Author Topic: Am I being hacked ?  (Read 9748 times)

labatvi

  • Newbie
  • *
  • Posts: 1
Am I being hacked ?
« on: February 25, 2014, 04:15:14 AM »
Hi

I am not sure if this log information can tell if I am being hacked
I think something keep sending my machine information to other teamviewer ID  862048129

2014/02/23 20:01:11.821  1036  3616 S0   CT3 CT.Send.CMD_ROUTERCMD From=167963052 To=862048129 L=59
2014/02/23 20:01:11.821  1036  5800 S0   CT31 CT.Run
2014/02/23 20:01:11.821  1036  5800 S0   CT31 TM.TM_GWout
2014/02/23 20:01:11.821  1036  5800 S0   CT31 CT.Run.LoopEnd
2014/02/23 20:03:10.337  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 20:33:54.243  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 21:04:35.430  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 21:35:15.555  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 22:05:56.790  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 22:36:36.665  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 23:07:13.899  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/23 23:37:43.321  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 00:08:10.805  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 00:38:38.196  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 01:09:06.446  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 01:39:34.290  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 02:10:04.993  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 02:40:32.665  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 03:11:00.649  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 03:41:28.259  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 04:11:56.634  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 04:42:24.165  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 05:12:56.009  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 05:43:23.555  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 06:13:51.055  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 06:44:18.508  1036  3616 S0   CT3 CConnectionThread::CmdPingRouter(): Router Pong Received with following Hops: 167963052 862048129
2014/02/24 07:09:20.555  1036  3616 S0   CT3 CT.Receive.CMD_ROUTERCMD From=862048129 To=167963052 L=414
2014/02/24 07:09:20.570  1036  3616 S0   CT33 CT.TM_GWout.203.162.172.5 - CT33 - S33
2014/02/24 07:09:20.570  1036  3616 S0   CT33 CT.Connect to TeamViewer Router 203.162.172.5:5938
2014/02/24 07:09:20.586  1036  3616 S0   CT33 CT.Connected
2014/02/24 07:09:20.586  1036  3616 S0   CT33 CT.Send.CMD_IDENTIFY From=167963052 To=0 L=32
2014/02/24 07:09:20.586  1036  3616 S0   CT33 CT.Send.CMD_CONNECTTOWAITINGTHREAD From=167963052 To=0 L=48
2014/02/24 07:09:20.586  1036  3888 S0   CT34 CT.Run
2014/02/24 07:09:20.586  1036  3888 S0   CT34 TM.TM_TV
2014/02/24 07:09:20.586  1036  3616 S0!! CTerminalServer::StartDesktopProcess(): External connection failed for ID 167963052, SessionFound=1 UserLoggedIn=1 MultiUserFallbackMode=0 SessionID=0 User=workstation\administrator, Errorcode=997
2014/02/24 07:09:20.602  1036  3616 S0   SessionID=0 Name=Console State=WTSActive Detailed state=WTS_SESSION_LOCK User=workstation\administrator Console=1 RDPClientIP= RDPClientName= DyngateID=167963052


Could you please help me ? I can provide more log if you want. Thank you very much

matt

  • Hero Member
  • *****
  • Posts: 904
Re: Am I being hacked ?
« Reply #1 on: February 25, 2014, 07:04:09 AM »
Is that a teamviewer 'heartbeat'?
Every 30 minutes or so...

 

anything