Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 37

Thread: Was I Hacked?

  1. #11
    lynx's Avatar .
    Join Date
    Sep 2002
    Location
    Yorkshire, England
    Posts
    9,759
    Originally posted by TheKiler@11 June 2004 - 05:19
    No, I've been doing some research for my school. That was it.
    You didn't do anything silly did you?

    Like actually take your pc to school and plug it into the network?
    .
    Political correctness is based on the principle that it's possible to pick up a turd by the clean end.

  2. Software & Hardware   -   #12
    No, I havent. I've scanned for the trojans and it found nothing. HELP :helpsmile:

  3. Software & Hardware   -   #13
    Poster
    Join Date
    Jun 2003
    Posts
    126
    well, seeing as you are at a loss, try this.

    download hijack this here.

    unzip into it's own folder and scan and save a log.

    post the contents here.

    good luck.

  4. Software & Hardware   -   #14
    Logfile of HijackThis v1.97.7
    Scan saved at 4:16:29 PM, on 6/11/2004
    Platform: Windows XP SP1, v.2096 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2096)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\protowall\ProtoWall.exe
    C:\Program Files\MYIE2\MyIE.exe
    C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe
    C:\DOCUME~1\STEPHE~1\LOCALS~1\Temp\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 216.165.109.81:3128
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: Shell=explorer.exe ,svchost.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
    O4 - HKCU\..\Run: [ProtoWall] C:\Program Files\protowall\ProtoWall.exe
    O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v4.windowsupdate.microsoft.com/v5co...b?1086544794265
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/...8073.5604282407
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab

  5. Software & Hardware   -   #15
    Poster
    Join Date
    Jun 2003
    Posts
    126
    ok. first please unzip hijack this into it's own folder. running it from the zip file is risky, since the backups will be deleted as soon as you clear your temp files.

    this item I have a question about:
    F2 - REG:system.ini: Shell=explorer.exe ,svchost.exe

    did you set that shell up yourself? if not, you can also check it with hijack this.

    rescan and check the following:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    close all browser windows and hit fix checked.

    I see you have nod32 still installed, but it isn't listed in your running processes.

    the corresponding 010 item is also missing.

    I suggest you go offline, and uninstall/reinstall your nod32 software.

    before doing that, though, using internet explorer, do an online virus scan here: http://housecall.trendmicro.com/hous...start_corp.asp

  6. Software & Hardware   -   #16
    Ok.. I get this now:

    

    IHDR , * F? pHYs   
    xڝSwX>eVBl "#Y a@Ņ
    VHUĂ
    H(gAZU&#092;8ܧ}zy&j 9R<:OHɽH g yx~t?o  p.&#036;P&W " R .T  Sd
    ly|B"
    I> ة آ  (G&#036;@ `UR, @".Y2G vX@` B, 8 C L0ҿ_pH ˕͗K3w&#33;lBa)f "#HL 8?flŢko">&#33; N_puk[ V h]3 Z
    zy8@P<
    %b0>3o~@z q@qanvRB1n#Dž)4&#092;,XP"MyRD&#33;ɕ2 w
    ONl~Xv @~- g42y @+ ͗ &#092;L D*A aD@ &#036;<B

  7. Software & Hardware   -   #17
    Poster
    Join Date
    Jun 2003
    Posts
    126
    did you fix the f2 item?

    and is this after a reboot? please elaborate.

    do run the virus scan as well.

    post a new log.

  8. Software & Hardware   -   #18
    F2 problem?

    I&#39;ve scanned again and I got this again

    

    IHDR , * F? pHYs   
    xڝSwX>eVBl "#Y a@Ņ
    VHUĂ
    H (gAZU&#092;8ܧ}zy&j 9R<:OHɽH g yx~t?o  p.&#036;P&W " R .T  Sd
    ly|B"
    I> ة آ  (G&#036;@ `UR,&nbsp; @".Y2G vX@` B, 8 C L 0ҿ_pH ˕͗K3w&#33;lBa)f "#HL 8?flŢko">&#33; N_puk[ V h]3&nbsp; Z
    zy8@P<
    %b0>3o~@z q@qanvRB1n#Dž)4&#092;,XP"MyRD&#33;ɕ2 w
    ONl~Xv @~- g42y @+ ͗ &#092;L D *A aD@ &#036;<B
    Ive done virus scans with norton, symantec, panda, kaspersky, and nod32 and found absolutly nothing.

  9. Software & Hardware   -   #19
    Poster
    Join Date
    Jun 2003
    Posts
    126
    is that what happens when you try to run hijack this? i&#39;m lost here.

  10. Software & Hardware   -   #20
    Yea.. that&#39;s what i get for HiJack this..

Page 2 of 4 FirstFirst 1234 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •