Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

I've been hacked!

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
callous taoboy Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:07 PM
Original message
I've been hacked!
My home comp has been hacked, I'm pretty sure. I look under "connections" in the Norton program and lately http80 has been actively connecting to remote computers. Someone has taken over the computer and is going to www.walmartdownloads.com, napster.com and several others including realprogrammers.com which I found out is a hacker site. Over 1,000,000 bytes of info have been received on my computer from these sites. Does anyone know exactly what is going on and what I can do about it?
Printer Friendly | Permalink |  | Top
BikeWriter Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:09 PM
Response to Original message
1. If you don't have Zone Alarm firewall get it!
Printer Friendly | Permalink |  | Top
 
callous taoboy Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 05:43 PM
Response to Reply #1
12. ZA did not catch it.
Printer Friendly | Permalink |  | Top
 
Lex Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:12 PM
Response to Original message
2. Maybe install a spyware zapper?
Something like "Ad Aware" which is free and will zap spyware might rid your computer of this.

Printer Friendly | Permalink |  | Top
 
mcscajun Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:14 PM
Response to Original message
3. Do as suggested above.
Get ZoneAlarm Firewall.
Also, AdAware SE Personal, and Spybot Search & Destroy
All are available at www.download.com

Start with those and clean up your PC. If problems persist, check out the Computer group here at DU. More powerful tools exist, but not certain you need them yet.
Printer Friendly | Permalink |  | Top
 
Logiola Donating Member (379 posts) Send PM | Profile | Ignore Tue Mar-29-05 04:24 PM
Response to Reply #3
7. make sure to boot into safe mode when using these programs.. it makes a
big difference, it finds, and gets rid of a lot more stuff then using it as a user..
Printer Friendly | Permalink |  | Top
 
BikeWriter Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:14 PM
Response to Original message
4. ...and SpyBot Search and Destroy.
Printer Friendly | Permalink |  | Top
 
short bus president Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:15 PM
Response to Original message
5. for gawds sake get off the network if you know yer compromised.
clean yer stuff, THEN get back on.

Printer Friendly | Permalink |  | Top
 
Technowitch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:19 PM
Response to Original message
6. Okay... here's what you wanna do--
If you can still use the computer, go to these sites:





These are worm, spyware, and trojan detecting programs.

You should also either enable the Microsoft built-in firewall (if available), or go to to get a copy of their free personal-use firewall program.

Finally, get thy butt on over to McAfee or Symantec and use one of their free virus scanning programs. Install and run it.

Once you have these downloaded, installed, and registered, run them.

I'd also recommend that you be sure to visit the Windows Update site and make sure your system is fully patched.

Good luck.
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:34 PM
Response to Original message
8. I had a client whose computer had literally been taken over
Edited on Tue Mar-29-05 04:38 PM by Prisoner_Number_Six
and converted into a pirate warez ftp site. There were about 10gb of warez hidden in a subfolder in the windows directory- the folder was hidden by being named like a dll file.

His machine had slowed down to a crawl because it was open to the world, and the world was downloading from it constantly.

So yes, this crap does happen. You need to firewall your computer, do a virus scan with an uncompromised scanner, and keep an eye open for excess cpu usage and unaccounted-for network usage.

The best way to firewall it is to put a good router on your network, even if you have only one computer. They all come with good hardware firewalls, and it basically hides your computer from the world. I do not like the Windoze native firewall-- I simply don't trust it to be as virgin-pure and invincible as they claim it is. And although Zone Alarm is pretty good (I use it myself), it can be a major pain if you accidentally block the wrong thing. You may suddenly find yourself unable to browse the web, for instance. And if you block port 80, you will most definitely be unable to browse, as that's the default for web browsers.
Printer Friendly | Permalink |  | Top
 
callous taoboy Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 05:21 PM
Response to Reply #8
10. I have a feeling that this is what is happening to me-
And I run Spybot, Adware and Norton on a regular basis and they come up with nothing. But the computer is definitely being connected to sites.
Printer Friendly | Permalink |  | Top
 
Bossy Monkey Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 07:05 PM
Response to Reply #10
17. You also need HijackThis
Here, about 3/4 way down the page: http://www.spywareinfo.com/downloads.php
Simplest is to download it, run it, and Google anything mysterious-sounding that turns up along with "HijackThis log" and check it against one of the many help desk inquiries that you find among the search results.
And thanks for reminding me: there's something funny on my computer, too, that I need to check on.
Off topic, but you probably have the best screenname on DU.
Printer Friendly | Permalink |  | Top
 
callous taoboy Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-30-05 10:42 AM
Response to Reply #17
19. Many thanks, man! n/t
Printer Friendly | Permalink |  | Top
 
frylock Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 04:39 PM
Response to Original message
9. hardware firewall is the only way to fly..
Edited on Tue Mar-29-05 04:40 PM by frylock
get yourself a Netgear or Linksys gateway router to use along with your software security. And please, change all defaults on the router when you configure it. You would be amazed at how many people in my area using WiFi just plug the things into their PC and walk away. I've hacked into my neighbors Linksys and an SMC router because the owners haven't changed the default logins or passwords.
Printer Friendly | Permalink |  | Top
 
Technowitch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 05:44 PM
Response to Reply #9
13. I use a Sonicwall for our network here
A 'gateway router' isn't really a firewall at all. It just uses NAT to separate internal network addresses from external ones.

Better than nothing, but to call a gateway router a firewall is a bit of a misnomer.
Printer Friendly | Permalink |  | Top
 
frylock Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 06:49 PM
Response to Reply #13
15. tru dat..
but it does serve as another line of defense for someone who can't afford to go out and buy a PIX.
Printer Friendly | Permalink |  | Top
 
miss_kitty Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 05:30 PM
Response to Original message
11. here's a site I visit after each and every reload!
http://www.grc.com/default.htm

not so frequently with the reloads and the check disk repairs and the writing 0s to the hard drive since I started closing shit up that I won't be using.
Printer Friendly | Permalink |  | Top
 
Mojambo Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 07:12 PM
Response to Reply #11
18. That's a great site. Thanks
I'm pretty rock solid secure, but that has some handy utilities.
Printer Friendly | Permalink |  | Top
 
mvd Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 05:53 PM
Response to Original message
14. First, I'd make sure that the computer doesn't have..
Edited on Tue Mar-29-05 05:54 PM by mvd
a trojan or backdoor allowing access. Norton is solid at trojans, but not as good as Kaspersky AV, which I use. You can download an evaluation of Kaspersky at www.kaspersky.com. Also try online checks like McAfee's and Trend Micro's HouseCall.

If you are clean, then it's a concern, because usually script kiddies can't bypass your software firewall. In that case, I'd do a format of the computer, and get an NAT router with good password protection.
Printer Friendly | Permalink |  | Top
 
bearfan454 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Mar-29-05 06:53 PM
Response to Original message
16. If you signed up for coolsavingsandcoupons.com, then
they use your computer as a server. It is in the fine print. Zone Alarm kept asking me if I wanted my computer used as a server by coolsavingsandcoupons.com. I thought What to fuck ? That's what it was.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed May 01st 2024, 01:04 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC