Computing.Net > Forums > Windows 95/98 > Did anyone hack you ???

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Did anyone hack you ???

Reply to Message Icon

Name: AM7+
Date: May 31, 2001 at 00:49:20 Pacific
Comment:

Then go to this site ... and read it carefully ...
AM7.netfirms.com/Protect_your_PC.htm



Sponsored Link
Ads by Google

Response Number 1
Name: Bryan
Date: May 31, 2001 at 04:18:30 Pacific
Reply:

Are we suppossed to go to that site if we have or have not been hacked?

If the information is so important then won't you share it with us here, like in a nutshell?


0

Response Number 2
Name: AM7+
Date: May 31, 2001 at 04:52:01 Pacific
Reply:

you will do a great help if you can post what was written in that site here ...


AM7+


0

Response Number 3
Name:
Date: May 31, 2001 at 05:39:43 Pacific
Reply:

It is basicly full of someone who wants to get rid of "Hack programs" tells you a free online virus scan but not the free real-time virus scan (InoculateIT) and doesn't tell you anything about setting up a firewall.

and it claims:
* go to the file (system.ini) and open it ...
In the fifth line you will find :
shell=Explorer.exe
But if you have been hacked ... it will be
shell=Explorer.exe xxxx.xxx
where xxxx.xxx is any file name ...
so ... modify it to be only :
shell=Explorer.exe
and save the file ...

Garenteed if your hacked that xxxx.xxx will be there. . .

I think "Hack program" = Trojan

And you should have a Real-time protection anti-virus


0

Response Number 4
Name: Original Bruce
Date: May 31, 2001 at 05:43:15 Pacific
Reply:

Why don't you post it yourself? You want us to go to your site and then post what we found there on this site? What do we find there, something free like a virus or spam in the mailbox?


0

Response Number 5
Name:
Date: May 31, 2001 at 05:57:50 Pacific
Reply:

Even though it's AM7+'s website:




 
 



 
This page
will be updated if I found any new hacking files ...

Protect Your
PC From Hacking !!!

First of all you have to know that there are many ways to hack ...
not only through the TCP/IP cracking ... but some hackers are using
the API programming ... and some are using a programming language
like VB or Delphi or any others ... and they will work in the Windows
environment ... and since most of you are using Windows then you have
to know that you are using a non secure OS ...

Now the first thing to do is to secure your PC ... for such a thing
... do the following ...

* DO NOT EVER test any
file that you got from the net or from any other person (even if he
is your friend) in the PC that you are using for browsing the
Internet ... (what I mean is ... it is better to have two PC's ...
and use the old one to test the files only ... wether you got the
files from the Internet or even from a disk) ...

* Always update your Anti-virus ... or if you want you can use an updated scanning site for Viruses and Trojans ... try this link ... (it
is Free
) ... http://housecall.antivirus.com/
... and click on Scan Now
on the left side under the HouseCall option ... and once you get the
names of the hacking files if any ... just write them in a piece of
paper ... (it might take some time) ...

* Check your PC if there is any hack file in it ... for
example ... search for any of these files (after you allow the hidden
and system files to appear) ... Click Here ... and if you found any of them then read the rest of this
page ...

* Right click on the Network Neighborhood icon ... and choose
properties ... then remove the last icon (file and printer sharing)
...
* Do not install any protocol that you don't really use ...

* Remove the AutoComplete option from your browser ... and regarding
the cookies ... it is better to go to tools ,,, Internet Options ,,,
and in the security tab click on Custom level and choose (prompt) for
both cookies options ...

* Do NOT check any "Save password" check box ...

* Try NOT to keep the FTP connections in your PC ...

* You also have to know that many sites are not trusted ... so don't
feel that free in downloading any file from the Internet ...

* Make your password as long as you can ... and make sure that you
include some upper case letters and some numbers in it ...

* go to the file (system.ini)
and open it ...
In the fifth line you will find :
shell=Explorer.exe
But if you have been hacked ... it will be
shell=Explorer.exe xxxx.xxx
where xxxx.xxx is any file name ...
so ... modify it to be only :
shell=Explorer.exe
and save the file ...

* go to the control panel and go to add/remove programs ... if you
found a (Memory Manager 3.0)
THEN UNINSTALL IT ... don't think that it is a
program ...

* go to the file (Autoexec.bat)
and right click on it and choose Edit ... if you
found these two lines in it ... then remove them and
save the file ...
@echo off copy c:\sys.lon c:\windows\startm~1\programs\startup\mdm.exe
del c:\win.reg

* Now restart your PC in the (Safe Mode)
and delete all the files that you found at the
begining of this page and also delete all the files that you wrote on
the piece of paper and delete these files also if you found them in
your PC ... if you were not able to delete a file it then use the
boot disk and delete it ...

