TheTechGuide Forum
General Category => Tech Clinic => Topic started by: Allanon on January 01, 2007, 05:20:51 PM
-
Well he can't post but this is what he told me to say
Hi, could somewon please help me, all of my computer has been hacked, i play runescape, all my accounts and items have been taken, i used to speak with the hacker on RS a few times, so i added him to msn, he explained what he done, (took my accounts my gp, my msn, my website) he explained that he sent me a .EXE file.. that connected to his computer through a port, from there he said he sent me an "exploit bug" that he made himself, he said it's attached to my system files, somewon please help, he is threatening to destroy my whole pc, i have norton anti-virus, spybot search and destroy, spyware doctor along with windows security system materials.. i ran countless scans and i keep removing the trojans bugs and registry changes he put on my computer, yet i can't seem to shake them off, they keep coming back after a few hours.. he can see everything i'm doing he also sees my password... i'm growing tired of it, my computer is running it's slowest since it was purchased, if anywon could recommend a program to rid these trojans and exploit bugs, please post here, OR I AM F--KED...
...:::Ryan:::... - The Supreme one, join W/E Now... Mod On Rs2MM. W>E! says:
please an expert help me here, he really is mangling my pc and i feel as if my privacy is gravely invaded...
any suggestions and support would greatly be appreciated.
Ryan...
-
try system restore
-
Allanon, can you have your friend run a couple quick scans for me please
1. Download this file - Combofix.exe (http://\"http://download.bleepingcomputer.com/sUBs/combofix.exe\") and save it too desktop
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. Post the log please
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Post the log from Combofix
2. Can you have him post a log from Hijackthis
Instructions are at the top of this forum
He'll have to email you the logs I guess and you can post the contents here
-
i agree with blak save everything ABSOLUTELY needed to disk and restore your computer to the earliest date possible and your computer will be like brand new
-
Hey guys it's the person who has been having the problem, ok guestolo, the problem is over FOR NOW, but thats only because i was tackling the RAT myself, he must have seen i was almost shutting him out, cause he delete a main windows file, my computer shut down immedeintly, and wouldn't run windows, so i just stuck in the formatting DVD's, i didn't have a chance to back up my files... my music and pictures are gone. along with my other e-mail address ETC, but questolo, i dont know if it's going to come back, do you think he will? or can he do it without sending me an EXE and getting a direct link between himself and i? i dont know, i still dont feel 100% safe.
-
Do you know what system file got deleted?
-
i'll have a look, will edit..
Well, i'm pretty sure it was the system file CSRSS.EXE, or it was my whole Win32 Folder, all i need to know is that now iv'e completely formatted my hard drive, does he still have access, and or, can he access me without a direct port again?
-
I doubt if he can get access if you set up proper protection
A good firewall & AntiVirus
Since you just clean installed, make sure you have the latest High Priority Windows Updates!!!
I would also put in some protections such as SpywareBlaster <--I can give instructions
Do you have your own AV and Firewall to install
Or do you need a free link?
In case you had some kind of keylogger, I would immediately change passwords to all online accounts
Eg... Emails, online banking, etc...
-
Well Questolo, it's a little late for that, luckily my Credit card ran out a week before this happened, because he took my paypal account aswell, i did have proper protection though, i have norton anti+spyware 2007, i also have ad-aware, spyware doctor and AVG Anti-virus, as i said, he sent me an executable file, when i clicked it, it opened a port up so my computer would have a direct link with his, all he had to do was deply his "exploit bug" to my system folders, that way if i was to find and delete them, my system would fail, i tryed an alternative method though, i was in the middle and last step of closing the port to shut him out, my system crashed and it came up with an error, i had to format.
as for you'r suggestion, is spyblaster good, better than ones i have at the moment,?
Thanks for the help bud.
Ryan.
-
Do you have both Norton AntiVirus + AVG AntiVirus
Having more than one AV running is not really a better thing, it's actually worse
They conflict with each other and can cause System instabilities
I would remove one and stick with the one your happiest with
Do you have a good software firewall setup?
This way you can filter incoming and outgoing traffic to your computer
I've been using Comodo free firewall lately, I'm very happy with it so far
I have a link to it at the top of the forum if needed, with others
Again, only use one Firewall software
Here's some more info on Firewalls
Understanding and using Firewalls (http://\"http://www.bleepingcomputer.com/tutorials/tutorial60.html\")
SpywareBlaster just sets registry killbits
Have a look see
SpywareBlaster 3.5.1 by JavaCool (http://\"http://www.javacoolsoftware.com/spywareblaster.html\") *Will block bad ActiveX Controls
*Block Malevolent cookies in Internet Explorer and Firefox
*Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates
After updating, select "Protection" on the Left
Then select "Enable all Protection"
"Check for updates every couple of weeks"
after every update just simply click the "enable protection on all unprotected items"
Wouldn't hurt to add a good Host file
http://www.mvps.org/winhelp2002/hosts.htm (http://\"http://www.mvps.org/winhelp2002/hosts.htm\")
Here's more info on how to download and extract it
http://www.mvps.org/winhelp2002/hosts2.htm (http://\"http://www.mvps.org/winhelp2002/hosts2.htm\")
You will want to do this once a month
Be very careful with anything you download from the Internet, I'm sure your aware of that
Have it scanned first with an updated AV before you open it
I wouldn't trust anyone, even if it was my Mom sending me an .exe
/laugh.gif\' class=\'bbc_emoticon\' alt=\':lol:\' />
She wouldn't know if it was good or bad anyways, hee hee
-
lmao, yeah, well before you posted i noticed in the firewall sticky "comodo", i just downloaded it there and so far, it looks good thanks for that i owe you one lol
/wink.gif\' class=\'bbc_emoticon\' alt=\';)\' />, i'll also take a check up on spyblaster, it doesn't look too bad, i also just removed AVG, norton normally does the jump of real-time protection, but when i run an AVG scan it normally picks up more than norton, i usually have AVG disabled and once a week i run a virus scan with AVG, but heh it's fixed now, as for the "hosts file" i'm not too familiar with that, is it for finding ip address' and seeing what component is connected, i had a quick flick through the wikipedia, but i'm still not 100% sure.
-
After you have Comodo installed
Run the Scan for know applications wizard, found under the Security tab
This way you won't be prompted for everything allowable
I can't remember if it runs automatically on install, but run it just in case
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
Host file
I can't explain better what a Host file is as Winhelp2002 can, the first link I gave you explains it pretty well
-
Alright, thanks again for you'r help questolo, hope to be talking more to you mate.
-
No problems Ryan
I'll lock this topic as you seem to have things in hand
Take care
/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />