Hacker!!!
Hacker!!!
Ok I had a problem with a hacker on yahoo. But nothing I have detected it. I have a firewall is there more I can do? I know they were putting a keylog on my computer I downloaded an antikey log but it doesn't appear to be working. Any advice would be appreciated. ~ Thanks
"The way to be safe is never to be secure."
- mountainman
- SG VIP
- Posts: 15451
- Joined: Tue Dec 26, 2000 12:00 am
- Location: Colorado
a screen kept flashing on screen for a second. I know the persons user name because of it and reported them but I would like to be able to stop it from happening again. JCOS helped me out a lot by giving my programs to download but what I have download didn't stop it.
"The way to be safe is never to be secure."
- YARDofSTUF
- Posts: 70006
- Joined: Sat Nov 11, 2000 12:00 am
- Location: USA
Kinda vague with the info.
Post your IP and we'll all take a shot at helping you out
Go over to http://www.grc.com and test your firewall with a port scan.
Also, get a good trojan scanner and check your system. Easiest way in is when a trojan holds the door open.
You sure this isn't just windows messenger ?
Post your IP and we'll all take a shot at helping you out
Go over to http://www.grc.com and test your firewall with a port scan.
Also, get a good trojan scanner and check your system. Easiest way in is when a trojan holds the door open.
You sure this isn't just windows messenger ?
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
Hey Norm.Originally posted by Norm
Kinda vague with the info.
Post your IP and we'll all take a shot at helping you out
Go over to http://www.grc.com and test your firewall with a port scan.
Also, get a good trojan scanner and check your system. Easiest way in is when a trojan holds the door open.
You sure this isn't just windows messenger ?
A quick pop up screen by the vandal lol showed up every 10 minutes or so. Tammy was luckily enough to get a screen shot of it.
The keylog.txt file found on in her systems folder would never have been found if she didn't get the path from the pop up.
She opened it up and there where her yahoo chats....word for word being sent back to that persons yahoo e-mail account which we also now have.
Tammy e-mailed abuse@yahoo but as of yet (i think) heard from them.
Did I miss anything Tammy?
>>Cult Master of International Affairs<<
Good detective work JCOS.
I doubt much will be done about it though. I've heard stories a lot worse where damage was done, and nothing was done.
All we can do is make sure we know our systems well enough to know when something is going on, and keep them secure best we can.
The cops won't lift a finger until the damage exceeds $5,000.
ISP's won't risk losing a customer and their $50 a month over a little incident. I wonder what they will do about the fact the chat sessions were being sent out. hmmm. That may be another legal issue altogether.
I doubt much will be done about it though. I've heard stories a lot worse where damage was done, and nothing was done.
All we can do is make sure we know our systems well enough to know when something is going on, and keep them secure best we can.
The cops won't lift a finger until the damage exceeds $5,000.
ISP's won't risk losing a customer and their $50 a month over a little incident. I wonder what they will do about the fact the chat sessions were being sent out. hmmm. That may be another legal issue altogether.
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
Thanks Norm but it was Tammy's quick fingers that got the screen shot. I should pass it over to you if you want to analyze it.Originally posted by Norm
Good detective work JCOS.
I doubt much will be done about it though. I've heard stories a lot worse where damage was done, and nothing was done.
All we can do is make sure we know our systems well enough to know when something is going on, and keep them secure best we can.
The cops won't lift a finger until the damage exceeds $5,000.
ISP's won't risk losing a customer and their $50 a month over a little incident. I wonder what they will do about the fact the chat sessions were being sent out. hmmm. That may be another legal issue altogether.
Got a good free trojan finder?
>>Cult Master of International Affairs<<
TDS-3 is supposed to be good. One of the best I've heard. I think it has a free demo that works for so many days. Not sure.Originally posted by Joint Chiefs Of Staff
Thanks Norm but it was Tammy's quick fingers that got the screen shot. I should pass it over to you if you want to analyze it.
Got a good free trojan finder?![]()
SwatIT is free.
Also you may want to have a look at http://www.gladiator-antivirus.com/ It's a new scanner that will also give you a list of all apps on your PC that have the potential to access the net.
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
I already have it. Hacked your system just a few seconds ago.Originally posted by Norm
Yes, I always like to check things out JCOS, send me any info you have, pics and all.
PM me if you need my email addy.
pfft crappy firewall dude!
j/k
I have it from a few weeks ago. lol
>>Cult Master of International Affairs<<
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
Originally posted by Norm
She's prolly good 64bit, secure your PC NOW !!![]()
Im probably this dudes next victim. I keep getting a grow.bat file from jenny@addinchestoyourmanhood.org. Im bound to click it one of these times....
She's presenting like a mandrill!
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
damnit! Outllook won't send it Norm. Potentially unsafe file it says. lol ya think! heheOriginally posted by Joint Chiefs Of Staff
Norm....e-mail being sent now! Read first before opening attachment!
I'm trying hotmail now. Should send there without a problem. lol
>>Cult Master of International Affairs<<
Open it in notepad and post it for us.Originally posted by 64bit
![]()
Im probably this dudes next victim. I keep getting a grow.bat file from jenny@addinchestoyourmanhood.org. Im bound to click it one of these times....![]()
![]()
Kinda curious what it says in the bat file.
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
I got it, sent blebbs a copy too.Originally posted by Joint Chiefs Of Staff
go figure...hotmail sent it. lol
I am on my way out for about 15-20 minutes. I'll get back to you later.
I don't have a test machine right now. Blew a couple of old mobo's testing client's crap. The joys of working as a tech. Make 50 bucks fixing a clients pc, only to blow a 75 mobo lol
I'll have a look at it with a hex editor and see if anything is visible worth reporting.
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
Thanks e-mail anything I mean anything you find.Originally posted by Norm
I got it, sent blebbs a copy too.
I am on my way out for about 15-20 minutes. I'll get back to you later.
I don't have a test machine right now. Blew a couple of old mobo's testing client's crap. The joys of working as a tech. Make 50 bucks fixing a clients pc, only to blow a 75 mobo lol
I'll have a look at it with a hex editor and see if anything is visible worth reporting.
I'll forwarded back to Tammy so she can keep some ass.
>>Cult Master of International Affairs<<
Originally posted by Joint Chiefs Of Staff
Thanks e-mail anything I mean anything you find.
I'll forwarded back to Tammy so she can keep some ass.and she can too. lol
So I can keep some ass????? WTH lol.
By the way just a smidge more detail. I know who the file was being sent to. But they are in denial. They say they have no idea whats going on but that I must have trojan. Funny why would it say it is emailing the info to their account?
"The way to be safe is never to be secure."
- Joint Chiefs of Staff
- Posts: 42832
- Joined: Mon Mar 26, 2001 12:00 am
- Location: The Sandbox
- YeOldeStonecat
- SG VIP
- Posts: 51171
- Joined: Mon Jan 15, 2001 12:00 pm
- Location: Somewhere along the shoreline in New England
- knightmare
- Posts: 6067
- Joined: Tue Feb 19, 2002 10:53 am
yahoo
next time u are in yahoo chat, dont go thru messenger, i wouldnt advise using yahoo messenger, many firewalls do not stop the scripts run thru yahoo messenger. Its not quite as functional, but logging into yahoo chat thru ur internet browser is safer, you will notice the yahoo booters cant seem to boot u that way. They have cookie stealers etc, they can take ur yahoo id, plus password crackers, i only go onto yahoo games anymore to play pool or spades, chat very seldom, everyone has a boot or script prog..
“"A wise man can learn more from a foolish question than a fool can learn from a wise answer."”
Bruce Lee
Bruce Lee
- ghettoside
- SG Elite
- Posts: 5134
- Joined: Thu Mar 13, 2003 5:18 pm
- Location: At Large in the US
TDS 3 is the best anti- trojan. don't know if the trial version removes, but here's link
tds 3
the prog is (or was) $50, well worth the money.
what other security progs did the guys give you? (what firewall, any other progs)
tds 3
the prog is (or was) $50, well worth the money.
what other security progs did the guys give you? (what firewall, any other progs)
- ghettoside
- SG Elite
- Posts: 5134
- Joined: Thu Mar 13, 2003 5:18 pm
- Location: At Large in the US
Hey Norm, that gladiator prog, I've tested that one, it looks great but it gives lots of false positives. don't know if its still beta... I abandoned that one. had some other problem with it too, can't remember exactly what it was.
[edit] just looked at it, it was the 'turbo loader' that was prob. scan was kinda slow. then tried the turbo loader and crash-ola...
it's still in beta too.
[edit] just looked at it, it was the 'turbo loader' that was prob. scan was kinda slow. then tried the turbo loader and crash-ola...
it's still in beta too.
Ok, I have found a few things that may or may not be of any value in ridding this thing. All the below files etc were referenced in that exe file I was sent.
I could tell by what I saw that the registry gets written to, and some keys deleted. Also it has it's own mail handler.
These files are worth investigating.
c:\profile.fil
ANSMPT.dll
winsyst.exe
iphlpapi.dll
dosapi.dll
ANSMTP.obj
ANSMTP.obj.1
stole2.tib
sm.exe
RegSVR32.exe - (this is a normal windows file)
c:\DevStudios\vb\v85.old
C:\\inetpub\\mailroot\\pickup
This is some evidence that it is using the mail system.
test mail
txtEmailInterval
startkeylogGoStealth
GoStealthDelay
GoOutStealthDelay
GetUsername
CallBackMessage
GetWindowsDirectory
GetSystemDirectory
v8InternalUpdate
A.Root-Servers.net
GetMailServer
It is written in C++
There may be more, I got tired of looking at code.
I could tell by what I saw that the registry gets written to, and some keys deleted. Also it has it's own mail handler.
These files are worth investigating.
c:\profile.fil
ANSMPT.dll
winsyst.exe
iphlpapi.dll
dosapi.dll
ANSMTP.obj
ANSMTP.obj.1
stole2.tib
sm.exe
RegSVR32.exe - (this is a normal windows file)
c:\DevStudios\vb\v85.old
C:\\inetpub\\mailroot\\pickup
This is some evidence that it is using the mail system.
test mail
txtEmailInterval
startkeylogGoStealth
GoStealthDelay
GoOutStealthDelay
GetUsername
CallBackMessage
GetWindowsDirectory
GetSystemDirectory
v8InternalUpdate
A.Root-Servers.net
GetMailServer
It is written in C++
There may be more, I got tired of looking at code.
- ghettoside
- SG Elite
- Posts: 5134
- Joined: Thu Mar 13, 2003 5:18 pm
- Location: At Large in the US
Norm how in the hell did you access the source code? The only thing I could do was view the thing with quickview. According to Pest Patrol it is Winspy but I haven't found any information on deleting the program altogether. I did delete the app folder with the keylogger text, the HKLM\Software\SSET folder key
HKLM\Software\Microsoft\Windows\Current Version\Run csrss.exe key and it appeared to stop functioning. Now you got me scratching my head.
HKLM\Software\Microsoft\Windows\Current Version\Run csrss.exe key and it appeared to stop functioning. Now you got me scratching my head.