Announcement

Collapse
No announcement yet.

Help! Was I hacked??

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Help! Was I hacked??

    I am pretty good about never getting viruses or malware/spyware/adware. Here is my perdicament:

    I left my computer for about an hour. When I came back, it was at the Windows user logon screen. I only have one user account on the computer, which is password protected. I saw 4 accounts. The other three were named "net", "asp.net", and "Support_256269a0" or something very similar to that. They were all password protected and had administrator privledges. One was logged in (the one named "net"). I checked Event Viewer and someone/something tried to "Connect to my machine". I forget exactly what it all said, but it was the only event under System that occured when I wasn't at my computer. I didn't see and rogue programs running under my account. I was able to remove the password for "net" and log onto it. The only thing open was the Windows Security window (that allows you to manage your Windows firewall, and anti-virus program). I logged out of that and deleted all the profiles.

    I don't use Windows firewall. I have a handfull of Windows updates to install. Symantec anti-virus Corporate runs daily. I unplugged my USB wireless adaptor when I saw all this (its the only way currently I can connect to the internet...no other wireless card, no ethernet connected). When I plugged it back in it did not work (but I didn't try to troubleshoot it beyond unplugging USB and plugging back in). Room mate #1's computer is on the network and didn't seem to be affected. I didn't check room mate #2's computer.

    I'm at work right now so I can't give a lot of specifics. I have it off the internet and turned off for the moment. Does anyone have any idea? I never get paranoid about computer problems but this one freaks me the fuck out.

  • #2
    The Support_xxxx account is used by Microsoft for support issues but I believe it's disabled by default.
    I recommend you disable it (Computer Management / Local users and groups) and also disable Remote Access / Remote Desktop (under System properties).

    In 'Local users and groups' you can see a description of each account; check if you see any unidentified accounts and check in what user group they are (if they are in administrators group for no reason, remove them).

    Do you have a good firewall and virus scanner? The virus scanner can prevent this by detecting and destroying trojans while the firewall prevents unauthorised access.
    Maverick
    Retired SSCU Trench Wars Super Moderator
    Retired SSCU Trench Wars Bot Coordinator
    Retired Trench Wars Core Administrator
    Subspace Statistics Administrator
    Former Mervbot plugin developer

    Comment


    • #3
      Originally posted by Maverick View Post
      The Support_xxxx account is used by Microsoft for support issues but I believe it's disabled by default.
      I recommend you disable it (Computer Management / Local users and groups) and also disable Remote Access / Remote Desktop (under System properties).

      In 'Local users and groups' you can see a description of each account; check if you see any unidentified accounts and check in what user group they are (if they are in administrators group for no reason, remove them).

      Do you have a good firewall and virus scanner? The virus scanner can prevent this by detecting and destroying trojans while the firewall prevents unauthorised access.
      I have symantec corporate edition (legit - provided by my school. virus definitions up to date, and scanned daily). Windows firewall is disabled, and the Motorola wireless modem/router's firewall is disabled. Probably a recipie for trouble but I've never had a problem

      Comment


      • #4
        it was xog--he's "hacking" everything! :fear:

        Comment


        • #5
          Originally posted by Stompa View Post
          Windows firewall is disabled, and the Motorola wireless modem/router's firewall is disabled. Probably a recipie for trouble but I've never had a problem
          Yup, better enable one of the two or even both. The firewall at your modem/router should always be enabled, it usually doesn't stop you from doing anything if configured correctly.
          Maverick
          Retired SSCU Trench Wars Super Moderator
          Retired SSCU Trench Wars Bot Coordinator
          Retired Trench Wars Core Administrator
          Subspace Statistics Administrator
          Former Mervbot plugin developer

          Comment


          • #6
            So no ideas as to why random profiles were crated on my computer? There was also a 4th one called "asery"

            UPDATE LOOK AT THESE PICTURES LOOK WHAT JUST HAPPENED WHAT THE FUCK IS GOING ON

            1. First my internet goes out for a couple of seconds (screen shot from Utorrent...uploading is always continuous as I seed 60+ torrents on Myspleen)



            2. Less than a minute later, this motherfucker pops up...lots more text was displayed before the window closed



            3. Then I think, this is just like last time. I look at my user profiles and sure enough, there are 4 NEW ONES. (I deleted one before I took the screen...called 'asery').



            Then a bubble pops up saying my WINDOWS FIREWALL WAS DISABLED...WTF!?!?!

            I checked event viewer and there were 4 events that occured:

            1. Service Control Manager: The Windows Firewall/Internet Connection Sharing (ICS) service entered the stopped state.

            2. Service Control Manager: The Windows Firewall/Internet Connection Sharing (ICS) service was successfully sent a stop control.

            3. Service Control Manager: The Application Layer Gateway Service service entered the stopped state.

            4. Windows File Protection: File replacement was attempted on the protected system file c:\windows\system32\net1.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.2180.


            SOMEONE HELP!!!
            Last edited by Stompa; 08-19-2007, 02:01 AM. Reason: Update, plus doubleposts are lame

            Comment


            • #7
              I'm really really sorry for self-bumpdoublepost but im desperate

              Comment


              • #8
                FUCK IT's THE FBI, GET IN THE CAR
                Warning: Disconnected From Server.
                paralyze> what is this, some sort of gay-out?
                paralyze> and nice try
                Sleuth> WTF
                Sleuth> OK QUIET
                JuNkA> LOL
                Sleuth> THOUGHTS COMING
                Sleuth> SHHH

                Warning: Disconnected From Server
                Thoughts> u wish
                Sleuth> WHAT THE FUCK
                Vue> LOOL
                Sleuth> LOLOLOLOL
                Sleuth> ABBOT IS COMING
                Sleuth> QUIET

                Warning: Disconnected from server
                abbot> ..
                Thoughts> LMFAO
                paralyze> ROFL
                Sleuth> stfu

                Comment


                • #9
                  This is why you need to install the security updates which are released once a month.

                  Comment


                  • #10
                    It seems you've become a victim of a virus/trojan or someone is actively trying to gain administrator access which they successfully gained.

                    - get your security updates
                    - let your virusscanner run through your entire system
                    - Enable all the firewalls
                    - Backup any of your sensitivity information or important documents to a different medium (flash / other computer). Just in case things go haywire you can format your computer.
                    - Look up more information for net1.exe, it seems it's a windows file but it can also be used for cloaking malware. Check if it's running on your computer by checking the running processes in the task manager and kill it if it's.
                    - If you see more things go wrong, just unplug it from the internet and look through your system for suspicious files.
                    Maverick
                    Retired SSCU Trench Wars Super Moderator
                    Retired SSCU Trench Wars Bot Coordinator
                    Retired Trench Wars Core Administrator
                    Subspace Statistics Administrator
                    Former Mervbot plugin developer

                    Comment


                    • #11
                      Or save yourself time, format reinstall and get some bloody protection
                      "People fear what they can't understand, hate what they can't conquer."

                      "Cherry blossoms in the Spring, and starry skies in the Summer. The Autumn brings the full moon. The Winter brings the snow. These things make Sake taste good. If you don't like Sake, then there is something wrong with you." Seijuro Hiko

                      Comment


                      • #12
                        Originally posted by RednaZ View Post
                        get some bloody protection
                        this works well with girls, too.
                        The above text is a personal opinion of an individual and is not representative of the statements or opinions of Trench Wars or Trench Wars staff.

                        SSCJ Distension Owner
                        SSCU Trench Wars Developer


                        Last edited by Shaddowknight; Today at 05:49 AM. Reason: Much racism. So hate. Such ban. Wow.

                        Comment


                        • #13
                          Originally posted by RednaZ View Post
                          Or save yourself time, format reinstall and get some bloody protection
                          And what kind of blood-covered protection would you suggest?


                          I got this message on another website:
                          Looks like the fxp scene hacked you. If you use vnc or something with common exploits thats the culprit! It could be another program that was exploitable...you are better off reformating and router with NAT. A firewall can't stop some common exploits.

                          I don't use VNC but...what is the fxp scene? I uninstalled everything I installed in the past week, and I'll see how that goes. If not I guess I will be reformatting. Luckily I have all my good stuff on separate hard drives

                          Comment


                          • #14
                            Originally posted by Stompa View Post
                            I have all my good stuff on separate hard drives
                            That's why the fuckin FBI's after you.
                            Warning: Disconnected From Server.
                            paralyze> what is this, some sort of gay-out?
                            paralyze> and nice try
                            Sleuth> WTF
                            Sleuth> OK QUIET
                            JuNkA> LOL
                            Sleuth> THOUGHTS COMING
                            Sleuth> SHHH

                            Warning: Disconnected From Server
                            Thoughts> u wish
                            Sleuth> WHAT THE FUCK
                            Vue> LOOL
                            Sleuth> LOLOLOLOL
                            Sleuth> ABBOT IS COMING
                            Sleuth> QUIET

                            Warning: Disconnected from server
                            abbot> ..
                            Thoughts> LMFAO
                            paralyze> ROFL
                            Sleuth> stfu

                            Comment


                            • #15
                              Sounds to me like you have a trojan and/or rootkit problem. Most likely someone is trying to gain admin access to your computer in order to run it as a server/proxy.

                              Oh, and the fxp community is a bunch of people who share warez and often use hacked computers as unwilling ftp servers.

                              If I were you I'd get my computer scanned by a good virus scanner, get my firewall up and running, and if it comes down to it you might even have to reformat and hope to god that it's not one of those special trojans that hides in certain system/cache files so that a reformat might not even get to it.

                              Also, find a good rootkit scanner as well.

                              Good luck.
                              (ZaBuZa)>sigh.. i been playing this game since i was 8... i am more mature then ull ever be...

                              Comment

                              Working...
                              X