izza been haxxed help!!!!

S

Silence

Guest
ello guys and gals, this hueston and we got a problem.


lost both my hard drives the other week, computer kind of suddenly decided it did not wanna work, takes it local pc shop and find out the hard drives were fine, even though i could not format them. gave wierd errors..

ne way they replace one hard drive with a new one, said was not compatible or somthing.. they reinstalled computer with a new version of xp.

ne way after one week, all bran new stuff all new drivers and such, and after not downloading any scary files,

i stumble across events manager thing in admin tools. and find 1935 very scary messages.

Annoymous login attempt, username or password wrong,

i checked loads out and it seemed someone was trying to connect to my computer using remote things,

alsort of user names attempede like administator, teacher, admin1, main, test, domain,

while half panicing to death i get zonealarm pro up and running, and at this time the attempts had stopped. i took it down to play planetside for a few hours.. one random night days later..

i come off and check events manager and they was a few successfull logins or somthing, things i had not done thats for sure.

imediaite shoove firewall backup, and its never been off since.

But now i am starting to get succesffull logins and things like new username for security preferences, changes to accounts and passwords will now be sent to system blabalbal..


this is while firewall is up.. i aint daft i aint downloaded no wierd files, i have not let the firewall give access to things i aint that sure of.

i think the program its done by is somthing to do with svghost.exe or somthing...

there is 6 different ones of them running. used to be one, tried stopping it and would not allow it, not tried recently stopping others.. currently at college posting cause of a new major problem

friend of mine told me trying changing remote connections on services to disabled. so i did this and restarted..

since then i can no longer access my adsl connection, when i run dialer it says " modem name(alacatel or somthing) cant no open.

it says fatal error i think, possibly some registery files for it died? well this is one of things that happened when i lost both my hard drives last week... so kind of scared atm..

i reinstalled modem drivers still cant do it, i been to the folder where the thing shortcuts from, if i run from there it opens up fine, but i cant click ok or connect, just does nothing....


i have run virus scans ever since i got new computer, nothing found ever..

i am totaly baffeled, i cant think of what to do, and cant get on net at home atm... i dont wanna loose 2 more hard drives



HELP!!!!!!!!!!!!!!!!!!
 
S

Silence

Guest
sorry another thing

i have run sygate probe scanner, it said all ports were stealth/blocked when i first got firewall

since then it says port 5000 is open, so connecting via that i think
 
S

Silence

Guest
application error

could not complete entry ("+ atelcetal modem+")

error i need fixing most, so i can get on the ruddy internet

says that when i try and dial up on adsl.

it says the modem bit in the shortcut for the file...


the file in the folder its from runs normally but clicking on connect does nothing at all.

help
 
C

chretien

Guest
Do you have a static IP address with your ADSL?
I would say that someone did a portscan while your firewall was down and got access to your machine that way. It is also possible to construct web pages that can run malicious script on a computer and gain access that way. You don't need to download a file or open an attachment to be vulnerable.
If I was you, I'd fdisk, format, reinstall windows put up a firewall before I even installed my modem. Then I'd get all the critical updates from microsoft.
 
O

old.Belorfyn

Guest
While your computer has been connected to your adsl providers network without firewall, the unsuccesful login things may be normal since windows pc's broadcast all kinda stuff over the net too (if not especially disabled/firewalled). So those messages may mostly be from other users like you who don't need to do pretty much else than connect their computer to network.

Some of the other things sound more serious though.
I think port 5000 was involved with some kinda serious bug in windows xp (and perhaps others). As mentioned, go to www.windowsupdate.com and install all the updates it says you're missing (atleast ones marked as critical updates).

Running a virus scanner will be good idea since it may be able to detect possible backdoor or trojan programs the hacker might had left to your computer (should this have happened).
Also, keep running the firewall and never store any sensitive info on your computer. No CC numbers, daoc password etc.
 
S

Silence

Guest
well i got a situation report

i used system restore and went back 3 days,

thats fixed everything, cept hacker..

i closed port 5000 which used to be blocked by firewall but not ne more, window website had a fix to close it.

now i aint got firewall , i removed zonealarm to put norton on, after installing norton my pc crashed when i tried to dial to net, then things got worse got not even log in :p

another system restore and here i am :p

not sure what to do atm,
 
H

Hargh

Guest
stop doing restores and start afresh? if u want to restore old files do it individually and only the ones you want, reinstall apps and games from scratch.
 
O

old.moriath

Guest
NOrton has been known to do some funny stuff and not like xp sometimes .. Seems ok when i used it but others have said so.

Like he says above format and start again :)
 

Users who are viewing this thread

Top Bottom