Computing.Net > Forums > Security and Virus > How are they doing it ???

How are they doing it ???

Reply to Message Icon

Original Message
Name: SP38
Date: June 27, 2003 at 18:44:14 Pacific
Subject: How are they doing it ???
OS: windows 2000 pro
CPU/Ram: 655 mg
Comment:

I used to know this group of people whom I haven't talked to in almost a year. I found out that they were hacking into my computer. I have reformatted my computer since the last time I talked to them and I can see with my zone alarm that they are still trying to get back on here.
Can someone tell me how they are getting my ip number?
As soon as I connect to the internet they start so it's as if they are getting the number immediately.
Do they have to have something on my computer that is sending it to them. I have gotten junk email that may have been from them but made to look like it was from someone else....although I never click on anything in emails I get from people I don't know.

If they do have something on here how do I find out what it is to remove it? I also have Norton antivirus and a trojan remover so I don't think it's a trojan.

Thanks


Report Offensive Message For Removal


Response Number 1
Name: EC
Date: June 27, 2003 at 20:02:39 Pacific
Reply: (edit)

Likely it's a TROJAN.
Download and install and then scan your PC with the 30-day free trial of TROJAN REMOVER from www.simplysup.com

Or maybe a keylogger, but a properly done format should have taken care of it the first time around. If you are having the same problems AFTER a Windows format, then you likely have an intruder with PHYSICAL ACCESS to your PC and they just keep adding it again and again.



Report Offensive Follow Up For Removal

Response Number 2
Name: wawadave
Date: June 27, 2003 at 20:10:47 Pacific
Reply: (edit)

hello
try these scans as well
free trojin scan
http://www.trojanscan.com/trojanscan/scanner.htm
panda scan
http://www.pandasoftware.es/activescan/
housecall
http://housecall.trendmicro.com/housecall/start_corp.asp
rav av
http://www.ravantivirus.com/scan/

test my sheilds grc
https://nanoprobe.grc.com/x/ne.dll?bh0bkyd2


Report Offensive Follow Up For Removal

Response Number 3
Name: SP38
Date: June 27, 2003 at 20:13:10 Pacific
Reply: (edit)

Thanks
I already use trojan remover and it didn't find anything, that's why I don't think it's a trojan. What is a keylogger? Does it only show keys typed with this computer or will it show any commands from another computer connected to this. As for my format....I removed everything.
Also is there anywhere I can find a list of programs that people can use to get my ip so I might have some kind of idea what to look for on here. All running programs in my task manager seem to be things that should be there.


Report Offensive Follow Up For Removal

Response Number 4
Name: EC
Date: June 27, 2003 at 21:04:50 Pacific
Reply: (edit)

Could be they are hosting a web site that you are visiting AND each visit it's set to reveal to them, info about you, especially if your box is not secure. Use a firewall like ZONE ALARM PRO and examine the secuirty logs, AND mostly make certain it is configured correctly.

Basically, your IP has to be revealed at each site you hit, or else how would the packets know the travel directions?
Besides, them just having your IP would not in etself be that harmful, especially if your are dial-up.

So, a key logger is installed on a PC to spy on that PC.

Would be interested to know HOW you are convinced they have/had hacked you.


Did you do a low-level format of your PC?
Or a ZERO WRITE/FILL run on your hard drive?
What exact method are you using to determine that your hard drive was in fact formatted correctly.

Bots roam the NET looking for unprotected and improperly configured window boxes and they then do IP scans and TCP scan, NET BIOS, etc to data mine your PC.

Visit they website www.astalavista.box.sk
to see how one might achieve this, as the best protection from a hacker, is information, information on what and how they do what they do.



Report Offensive Follow Up For Removal

Response Number 5
Name: SP38
Date: June 28, 2003 at 06:53:29 Pacific
Reply: (edit)

I already use Zone Alarm Pro....this is how I am seeing their supposed ip numbers. They can be faking ip numbers also correct?
I thought about the webpage thing but it starts happening when I connect.....I don't have to do anything internet related for them to start.
I used to talk to one of them through email and icq and I'm sure they gave me a fileto let them on but now I don't talk to them and I can't figure out how they do it.
I didn't know there were 2 kinds of formats. I do erase everything on every drive and have to reinstall everything afterwards.

The way I know they have hacked me is because they used to say things that had something to do with files on my desktop.....they changed an entry for one of their addresses that I had in a name/address book I had on here (not related to the email address book) and they created a new folder in my email. They changed file names. They knew of places I used to go to on the net.They never did anything to hurt the computer but they did little things and said little things so I knew they were on here.


Report Offensive Follow Up For Removal


Response Number 6
Name: EC
Date: June 28, 2003 at 07:08:49 Pacific
Reply: (edit)

Again, a properly done low-level foramt will COMPLETELY eradicate your hard drive of ALL data.
Go to your hard drive manuf. web site and look for a utility to do that.


Report Offensive Follow Up For Removal

Response Number 7
Name: safeTsurfa
Date: June 28, 2003 at 09:08:19 Pacific
Reply: (edit)

Don't need to go anywhere. I have BCwipe here, it has a second killer proggie inside a sub folder - that thing totally overwrites then collapses the hard drive. Would need the thing building back from partition upwards after using that. Only way they could *maybe* survive that is if they managed to slip something into track 0 which isn't written to. Shrug but if they know how to do that, they'd not be wasting their energy playing childish mind games with you, they'd be busting into the Pentagon instead.


Report Offensive Follow Up For Removal

Response Number 8
Name: anonproxy
Date: June 28, 2003 at 23:01:28 Pacific
Reply: (edit)

How do you know they are still trying to get back on your machine?

What do they do to try to get on your computer?



Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: How are they doing it ???

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge