TheTechGuide Forum

General Category => Tech Clinic => Topic started by: Allanon on January 01, 2007, 05:20:51 PM

Title: Friend having computer troubles
Post by: Allanon on January 01, 2007, 05:20:51 PM
Well he can't post but this is what he told me to say

Quote
Hi, could somewon please help me, all of my computer has been hacked, i play runescape, all my accounts and items have been taken, i used to speak with the hacker on RS a few times, so i added him to msn, he explained what he done, (took my accounts my gp, my msn, my website) he explained that he sent me a .EXE file.. that connected to his computer through a port, from there he said he sent me an "exploit bug" that he made himself, he said it's attached to my system files, somewon please help, he is threatening to destroy my whole pc, i have norton anti-virus, spybot search and destroy, spyware doctor along with windows security system materials.. i ran countless scans and i keep removing the trojans bugs and registry changes he put on my computer, yet i can't seem to shake them off, they keep coming back after a few hours.. he can see everything i'm doing he also sees my password... i'm growing tired of it, my computer is running it's slowest since it was purchased, if anywon could recommend a program to rid these trojans and exploit bugs, please post here, OR I AM F--KED...
...:::Ryan:::... - The Supreme one, join W/E Now... Mod On Rs2MM. W>E! says:
please an expert help me here, he really is mangling my pc and i feel as if my privacy is gravely invaded...

any suggestions and support would greatly be appreciated.

Ryan...
Title: Friend having computer troubles
Post by: ~*Blak*~ on January 01, 2007, 05:28:09 PM
try system restore
Title: Friend having computer troubles
Post by: guestolo on January 01, 2007, 05:58:28 PM
Allanon, can you have your friend run a couple quick scans for me please

1. Download this file - Combofix.exe (http://\"http://download.bleepingcomputer.com/sUBs/combofix.exe\") and save it too desktop
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. Post the log please
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post the log from Combofix

2. Can you have him post a log from Hijackthis
Instructions are at the top of this forum

He'll have to email you the logs I guess and you can post the contents here
Title: Friend having computer troubles
Post by: lordlazer on January 01, 2007, 07:46:14 PM
i agree with blak save everything ABSOLUTELY needed to disk and restore your computer to the earliest date possible and your computer will be like brand new
Title: Friend having computer troubles
Post by: Mod Ryan on January 01, 2007, 11:13:35 PM
Hey guys it's the person who has been having the problem, ok guestolo, the problem is over FOR NOW, but thats only because i was tackling the RAT myself, he must have seen i was almost shutting him out, cause he delete a main windows file, my computer shut down immedeintly, and wouldn't run windows, so i just stuck in the formatting DVD's, i didn't have a chance to back up my files... my music and pictures are gone. along with my other e-mail address ETC, but questolo, i dont know if it's going to come back, do you think he will? or can he do it without sending me an EXE and getting a direct link between himself and i? i dont know, i still dont feel 100% safe.
Title: Friend having computer troubles
Post by: guestolo on January 02, 2007, 12:22:01 AM
Do you know what system file got deleted?
Title: Friend having computer troubles
Post by: Mod Ryan on January 02, 2007, 12:34:23 AM
i'll have a look, will edit..

Well, i'm pretty sure it was the system file CSRSS.EXE, or it was my whole Win32 Folder, all i need to know is that now iv'e completely formatted my hard drive, does he still have access, and or, can he access me without a direct port again?
Title: Friend having computer troubles
Post by: guestolo on January 02, 2007, 12:48:36 AM
I doubt if he can get access if you set up proper protection
A good firewall & AntiVirus
Since you just clean installed, make sure you have the latest High Priority Windows Updates!!!

I would also put in some protections such as SpywareBlaster <--I can give instructions
Do you have your own AV and Firewall to install
Or do you need a free link?

In case you had some kind of keylogger, I would immediately change passwords to all online accounts

Eg... Emails, online banking, etc...
Title: Friend having computer troubles
Post by: Mod Ryan on January 02, 2007, 12:52:54 AM
Well Questolo, it's a little late for that, luckily my Credit card ran out a week before this happened, because he took my paypal account aswell, i did have proper protection though, i have norton anti+spyware 2007, i also have ad-aware, spyware doctor and AVG Anti-virus, as i said, he sent me an executable file, when i clicked it, it opened a port up so my computer would have a direct link with his, all he had to do was deply his "exploit bug" to my system folders, that way if i was to find and delete them, my system would fail, i tryed an alternative method though, i was in the middle and last step of closing the port to shut him out, my system crashed and it came up with an error, i had to format.

as for you'r suggestion, is spyblaster good, better than ones i have at the moment,?

Thanks for the help bud.

Ryan.
Title: Friend having computer troubles
Post by: guestolo on January 02, 2007, 01:06:17 AM
Do you have both Norton AntiVirus + AVG AntiVirus
Having more than one AV running is not really a better thing, it's actually worse
They conflict with each other and can cause System instabilities

I would remove one and stick with the one your happiest with

Do you have a good software firewall setup?
This way you can filter incoming and outgoing traffic to your computer
I've been using Comodo free firewall lately, I'm very happy with it so far
I have a link to it at the top of the forum if needed, with others
Again, only use one Firewall software
Here's some more info on Firewalls
Understanding and using Firewalls (http://\"http://www.bleepingcomputer.com/tutorials/tutorial60.html\")

SpywareBlaster just sets registry killbits
Have a look see
SpywareBlaster 3.5.1 by JavaCool (http://\"http://www.javacoolsoftware.com/spywareblaster.html\")   After installation, Check for updates
After updating, select "Protection" on the Left
Then select "Enable all Protection"
"Check for updates every couple of weeks"
after every update just simply click the "enable protection on all unprotected items"


Wouldn't hurt to add a good Host file
http://www.mvps.org/winhelp2002/hosts.htm (http://\"http://www.mvps.org/winhelp2002/hosts.htm\")
Here's more info on how to download and extract it
http://www.mvps.org/winhelp2002/hosts2.htm (http://\"http://www.mvps.org/winhelp2002/hosts2.htm\")
You will want to do this once a month

Be very careful with anything you download from the Internet, I'm sure your aware of that
Have it scanned first with an updated AV before you open it
I wouldn't trust anyone, even if it was my Mom sending me an .exe  /laugh.gif\' class=\'bbc_emoticon\' alt=\':lol:\' />
She wouldn't know if it was good or bad anyways, hee hee
Title: Friend having computer troubles
Post by: Mod Ryan on January 02, 2007, 01:18:49 AM
lmao, yeah, well before you posted i noticed in the firewall sticky "comodo", i just downloaded it there and so far, it looks good thanks for that i owe you one lol /wink.gif\' class=\'bbc_emoticon\' alt=\';)\' />, i'll also take a check up on spyblaster, it doesn't look too bad, i also just removed AVG, norton normally does the jump of real-time protection, but when i run an AVG scan it normally picks up more than norton, i usually have AVG disabled and once a week i run a virus scan with AVG, but heh it's fixed now, as for the "hosts file" i'm not too familiar with that, is it for finding ip address' and seeing what component is connected, i had a quick flick through the wikipedia, but i'm still not 100% sure.
Title: Friend having computer troubles
Post by: guestolo on January 02, 2007, 01:26:39 AM
After you have Comodo installed
Run the Scan for know applications wizard, found under the Security tab
This way you won't be prompted for everything allowable
I can't remember if it runs automatically on install, but run it just in case /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Host file
I can't explain better what a Host file is as Winhelp2002  can, the first link I gave you explains it pretty well
Title: Friend having computer troubles
Post by: Mod Ryan on January 02, 2007, 01:29:45 AM
Alright, thanks again for you'r help questolo, hope to be talking more to you mate.
Title: Friend having computer troubles
Post by: guestolo on January 02, 2007, 01:37:02 AM
No problems Ryan
I'll lock this topic as you seem to have things in hand
Take care  /smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />