Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

Threaded View

everytime when I'm online, Kaspersky Internet Securite 6 (the
Anti-Hacker-module) says:

Intrusion.Win.MSSQL.worm.Helkern Adresse    UDP Port 1434


Any hint what happened, what that is/mean? THX in advance.

by(e) PS
spam will be killed

Re: Intrusion.Win.MSSQL.worm.Helkern

Quoted text here. Click to load it

I've always thought those were hackers looking for open computers.

Below is what showed for
the IP address you listed. Kerio Personal Firewall has shown me stuff like
your post a lot of times. I deny the connection, look up the IP at geektools,
then e-mail the Provider with a complaint with a copy/paste of the info
KPF provided me.

Final results obtained from
% [ node-1]
% Whois data copyright terms

inetnum: -
netname: CHINANET-SN
descr: CHINANET shanxi(SN) province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: XC10-AP
mnt-by: APNIC-HM
remarks: This object can only modify by APNIC hostmaster
remarks: If you wish to modify this object details please
remarks: send email to with your
remarks: organisation account name in the subject line.
changed: 20040224
source: APNIC

person: Chinanet Hostmaster
nic-hdl: CH93-AP
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: 20051212
source: APNIC

person: Xianghong Cao
address: Shaanxi province data communication Bureau
address: 8# guangde Road west development zone
address: Xi'an city, Shanxi province 710075
address: CN
phone: +8629-837-1049
fax-no: +8629-837-1049
nic-hdl: XC10-AP
changed: IPADM@PUBLIC.XA.SN.CN 20011203
source: APNIC

Re: Intrusion.Win.MSSQL.worm.Helkern

Quoted text here. Click to load it
Take a look at

Replies to: Nherr1professor2doktor31109(at)Oyahoo(dot)Tcom

Re: Intrusion.Win.MSSQL.worm.Helkern

| Intrusion.Win.MSSQL.worm.Helkern Adresse UDP Port 1434

| blocked

| Any hint what happened, what that is/mean? THX in advance.

It sounds like activity at the FireWall.  If you were using a NAT Router then you
would not see the activity at all on the PC and would only be at the Router.

It looks like just information.  You can think of it as just "noise" and can be


Re: Intrusion.Win.MSSQL.worm.Helkern

Peter Seiler wrote:
Quoted text here. Click to load it

You don't have MS SQL Server running on your computer. MS SQL Server
runs and uses post 1434. If SQL Server is not running on your computer
and it most likely is not, then there is nothing to attack the port is
not being used.

Duane :)

Re: Intrusion.Win.MSSQL.worm.Helkern

Peter Seiler - 11.03.2006 10:42 :

THX to all who reposted.

by(e) PS
spam will be killed

Site Timeline