|
|
#1 (permalink) |
|
New Member
![]() Join Date: Jun 2006
Posts: 2
|
a friend of mine has been learning hacking from a site and is now using his knowledge to **** me...He hacked my hi5 account and got my password and also sumhow got my yahoo password.
Now hes threatin to delete my hi5 account.I've changed my password but i dun think its gonna b of ny use cuz he can hack it again.hes also done sumthing to my account and changed my display name to "assho**".I changed it back to the original name,but when i logged in again in the evening,i found that that the name was again back to"assh***".He's told me that for the next 3 weeks i wont b able to see my normal name for 3 continous daze...How is he able to give me such a timeframe?has he hijacked my cookies or sumthin? I dont think hes inserted a keylogger or sumthin like that in my comp cuz i've never accepted ny files from him.. nywaze..heres my hijackthis logfile,just in case u need it, Logfile of HijackThis v1.99.1 Scan saved at 1:31:56 AM, on 6/19/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Skype\Phone\Skype.exe E:\Program Files\NetMeter\NetMeter.exe E:\Program Files\adobe\Distillr\AcroTray.exe E:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\Opera\Opera.exe H:\hijackthis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\program files\adobe\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - (no file) O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [E:\Program Files\NetMeter\NetMeter.exe] E:\Program Files\NetMeter\NetMeter.exe O4 - HKCU\..\RunOnce: [CleanUp!] C:\CleanUp!\Cleanup.exe /WindowsRestart O4 - Startup: Anapod Manager.lnk = E:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe O4 - Global Startup: Acrobat Assistant.lnk = E:\Program Files\adobe\Distillr\AcroTray.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe sumone pls help me..this things kinda freakin me out...u knoe itz not a very nice feelin to see assho** written in capital letters over ur foto!! btw,hi5's an online community,for those of u who didnt knoe i've also written to hi and am awaitin their reply P.S-sorry if i've posted this in the wrong place..cudnt find ny place better.. |
|
|
|
|
|
#2 (permalink) |
|
banned
Join Date: Feb 2005
Posts: 1,486
|
I dont see anything in your log it looks clean. Did this person have access to your pc? There are only a few ways a person can hack something like a yahoo, hi5, myspace account ect ect.
#1 He actually hacked into their server and software (HIGHLY UNLIKELY) that takes alot of skill not something you learn in a few days. #2 He has installed a backdoor trojan on your PC (thats why I asked if he had access to your pc) script kiddie programs. #3 He just guessed your password because it was to easy. This is what I would do! #1 Download Ewido here http://www.ewido.net/en/download/ then update it's definitions and do a full system scan for trojans, I see you have a firewall and avg antivirus and thats great but unfortunately avg is not too great for detecting trojans! #2 Change all your passwords to something random not your pets name or your wifes birthday ect ect...make them long, at least 10 characters and do not share them with anyone! #3 Secure your PC, turn off remote assistance, secure file and printer sharing here is a link as to how to do it http://security.uchicago.edu/windows...os/index.shtml #4 Make sure windows security patches are up to date http://update.microsoft.com/windowsu....aspx?ln=en-us #5 Test your firewall and make sure there are no open ports https://www.grc.com/x/ne.dll?bh0bkyd2 #6 Password protect everything on your PC set up a power on password, bios, log on ect ect. #7 Tell him to hack you again after all this and post back...lol! Last edited by cell4me; 06-18-2006 at 09:51 PM. |
|
|
|
|
|
#3 (permalink) |
|
New Member
![]() Join Date: Jun 2006
Posts: 2
|
no he didnt hav access to my computer,cuz he lives in a different place.dont worry bout my passwords..they r random ones and there wuz no way he cud hav guessed them.I'm sure bout this because even after changing my password,he cud still change my name.
btw,ewido check came out clean... Last edited by kreigsmarine; 06-19-2006 at 05:45 AM. |
|
|
|