Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 02-08-2005, 01:55 PM   #1 (permalink)
Guest
 
Posts: n/a
Default my pc is hacked!!


i m getting new prob nw..
in this my dialup connection is changed everytime i login. it is changed to dail some isd number.. every time i have to change it .. and during connection sent bits are more then recived bits even if nothing is being uploaded !!! help me in this fast plz
 
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 02-08-2005, 02:06 PM   #2 (permalink)
Wise Old Owl
 
siriusb's Avatar
 
Join Date: May 2005
Location: Chennai, India, Asia, the Earth, the Solar system, the Milky Way, the Local group, this Universe.
Posts: 1,171
Default

There's more probablity of u having spyware/malware/dialler in ur comp than an external perpertrator. Sweep ur system for such wares before assuming that u have hacking activity. Chek for viral infection as well.
__________________
http://myxp.blogspot.com
-----------------------
Winchester 3200+ @2,500MHz
LeadTek 7900GT VOLT MODDED @ 680 core, 1800 mem
2x1GB Transcend DDR400 @ DDR454 2.5,3,3,5,1T
siriusb is offline  
Old 02-08-2005, 02:07 PM   #3 (permalink)
Broken In
 
Join Date: Jun 2005
Location: Beyond the Horizon
Posts: 168
Default

I think you hv a problem of browser hijack. try using ad-aware or sybot-search and destroy.
raasm287 is offline  
Old 02-08-2005, 02:14 PM   #4 (permalink)
Microsoft MVP
 
Vishal Gupta's Avatar
 
Join Date: Jul 2005
Location: AskVG.com
Posts: 5,173
Default

Instead of changing the phone no. every time in the Dialer, u can change the phone no. to be dialled in Connection's Properties.
Check whether it works or not?
__________________
:arrow: http://www.AskVG.com/
Vishal Gupta is offline  
Old 02-08-2005, 02:24 PM   #5 (permalink)
Guest
 
Posts: n/a
Default

i have created new connection as well..
i have used now hijack this and delete some suspicios enrty .. now log file is as followed
Code:
Logfile of HijackThis v1.99.1
Scan saved at 2:14:47 PM, on 8/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost32.exe
C:\WINDOWS\system32\usbn.exe
C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\slserv.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\slrundll.exe
C:\PROGRA~1\NORTON~1\NORTON~3\navw32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\nik\My Documents\HijackThis.exe

O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_6_2_0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SystemClock] C:\WINDOWS\System32\SysClock.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Windows Automatic32Updater] svchost32.exe
O4 - HKLM\..\RunServices: [Windows Automatic32Updater] svchost32.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
Old 02-08-2005, 02:41 PM   #6 (permalink)
Apprentice
 
Join Date: May 2005
Location: reaching hell
Posts: 89
Default

hi nik. i can surely tell u that it is some kind of malware or spyware.even i had the same problem with my dialup.i used to change the number but while dialing it changed automatically to some crappy number.i even made new connections but of no use.i tried anti viruses like norton,avg,mcafee and anti spywares like spybot,lavasoft ad-aware.but none of them helped.eventually i had to format my c: drive.
__________________
To handle yourself, use your head; to handle others, use your heart.
sensationalboy is offline  
Old 02-08-2005, 03:05 PM   #7 (permalink)
Guest
 
Posts: n/a
Default

ya ther were adware and dialer .. i deleted them using adaware and norton.. but net speed is very slow now . as i told earlier sent is very much more than recieved data!!! i suspect this is some problem ?? is it?
 
Old 02-08-2005, 03:23 PM   #8 (permalink)
Wise Old Owl
 
siriusb's Avatar
 
Join Date: May 2005
Location: Chennai, India, Asia, the Earth, the Solar system, the Milky Way, the Local group, this Universe.
Posts: 1,171
Default

Do a "netstat -abv" in dos prompt to see if any suspicious exe is running in a local port.
Or better yet, get a prog that will monitor ports and give you real-time feedback.
__________________
http://myxp.blogspot.com
-----------------------
Winchester 3200+ @2,500MHz
LeadTek 7900GT VOLT MODDED @ 680 core, 1800 mem
2x1GB Transcend DDR400 @ DDR454 2.5,3,3,5,1T
siriusb is offline  
Old 02-08-2005, 03:49 PM   #9 (permalink)
In The Zone
 
Biplav's Avatar
 
Join Date: Jan 2005
Location: U REALLY WANNA KNOW???
Posts: 498
Default

well u can use symantec client security :
it comes with symantec antivirus corporate and frewall;
i use that and i must say it is pretty much easiler for a newbie to understand the ports on this.
__________________
"Try again, fail again, fail better" - Samuel Beckett
Biplav is offline  
Old 02-08-2005, 05:34 PM   #10 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Till someone analyses that Hijackthis log file get TCPViews from sysinternals: http://www.sysinternals.com/Utilities/TcpView.html

And no continuous sending & recieving isnt a modem problem most of the times now.It is malware or RAT[Remote access tool] phoning home giving a backdoor.
Post a screeny of the TCPView open ports.

Btw from when did this problem start?

EDIT:I just saw your hjt log again & from what it says,

Code:
Platform: Windows XP SP1 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
I would suggest you update the OS with latest patches once this problem of yours has been sorted out.Rest is upto you.[/quote]
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 02-08-2005, 06:35 PM   #11 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

a related suggestion : DAP is said to have spyware. suggest u switch to getright or any other one.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 02-08-2005, 07:09 PM   #12 (permalink)
Wise Old Owl
 
alib_i's Avatar
 
Join Date: Jun 2004
Location: omnipresent
Posts: 1,191
Default

you have quite a few trojans in your comp !

delete the following entries ->
Code:
C:\WINDOWS\system32\usbn.exe
Adult content dialer, recognized by Kaspersky antivirus as Trojan-Downloader.Win32.Small.afa | More Info
Delete the file "usbn.exe" and remove it from startup
To remove from startup, either use any standard registry editor, or type "msconfig" in Run box, go to startup tab and uncheck its entry.

Code:
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
It's
Trojan-Clicker.Win32.Agent.ac | More Info
Delete the following files
c:\ied_s7m.cab
c:\ex.cab (if present)
C:\WINDOWS\System32\vbsys2.dll
You may have to unregister vbsys2.dll too .. look at the link I gave above.

Rest I think is clean ...
Just one thing .. you have IIS running in your computer .. ie you have a web-server running in your computer.
C:\WINDOWS\System32\inetsrv\inetinfo.exe
you can switch it off if you dont need it .. its not a spyware. just unnecessary
Remove it by "Add/Remove Programs" -> Add/Remove Windows Components -> Uncheck IIS -> OK


hope my time was spent in something useful for you

-----
alibi
__________________
What I've felt, What I've known; Never shined through in what I've shown
Never free, Never me; So I dub thee unforgiven
-Metallica
alib_i is offline  
Old 02-08-2005, 09:49 PM   #13 (permalink)
Guest
 
Posts: n/a
Default

i deleted usbn.exe . and downloading tcpview now. i found vbsys2.dll . but how to deregister it?
 
Old 02-08-2005, 09:56 PM   #14 (permalink)
Wise Old Owl
 
siriusb's Avatar
 
Join Date: May 2005
Location: Chennai, India, Asia, the Earth, the Solar system, the Milky Way, the Local group, this Universe.
Posts: 1,171
Default

Use "regsvr32 -u vbsys2.dll" in dos prompt or in run window to deregister.
__________________
http://myxp.blogspot.com
-----------------------
Winchester 3200+ @2,500MHz
LeadTek 7900GT VOLT MODDED @ 680 core, 1800 mem
2x1GB Transcend DDR400 @ DDR454 2.5,3,3,5,1T
siriusb is offline  
Old 02-08-2005, 10:15 PM   #15 (permalink)
Guest
 
Posts: n/a
Default

it gives error like "vbsys2.dll was loaded but the dllunregisterserver entry point was not found this file can not be register"
 
Old 02-08-2005, 10:38 PM   #16 (permalink)
Guest
 
Posts: n/a
Default

i tried tcpview and find this . in this my pc is connected to ziv04.plus.sbg.ac at 7000 by svchost32.exe ?? is it suspicious??
 
Old 02-08-2005, 10:41 PM   #17 (permalink)
Guest
 
Posts: n/a
Default

and when i stoped this process from tcpview problem is solved means normal sending and recieving ..

now how can i fix this problem means each time i have to stop this as it starts each time automatically
 
Old 02-08-2005, 11:51 PM   #18 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

Oh yeah !
Svchost32.exe is a WORM !
Code:
W32.Mimail.J@mm is a mass-mailing worm that attempts to steal personal information. This worm displays a series of forms that ask users to enter their credit card information. (See the "Technical Details" for illustrations.) This information is saved and later emailed to several predetermined email addresses.
Read more about it here: http://securityresponse.symantec.com...mail.j@mm.html

Read the removal instructions & tool here : http://securityresponse.symantec.com...oval.tool.html
Follow the instructions carefully & carry it out accordingly.I hope atleast for the time being you install a firewall,enable it & block that process.If you have any difficultly removing it then reply here.

More info bout the worm: http://www.pchell.com/virus/mimaili.shtml
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 02-08-2005, 11:58 PM   #19 (permalink)
Broken In
 
Join Date: May 2005
Location: Bangalore
Posts: 102
Default

OMG
And all these days i thought it was a service coz i was using apache+PHP
Jeez
__________________
\"Cogito,Ergo Sum\"
whim_gen is offline  
Old 03-08-2005, 04:13 PM   #20 (permalink)
Alpha Geek
 
Join Date: Feb 2004
Location: Belgaum
Posts: 745
Default

huh? Sorry but dont get me wrong I said SVCHOST32.EXE is a WORM & not SVCHOST.EXE which is a windows process.
Though the latter can be infected & you will never know but dont confuse the two.
__________________
The protection of a machine is a process & not a given -Duane Arnold.
www.Oobertech.net
Look ma my blog http://techhub.blogspot.com/
digen is offline  
Old 04-08-2005, 12:00 PM   #21 (permalink)
Guest
 
Posts: n/a
Default

right now i m doing job at other town so i m not at home so cnt fix prob.. will fix when i go back thax all
 
Old 04-08-2005, 07:13 PM   #22 (permalink)
Commander in Chief
 
QwertyManiac's Avatar
 
Join Date: Jul 2005
Posts: 6,658
Default

Use Microsoft AntiSpyware, itwill remove most of ur infections u have mentioned in ur hijackthis...
__________________
Harsh J
www.harshj.com
QwertyManiac is offline  
Old 07-08-2005, 10:21 AM   #23 (permalink)
Guest
 
Posts: n/a
Default

yar my antispyware is expired on 31st july . and to download from micreosoft.com validation is required that's not possible for me
 
Old 08-08-2005, 11:37 PM   #24 (permalink)
Guest
 
Posts: n/a
Default

i think it is removed now
 
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Krow
- by abhidev
- by topgear
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 07:05 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2