Help Pls!!

kreigsmarine

New Member
a friend of mine has been learning hacking from a site and is now using his knowledge to **** me...He hacked my hi5 account and got my password and also sumhow got my yahoo password.
Now hes threatin to delete my hi5 account.I've changed my password but i dun think its gonna b of ny use cuz he can hack it again.hes also done sumthing to my account and changed my display name to "assho**".I changed it back to the original name,but when i logged in again in the evening,i found that that the name was again back to"assh***".He's told me that for the next 3 weeks i wont b able to see my normal name for 3 continous daze...How is he able to give me such a timeframe?has he hijacked my cookies or sumthin?
I dont think hes inserted a keylogger or sumthin like that in my comp cuz i've never accepted ny files from him..
nywaze..heres my hijackthis logfile,just in case u need it,
Logfile of HijackThis v1.99.1
Scan saved at 1:31:56 AM, on 6/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
E:\Program Files\NetMeter\NetMeter.exe
E:\Program Files\adobe\Distillr\AcroTray.exe
E:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Opera\Opera.exe
H:\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\program files\adobe\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [E:\Program Files\NetMeter\NetMeter.exe] E:\Program Files\NetMeter\NetMeter.exe
O4 - HKCU\..\RunOnce: [CleanUp!] C:\CleanUp!\Cleanup.exe /WindowsRestart
O4 - Startup: Anapod Manager.lnk = E:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Program Files\adobe\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

sumone pls help me..this things kinda freakin me out...u knoe itz not a very nice feelin to see assho** written in capital letters over ur foto!!
btw,hi5's an online community,for those of u who didnt knoe
i've also written to hi and am awaitin their reply
P.S-sorry if i've posted this in the wrong place..cudnt find ny place better..
 
I dont see anything in your log it looks clean. Did this person have access to your pc? There are only a few ways a person can hack something like a yahoo, hi5, myspace account ect ect.

#1 He actually hacked into their server and software (HIGHLY UNLIKELY) that takes alot of skill not something you learn in a few days.

#2 He has installed a backdoor trojan on your PC (thats why I asked if he had access to your pc) script kiddie programs.

#3 He just guessed your password because it was to easy.

This is what I would do!

#1 Download Ewido here http://www.ewido.net/en/download/ then update it's definitions and do a full system scan for trojans, I see you have a firewall and avg antivirus and thats great but unfortunately avg is not too great for detecting trojans!

#2 Change all your passwords to something random not your pets name or your wifes birthday ect ect...make them long, at least 10 characters and do not share them with anyone!

#3 Secure your PC, turn off remote assistance, secure file and printer sharing here is a link as to how to do it http://security.uchicago.edu/windows/netbios/index.shtml

#4 Make sure windows security patches are up to date http://update.microsoft.com/windowsupdate/v6/default.aspx?ln=en-us

#5 Test your firewall and make sure there are no open ports https://www.grc.com/x/ne.dll?bh0bkyd2

#6 Password protect everything on your PC set up a power on password, bios, log on ect ect.

#7 Tell him to hack you again after all this and post back...lol!
 
Last edited:
no he didnt hav access to my computer,cuz he lives in a different place.dont worry bout my passwords..they r random ones and there wuz no way he cud hav guessed them.I'm sure bout this because even after changing my password,he cud still change my name.
btw,ewido check came out clean...
 
Last edited:
Back
Top