=-1331370144&#012;HighDateTime=29944263&#012;DialParamsUID=172546&#012;Guid=7106BE987679AF4B8258EFCCADA692A5&#012;BaseProtocol=1&#012;VpnStrategy=3&#012;ExcludedProtocols=2&#012;LcpExtensions=1&#012;DataEncryption=8&#012;SwCompression=1&#012;NegotiateMultilinkAlways=1&#012;SkipNwcWarning=0&#012;SkipDownLevelDialog=0&#012;SkipDoubleDialDialog=0&#012;DialMode=1&#012;OverridePref=15&#012;RedialAttempts=99&#012;RedialSeconds=30&#012;IdleDisconnectSeconds=0&#012;RedialOnLinkFailure=0&#012;CallbackMode=0&#012;CustomDialDll=&#012;CustomDialFunc=&#012;CustomRasDialDll=&#012;ForceSecureCompartment=0&#012;DisableIKENameEkuCheck=0&#012;AuthenticateServer=0&#012;ShareMsFilePrint=1&#012;BindMsNetClient=1&#012;SharedPhoneNumbers=0&#012;GlobalDeviceSettings=0&#012;PrerequisiteEntry=&#012;PrerequisitePbk=&#012;PreferredPort=VPN2-0&#012;PreferredDevice=WAN Miniport (L2TP)&#012;PreferredBps=0&#012;PreferredHwFlow=1&#012;PreferredProtocol=1&#012;PreferredCompression=1&#012;PreferredSpeaker=1&#012;PreferredMdmProtocol=0&#012;PreviewUserPw=1&#012;PreviewDomain=0&#012;PreviewPhoneNumber=0&#012;ShowDialingProgress=1&#012;ShowMonitorIconInTaskBar=1&#012;CustomAuthKey=-1&#012;AuthRestrictions=544&#012;TypicalAuth=2&#012;IpPrioritizeRemote=1&#012;IpInterfaceMetric=0&#012;fCachedDnsSuffix=0&#012;IpHeaderCompression=0&#012;IpAddress=0.0.0.0&#012;IpDnsAddress=0.0.0.0&#012;IpDns2Address=0.0.0.0&#012;IpWinsAddress=0.0.0.0&#012;IpWins2Address=0.0.0.0&#012;IpAssign=1&#012;IpNameAssign=1&#012;IpDnsFlags=0&#012;IpNBTFlags=1&#012;TcpWindowSize=0&#012;UseFlags=0&#012;IpSecFlags=0&#012;IpDnsSuffix=&#012;IpCachedDnsSuffix=&#012;Ipv6PrioritizeRemote=1&#012;Ipv6InterfaceMetric=0&#012;Ipv6NameAssign=1&#012;Ipv6DnsAddress=::&#012;Ipv6Dns2Address=::&#012;Ipv6InterfaceId=0000000000000000&#012; &#012;NETCOMPONENTS=&#012;ms_server=1&#012;ms_msclient=1&#012;ms_psched=1&#012;ms_nwsapagent=1&#012;ms_nwclient=1&#012;ms_pacer=1&#012;cfosspeed=1&#012;odysseyim4=1&#012;vmware_bridge=1&#012; &#012;MEDIA=rastapi&#012;Port=VPN0-0&#012;Device=WAN-miniport (L2TP)&#012; &#012;DEVICE=vpn&#012;PhoneNumber=ttu.15.usaip.eu&#012;AreaCode=&#012;CountryCode=98&#012;CountryID=98&#012;UseDialingRules=0&#012;Comment=&#012;LastSelectedPhone=0&#012;PromoteAlternates=0&#012;TryNextAlternateOnFail=1&#012; &#012;&#91;EUROIP PPTP Ukraine&#93;&#012;Encoding=1&#012;Type=2&#012;AutoLogon=0&#012;UseRasCredentials=1&#012;LowDateTime=-1542958000&#012;HighDateTime=29944249&#012;DialParamsUID=172546&#012;Guid=7106BE987679AF4B8258EFCCADA692A5&#012;BaseProtocol=1&#012;VpnStrategy=1&#012;ExcludedProtocols=2&#012;LcpExtensions=1&#012;DataEncryption=8&#012;SwCompression=1&#012;NegotiateMultilinkAlways=1&#012;SkipNwcWarning=0&#012;SkipDownLevelDialog=0&#012;SkipDoubleDialDialog=0&#012;DialMode=1&#012;OverridePref=15&#012;RedialAttempts=99&#012;RedialSeconds=30&#012;IdleDisconnectSeconds=0&#012;RedialOnLinkFailure=0&#012;CallbackMode=0&#012;CustomDialDll=&#012;CustomDialFunc=&#012;CustomRasDialDll=&#012;ForceSecureCompartment=0&#012;DisableIKENameEkuCheck=0&#012;AuthenticateServer=0&#012;ShareMsFilePrint=1&#012;BindMsNetClient=1&#012;SharedPhoneNumbers=0&#012;GlobalDeviceSettings=0&#012;PrerequisiteEntry=&#012;PrerequisitePbk=&#012;PreferredPort=VPN2-0&#012;PreferredDevice=WAN Miniport (L2TP)&#012;PreferredBps=0&#012;PreferredHwFlow=1&#012;PreferredProtocol=1&#012;PreferredCompression=1&#012;PreferredSpeaker=1&#012;PreferredMdmProtocol=0&#012;PreviewUserPw=1&#012;PreviewDomain=0&#012;PreviewPhoneNumber=0&#012;ShowDialingProgress=1&#012;ShowMonitorIconInTaskBar=1&#012;CustomAuthKey=-1&#012;AuthRestrictions=544&#012;TypicalAuth=2&#012;IpPrioritizeRemote=1&#012;IpInterfaceMetric=0&#012;fCachedDnsSuffix=0&#012;IpHeaderCompression=0&#012;IpAddress=0.0.0.0&#012;IpDnsAddress=0.0.0.0&#012;IpDns2Address=0.0.0.0&#012;IpWinsAddress=0.0.0.0&#012;IpWins2Address=0.0.0.0&#012;IpAssign=1&#012;IpNameAssign=1&#012;IpDnsFlags=0&#012;IpNBTFlags=1&#012;TcpWindowSize=0&#012;UseFlags=0&#012;IpSecFlags=1&#012;IpDnsSuffix=&#012;IpCachedDnsSuffix=&#012;Ipv6PrioritizeRemote=1&#012;Ipv6InterfaceMetric=0&#012;Ipv6NameAssign=1&#012;Ipv6DnsAddress=::&#012;Ipv6Dns2Address=::&#012;Ipv6InterfaceId=0000000000000000&#012; &#012;NETCOMPONENTS=&#012;ms_server=1&#012;ms_msclient=1&#012;ms_psched=1&#012;ms_nwsapagent=1&#012;ms_nwclient=1&#012;ms_pacer=1&#012;cfosspeed=1&#012;odysseyim4=1&#012;vmware_bridge=1&#012; &#012;MEDIA=rastapi&#012;Port=VPN0-0&#012;Device=WAN-miniport (L2TP)&#012; &#012;DEVICE=vpn&#012;PhoneNumber=ttu.15.usaip.eu&#012;AreaCode=&#012;CountryCode=98&#012;CountryID=98&#012;UseDialingRules=0&#012;Comment=&#012;LastSelectedPhone=0&#012;PromoteAlternates=0&#012;TryNextAlternateOnFail=1&#012; &#012;&#91;EUROIP SSTP Ukraine&#93;&#012;Encoding=1&#012;PBVersion=1&#012;Type=2&#012;AutoLogon=0&#012;UseRasCredentials=1&#012;LowDateTime=463995664&#012;HighDateTime=30143741&#012;DialParamsUID=172546&#012;Guid=7106BE987679AF4B8258EFCCADA692A5&#012;VpnStrategy=5&#012;ExcludedProtocols=2&#012;LcpExtensions=1&#012;DataEncryption=8&#012;SwCompression=1&#012;NegotiateMultilinkAlways=1&#012;SkipDoubleDialDialog=0&#012;DialMode=1&#012;OverridePref=15&#012;RedialAttempts=99&#012;RedialSeconds=30&#012;IdleDisconnectSeconds=0&#012;RedialOnLinkFailure=0&#012;CallbackMode=0&#012;CustomDialDll=&#012;CustomDialFunc=&#012;CustomRasDialDll=&#012;ForceSecureCompartment=0&#012;DisableIKENameEkuCheck=0&#012;AuthenticateServer=0&#012;ShareMsFilePrint=1&#012;BindMsNetClient=1&#012;SharedPhoneNumbers=0&#012;GlobalDeviceSettings=0&#012;PrerequisiteEntry=&#012;PrerequisitePbk=&#012;PreferredPort=VPN0-0&#012;PreferredDevice=WAN Miniport (SSTP)&#012;PreferredBps=0&#012;PreferredHwFlow=1&#012;PreferredProtocol=1&#012;PreferredCompression=1&#012;PreferredSpeaker=1&#012;PreferredMdmProtocol=0&#012;PreviewUserPw=1&#012;PreviewDomain=0&#012;PreviewPhoneNumber=0&#012;ShowDialingProgress=1&#012;ShowMonitorIconInTaskBar=1&#012;CustomAuthKey=0&#012;AuthRestrictions=544&#012;IpPrioritizeRemote=1&#012;IpInterfaceMetric=0&#012;IpHeaderCompression=0&#012;IpAddress=0.0.0.0&#012;IpDnsAddress=0.0.0.0&#012;IpDns2Address=0.0.0.0&#012;IpWinsAddress=0.0.0.0&#012;IpWins2Address=0.0.0.0&#012;IpAssign=1&#012;IpNameAssign=1&#012;IpDnsFlags=0&#012;IpNBTFlags=1&#012;TcpWindowSize=0&#012;UseFlags=0&#012;IpSecFlags=0&#012;IpDnsSuffix=&#012;Ipv6Assign=1&#012;Ipv6Address=::&#012;Ipv6PrefixLength=0&#012;Ipv6PrioritizeRemote=1&#012;Ipv6InterfaceMetric=0&#012;Ipv6NameAssign=1&#012;Ipv6DnsAddress=::&#012;Ipv6Dns2Address=::&#012;Ipv6Prefix=0000000000000000&#012;Ipv6InterfaceId=0000000000000000&#012;DisableClassBasedDefaultRoute=0&#012;DisableMobility=0&#012;NetworkOutageTime=0&#012;ProvisionType=0&#012;PreSharedKey=&#012; &#012;NETCOMPONENTS=&#012;ms_server=1&#012;ms_msclient=1&#012;ms_psched=1&#012;ms_nwsapagent=1&#012;ms_nwclient=1&#012;ms_pacer=1&#012;cfosspeed=1&#012;odysseyim4=1&#012;vmware_bridge=1&#012; &#012;MEDIA=rastapi&#012;Port=VPN0-0&#012;Device=WAN Miniport (SSTP)&#012; &#012;DEVICE=vpn&#012;PhoneNumber=vpn15.usaip.eu&#012;AreaCode=&#012;CountryCode=98&#012;CountryID=98&#012;UseDialingRules=0&#012;Comment=&#012;FriendlyName=&#012;LastSelectedPhone=0&#012;PromoteAlternates=0&#012;TryNextAlternateOnFail=1&#012; &#012;</pre><!--end code block--><br>There is no way of knowing if you were hacked while attached to that VPN server, or if what you have is something that came packaged with some game you downloaded. However, the safest thing to do would be to nuke the effected PCs from orbit, change all passwords to everything you use that uses a password, and carefully check your bank and credit card accounts for at least several months. <a href="http://www.dban.org/">DBAN</a> is the ultimate malware removal tool.<br><br><small>--<br><A HREF="http://nature-pics.com">We can never have enough of nature.</a><br>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848272</guid>
<pubDate>Sat, 22 Dec 2012 00:56:21 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848246</link>
<description><![CDATA[anon posted : I uploaded the file here:<br>&raquo;<A HREF="http://www.2shared.com/file/xJjERHDA/CDKEYZIP.html" >www.2shared.com/file/xJjERHDA/CDKEYZIP.html</A><br><br>Microsoft Windows [version 6.1.7601]<br>Copyright (c) 2009 Microsoft Corporation. Tous droits r&Atilde;&copy;serv&Atilde;&copy;s.<br><br>C:\Users\Anarchoi>nbtstat -S<br><br>ANARCHOI:<br>Adresse IP du noeud&Acirc;&nbsp;: [192.168.2.2] ID d'&Atilde;&copy;tendue&Acirc;&nbsp;: []<br><br>    Aucune connexion<br><br>Hamachi:<br>Adresse IP du noeud&Acirc;&nbsp;: [25.162.23.89] ID d'&Atilde;&copy;tendue&Acirc;&nbsp;: []<br><br>    Aucune connexion<br><br>C:\Users\Anarchoi>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848246</guid>
<pubDate>Sat, 22 Dec 2012 00:33:11 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848239</link>
<description><![CDATA[HELLFIRE posted : Okay, so PBK files supposedly store connection settings for Windows... dunno if you still have the file to<br>be reviewed and/or submitted for a malware investigation / analysis.<br><br>...and it was "nbtstat -S" (capitalized, not lower case).<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848239</guid>
<pubDate>Sat, 22 Dec 2012 00:26:07 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27848073</link>
<description><![CDATA[anon posted : <blocKQUOTE>What website was this, and what "VPN" software did you have to download / install?<br></blocKQUOTE>First VPN was a game i bought on eBay. The seller sent me a file called<br>CDKEYZIP.pbk and asked me to connect to "EUROIP PPTP Ukraine" VPN<br><br>Second one was from www.direct2play.com<br><br>The game was Borderlands 2<br><br><blocKQUOTE>Also agree with Bullwhip See Profile in that is the VPN software still running on Anarchoi-Pc and Anarchoi-Laptop<br>at the time "PIMP" is visible?<br></blocKQUOTE>I deleted all files related to the VPN's<br><br>When i do "nbtstat" i don't see PIMP in the list even if i see it in the windows network neighboorhood. "DBTOA000" is listed twice (this is my girlfriend's laptop)<br><br>C:\Users\Anarchoi>nbtstat -c<br><br>ANARCHOI:<br>Adresse IP du noeud&nbsp;: [192.168.2.2] ID d'&eacute;tendue&nbsp;: []<br><br>                  Table de nom de cache distant NetBIOS<br><br>        Nom               Type        Adresse d'h&ocirc;te   Vie [sec]<br>    ------------------------------------------------------------<br>    ANARCHOI_LAPTOP  UNIQUE          192.168.2.9         227<br>    DBTOA000         UNIQUE          192.168.2.5         215<br>    DBTOA000         UNIQUE          192.168.2.5         215<br><br>Hamachi:<br>Adresse IP du noeud&nbsp;: [25.162.23.89] ID d'&eacute;tendue&nbsp;: []<br><br>                  Table de nom de cache distant NetBIOS<br><br>        Nom               Type        Adresse d'h&ocirc;te   Vie [sec]<br>    ------------------------------------------------------------<br>    ANARCHOI_LAPTOP  UNIQUE          25.207.9.158        187<br><br>Microsoft Windows [version 6.1.7601]<br>Copyright (c) 2009 Microsoft Corporation. Tous droits r&eacute;serv&eacute;s.<br><br>C:\Users\Anarchoi>nbtstat -n<br><br>ANARCHOI:<br>Adresse IP du noeud&nbsp;: [192.168.2.2] ID d'&eacute;tendue&nbsp;: []<br><br>                Table nom local NetBIOS<br><br>       Nom                Type         Statut<br>    ---------------------------------------------<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br>    WORKGROUP        UNIQUE      Inscrit<br>    ..__MSBROWSE__.  Groupe      Inscrit<br><br>Hamachi:<br>Adresse IP du noeud&nbsp;: [25.162.23.89] ID d'&eacute;tendue&nbsp;: []<br><br>                Table nom local NetBIOS<br><br>       Nom                Type         Statut<br>    ---------------------------------------------<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br>    ANARCHOI-PC      UNIQUE      Inscrit<br>    WORKGROUP        Groupe      Inscrit<br><br>C:\Users\Anarchoi><br><br>Microsoft Windows [version 6.1.7601]<br>Copyright (c) 2009 Microsoft Corporation. Tous droits r&eacute;serv&eacute;s.<br><br>C:\Users\Anarchoi>nbtstat -s<br><br>ANARCHOI:<br>Adresse IP du noeud&nbsp;: [192.168.2.2] ID d'&eacute;tendue&nbsp;: []<br><br>Table de connexion NetBIOS<br><br>    Nom local              &Eacute;tat     Ent/Sor H&ocirc;te Distant          Entr&eacute;e Sortie<br>    ---------------------------------------------------------------------------<br>    ANARCHOI-PC      Connect&eacute;      Sortie               DBTOA000<br>      665B         656B<br><br>Hamachi:<br>Adresse IP du noeud&nbsp;: [25.162.23.89] ID d'&eacute;tendue&nbsp;: []<br><br>    Aucune connexion<br><br>C:\Users\Anarchoi>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27848073</guid>
<pubDate>Fri, 21 Dec 2012 22:58:53 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27847692</link>
<description><![CDATA[Just Bob posted : Have you checked to see if you can find pimp.exe anywhere on your computer?<br><br>If so, it may or may not be a problem, but this is the most authoritative source I've found:<br>&raquo;<A HREF="http://www.prevx.com/filenames/X1612480113889191672-X1/PIMP.EXE.html" >www.prevx.com/filenames/X1612480&middot;&middot;&middot;EXE.html</A><br><small>--<br>"...an imbalance between rich and poor is the oldest and most fatal ailment of all republics." Plutarch<br>Judging other people is easy. Understanding them can break your heart.<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27847692</guid>
<pubDate>Fri, 21 Dec 2012 20:28:35 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27847283</link>
<description><![CDATA[NetFixer posted : <div class="bquote"><said>said by Teknikal01 :</said><p>Wireless is simple unsecure - Despite the security/authentication protocols....<br><br>You would have better luck with a wired network. <br> </p></div>And some posters would have better luck if they actually read a thread before responding to it.  :uhh:<br><small>--<br><A HREF="http://nature-pics.com">We can never have enough of nature.</a><br>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27847283</guid>
<pubDate>Fri, 21 Dec 2012 17:57:11 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27847138</link>
<description><![CDATA[anon posted : Wireless is simple unsecure - Despite the security/authentication protocols....<br><br>You would have better luck with a wired network. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27847138</guid>
<pubDate>Fri, 21 Dec 2012 16:51:13 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27845284</link>
<description><![CDATA[HELLFIRE posted : <div class="bquote"><said>said by anarchoi2 :</said><p>- "PIMP" is still here even if i turn off wifi. Not a wifi problem.<br>- If i turn off internet, "PIMP" will diseappear after around 15 minutes </p></div>Okay, that DEFINATELY helps clarify and narrow things down.<br><br><div class="bquote"><said>said by anarchoi2 :</said><p>The website asked me to download a VPN software to connect to a Russian IP to download the game from Steam because it was meant to be available only for russians users. </p></div>What website was this, and what "VPN" software did you have to download / install?<br><br>Also agree with  Lagz <A HREF="/useremail/u/195618"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> in that is the VPN software still running on Anarchoi-Pc and Anarchoi-Laptop<br>at the time "PIMP" is visible?<br><br>Also, from the command prompt, try "nbtstat -c" "nbtstat -n" and "nbtstat -S" and post the results<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27845284</guid>
<pubDate>Fri, 21 Dec 2012 04:09:07 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27841677</link>
<description><![CDATA[Lagz posted : Sorry I missed the VPN post earlier. This is probably related to the VPN since pimp is only visible from those computers. Have you uninstalled the VPN or do you need it to play the game? What VPN did you install?<br><br>edit: It seems steam isn't to particularly fond of VPN's.<br><small>--<br>When somebody tells you nothing is impossible, ask him to dribble a football.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27841677</guid>
<pubDate>Thu, 20 Dec 2012 06:26:58 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27841422</link>
<description><![CDATA[anon posted : Ok after some investigations:<br><br>- "PIMP" is still here even if i turn off wifi. Not a wifi problem.<br>- If i turn off internet, "PIMP" will diseappear after around 15 minutes<br><br>Like i explained earlier, a few days ago i bought Borderlands 2 in digital game. The website asked me to download a VPN software to connect to a Russian IP to download the game from Steam because it was meant to be available only for russians users.<br>"Anarchoi-pc" and "Anarchoi-Laptop" were exposed to the VPN files that may have been infected.<br><br>Notes:<br>- I use the default settings of my router<br>- I'm on DSL (Distributel) and Windows 7 on almost all PC.<br>- "PIMP" is only visible from the computers that were exposed to the Russian VPN files. When i check the network from my HTPC, i can't see "PIMP" !!!<br>- I don't have Ethernet over power line.<br>- I don,t have an apartment with built-in ethernet.<br><br>Some screenshots:<br><br>From my main computer (Anarchoi-Pc) that was exposed to the russian VPN<br>&raquo;<A HREF="http://www.ni-dieu-ni-maitre.com/_uploads/pimp1.jpg" >www.ni-dieu-ni-maitre.com/_uploads/pimp1.jpg</A><br><br>From my laptop (Anarchoi-Laptop) that was exposed to the russian VPN<br>&raquo;<A HREF="http://www.ni-dieu-ni-maitre.com/_uploads/pimp2.jpg" >www.ni-dieu-ni-maitre.com/_uploads/pimp2.jpg</A><br><br>Another screenshot from my Laptop. Note that "PIMP" is now displayed as a media share (it happens rarely)<br>&raquo;<A HREF="http://www.ni-dieu-ni-maitre.com/_uploads/pimp2b.jpg" >www.ni-dieu-ni-maitre.com/_uploa&middot;&middot;&middot;mp2b.jpg</A><br><br>Screenshot from my HTPC that was NOT exposed to the russian VPN. Note that "PIMP" is not visible from this computer<br>&raquo;<A HREF="http://www.ni-dieu-ni-maitre.com/_uploads/pimp3.jpg" >www.ni-dieu-ni-maitre.com/_uploads/pimp3.jpg</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27841422</guid>
<pubDate>Thu, 20 Dec 2012 05:49:10 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27841477</link>
<description><![CDATA[Doctor Olds posted : <div class="bquote"><said>said by anarchoi2 :</said><p>Yesterday i noticed a new computer was listed in my network computers... It's called "PIMP"<br> </p></div>Post a screenshot of that please.<br><br>&raquo;<A HREF="/faq/softapps">Software FAQ</A> &raquo;<A HREF="/faq/14188">How do I make a Screenshot?</A><br><br>&raquo;<A HREF="/faq/devnull">/dev/null forum FAQ</A> &raquo;<A HREF="/faq/2901">How do I post attachments &amp; screen shots?</A><br><small>--<br><A HREF="http://www.thetruthaboutcars.com/ford-gt/">What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27841477</guid>
<pubDate>Thu, 20 Dec 2012 00:45:11 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840660</link>
<description><![CDATA[NetFixer posted : I have no way to know how your network is setup, but if you have an Ethernet over power line switch/bridge in your network, they can be a  bigger security risk than WiFi. Most such devices can be setup reasonably securely, but the factory default values (which are often not changed) can leave them wide open for intrusion by anyone attached to the same power circuit. I have run into multiple cases where the end user had such devices, but did not have a clue about what they were or the security implications.<br><br>Another possibility if you live in an apartment that has built-in Ethernet distribution between rooms, is that your connections may be accessible from another apartment if the apartment building's wiring or VLAN setup is not done properly. Like the Ethernet over power line switch/bridge mentioned above, I have run into this situation too.<br><small>--<br><A HREF="http://nature-pics.com">We can never have enough of nature.</a><br>We need to witness our own limits transgressed, and some life pasturing freely where we never wander.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840660</guid>
<pubDate>Wed, 19 Dec 2012 19:45:26 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840578</link>
<description><![CDATA[HELLFIRE posted : Guessing this was in Windows Network Neighborhood?  Got a screenshot?<br><br>Can you view the FVS318N's ARP table, or DHCP leases?<br><br>If wifi's off and this 'PIMP' is still there, I'd start looking at the physical connections.<br><br><div class="bquote"><said>said by anarchoi2 :</said><p>What the hell happenned ? WPA2 is almost impossible to crack, right ?<br> </p></div><u><b>IF</b></u>  it is configured right... but there's the old adage, "if it was made by human hands, it<br>can be broken by human hands."<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840578</guid>
<pubDate>Wed, 19 Dec 2012 19:19:09 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840560</link>
<description><![CDATA[Ken1943 posted : What OS and internet connection cable/dsl]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840560</guid>
<pubDate>Wed, 19 Dec 2012 19:13:11 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840437</link>
<description><![CDATA[Juggernaut posted : Do a router FW upgrade lately?  :hmm:<br><br>At this point, I'll bet the router has been breached someway, somehow. Try a different router, and see what happens. <br><small>--<br>"I fear the day that technology will surpass our human interaction. The world will have a generation of idiots." ~ Albert Einstein</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840437</guid>
<pubDate>Wed, 19 Dec 2012 18:35:19 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840374</link>
<description><![CDATA[anon posted : I have just ran full scans of AVG, Malware Bytes and Ad-Aware. Everything should be clean, but there's still the intruder in my network.<br><br>I have tryed turning off my computer, then logging on the network from a laptop and the intruder is still connected to the network !!!! So it can't be a virus since my computer was off...<br><br>I don't understand...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840374</guid>
<pubDate>Wed, 19 Dec 2012 18:31:13 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840316</link>
<description><![CDATA[Juggernaut posted : Or, a bot.<br><br>I'd disconnect and work from another computer if possible. As suggested, see if you can download MalwareBytes to your drive, run it, and update it. Or, download MalwareBytes from a safe computer onto a thumb drive, and try to load it to your box that way.<br><br>If all else fails, go to &raquo;<A HREF="/forum/cleanup">Security Cleanup</A> and follow the instructions first.<br><small>--<br>"I fear the day that technology will surpass our human interaction. The world will have a generation of idiots." ~ Albert Einstein</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840316</guid>
<pubDate>Wed, 19 Dec 2012 17:57:40 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840106</link>
<description><![CDATA[anon posted : I just disabled wifi on my router, and the intruder is still in my network !!! This is definatly a trojan or something.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840106</guid>
<pubDate>Wed, 19 Dec 2012 17:48:06 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27839922</link>
<description><![CDATA[anon posted : I don't know, i'm using a Netgear ProSafe FVS318N]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27839922</guid>
<pubDate>Wed, 19 Dec 2012 16:28:23 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27840026</link>
<description><![CDATA[Juggernaut posted : Why don't you turn off the wifi until you get this fixed? I sure the heck would! You are responsible for whatever this person is downloading, or doing on your connection. <br><small>--<br>"I fear the day that technology will surpass our human interaction. The world will have a generation of idiots." ~ Albert Einstein</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27840026</guid>
<pubDate>Wed, 19 Dec 2012 16:22:31 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27839889</link>
<description><![CDATA[Lagz posted : <div class="bquote"><said>said by anarchoi2 :</said><p>Yesterday i noticed a new computer was listed in my network computers... It's called "PIMP"<br><br>I don't have any computers using that name so i thought i had been hacked.<br><br>I don't understand how it happenned since my password isn't easy to guess and i am using WPA2/PSK<br><br>So i changed my network password and even changed the network name. Then today, the intruder is back in my network again.<br><br>What the hell happenned ? WPA2 is almost impossible to crack, right ?<br> </p></div>Does your device have WPS? <br>&raquo;<A HREF="http://en.wikipedia.org/wiki/Wi-Fi_Protected_Setup#Security" >en.wikipedia.org/wiki/Wi-Fi_Prot&middot;&middot;&middot;Security</A><br><small>--<br>When somebody tells you nothing is impossible, ask him to dribble a football.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27839889</guid>
<pubDate>Wed, 19 Dec 2012 15:51:53 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27839587</link>
<description><![CDATA[EGeezer posted : <div class="bquote"><said>said by anarchoi2 :</said><p>... I recently had to use a VPN software to connect to Russia to download a digital game i bought... Is it possible that there was a virus inside the VPN or something like that ? <br></p></div>I would guess your computer has a remote access trojan. I recommend downloading Malwarebytes free scanner, disconnecting the PC(s) from the network and running a full scan of all systems that were on the network with it. <br><br>Then follow the steps in &raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A> and &raquo;<A HREF="/forum/cleanup">Security Cleanup</A> <br><br>I'd also recommend a factory reset and re-configuration of your router after the scan. <br><small>--<br>Buckle Up. It makes it harder for the aliens to suck you out of your car.<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27839587</guid>
<pubDate>Wed, 19 Dec 2012 14:41:00 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27839497</link>
<description><![CDATA[anon posted : I just changed my password and SSID name again, and 10 minutes after the intruder with computer name "PIMP" is back in my network... Is it really possible to crack WPA2 in only a few minutes ?<br><br>Also i live in a small town i doubt there are computer nerds around my house that could crack my wifi...<br><br>I recently had to use a VPN software to connect to Russia to download a digital game i bought... Is it possible that there was a virus inside the VPN or something like that ?<br><br>I'm not sure what TKIP and AES is...<br><br>My settings are:<br>Security - WPA2<br>Encryption - CCMP<br>Auth: PSK]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27839497</guid>
<pubDate>Wed, 19 Dec 2012 14:24:44 EDT</pubDate>
</item>

<item>
<title>Re: intruder in my network</title>
<link>http://www.dslreports.com/forum/Re-intruder-in-my-network-27839362</link>
<description><![CDATA[Sarick posted : Was it set to AES or TKIP <br><br>TKIP is known to have security issues. (use AES)<br> <br>If your password is under 20 characters fix it. Use something like this.<br><br>&raquo;<A HREF="https://www.grc.com/passwords.htm" >www.grc.com/passwords.htm</A> <br><br>Last make sure your access point doesn't have a common SSID name. The SSID name is used as part of the encryption.  People have created rainbow tables for common names. These give shortcuts shortcuts in breaking in Wi-fi.<br><small>--<br><A HREF="http://www.frontiernet.net/~sarick/dunart/main.htm">Sarick's Dungeon Clipart</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-intruder-in-my-network-27839362</guid>
<pubDate>Wed, 19 Dec 2012 13:53:15 EDT</pubDate>
</item>

<item>
<title>intruder in my network</title>
<link>http://www.dslreports.com/forum/intruder-in-my-network-27839259</link>
<description><![CDATA[anon posted : Yesterday i noticed a new computer was listed in my network computers... It's called "PIMP"<br><br>I don't have any computers using that name so i thought i had been hacked.<br><br>I don't understand how it happenned since my password isn't easy to guess and i am using WPA2/PSK<br><br>So i changed my network password and even changed the network name. Then today, the intruder is back in my network again.<br><br>What the hell happenned ? WPA2 is almost impossible to crack, right ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/intruder-in-my-network-27839259</guid>
<pubDate>Wed, 19 Dec 2012 13:27:46 EDT</pubDate>
</item>

</channel>
</rss>