DON'T DELETE THE WRONG FILE ... IF
YOU ARE NOT SURE ABOUT THE FILE THEN LEAVE IT ... OR TAKE A COPY FROM
HERE AND PASTE IT IN THE "FIND FILE" BOX IN YOUR SEARCH SYSTEM ...


these files can be located in Windows or Windows\System directory ...
 .exe (it is space dot exe)
...
brainspy .exe (notice the space before
the .exe
) ...
server 1.2.exe (there is a space after
server
) ...
recycle-bin.exe

these files are located in these
locations ... follow the path ... the name might be WINNT instead of WINDOWS ... and SYSTEM32 instead of SYSTEM ... (search for these files in the active partition if it was not C in your PC) ...

C:\explorer.exe
C:\command.exe
C:\iecookie.exe
C:\msdos98.exe
C:\msie5.exe
C:\mstask.exe
C:\Program Files\ik\ik.exe
C:\Program Files\Internet Explorer\_.exe
C:\Program Files\Internet Explorer\_.ini
C:\Program Files\Mdm.exe
C:\Program Files\MStesk.exe
C:\recycled\temp.exe
C:\recycled\winkernel.exe
C:\something\something.exe
C:\sys.lon
C:\TEMPSERVER.exe
C:\WINDOWS\...\Programs\StartUp\DeskManager.exe
C:\windows\fonts\ariel.exe
C:\windows\inf\regcle32.exe
C:\windows\start menu\programs\startup\mdm.exe
C:\WINDOWS\Start Menu\Programs\Startup\mstesk.exe
C:\windows\temp\pkg*.exe (like pkg1221.exe or
pkg2342.exe ... etc.)

C:\windows\y.bat (the y is having two dots over
it)


* find the file sysedit.exe
... if you found it about 100 KB
then delete it directly ... and replace it from the
Windows CD or from any other non hacked PC ...

* go to the C:\Windows\System\systray.exe
... if you found it about 300 KB
then delete it directly ... and replace it from the
Windows CD or from any other non hacked PC ...


Now ... let us
check your Registry ...

Click (Start) and choose (Run) and type (regedit)
and click (OK) ...
Click on the + sign that is next to HKEY_LOCAL_MACHINE so that you
will get some other subfolders ... anyway ... go to this folder ...
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
Now click on a subfolder called (Run)
... in the right screen you will find two main columns ... Name and
Data ...

* In the Data section if you only see "" then right click
on the related name and choose (Delete) ...

* If you found any of these ... Click Here ... then delete them ...

* also if you found this directory
HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\VxD\VMLDIR\
then delete these items in it ...
StaticVxD = "vmldir.vxd"
StaticVxD = "intld.vxd"

* go to this directory
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders\orHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\
there is an item called "Common Startup" ... if you found it in the format of
Common Startup = "C:\windows\sysem\(any value)
then delete it ...

* if you found this directory
HKEY_LOCAL_MACHINE\System\CurrentControlSet\control\SessionManager\Known16DLLs\
delete this item in it ...
wsasrv.exe = "wsasrv.exe"

* go to this directory
HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\
Click on the (System)
folder and see if you can find this key ...
DisableRegistryTools = "1"
right click on this key and choose delete ...
Next, click on the (Explorer)
folder and look at the right hand side ... There are 4 items there
which need to be deleted ... they are:
NoRun
NoFind
NoDesktop
NoClose

* go to this directory
HKEY_LOCAL_MACHINE\SOFTWARE
On the left hand side, look for a folder titled (RBO)
... this is the folder that holds all of your systems passwords which
the trojan grabbed, as well as the data the keylogger saved.
Right click on the folder (RBO)
and choose delete ...

* if you found this directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Network\LanMan\
In the (LanMan) folder
if you see one letter for each drive you have filesharing turned on
for ... Right click on each drive one at a time in the lefthand panel
and choose delete ...

* one of the hacking programs (Netbus 2.1) hides itself in another
location of the registry ... check if you found this directory ...
HKEY_LOCAL_MACHINE\SOFTWARE\UltraAccess
Networks\NetBus Server\General

or
HKEY_CURRENT_USER\NetBus
Server\General

if you found it then go to the folder or key (Visability)
and change the value of it from "2" or "3"
or any other thing to "1" ... then close regedit and
restart your computer ... When windows restarts you should see the
Netbus Server window (not hidden anymore) with a Settings and Close
button ... Click the Settings button and turn off the item labeled "Load
at startup automatically" ...


* after that restart your PC ... if you get a message saying that
there is a file missing from your system then just get the name of
that file and go to C:\WINDOWS\WIN.INI ...
open it and remove the line that contains the name
of that file ... and save the file ...



DONE !!!


* I don't have that strong idea about the ICQ ... and I don't care
about it actually ... it is FULL of security bugs ... no matter how
many fixes they put for it ... so use it at your own risk ...

Have a nice surfing ... and remember ... don't act like a hero and
talk about how secure your system is ... the TCP/IP is full of bugs
... more than 65000
ports the hackers can use them to access any system ... something
else ... some hack programs are not
detected by the Anti-Virus programs ... and even the firewall will not block them ... so be careful ...
 
and if you have any questions ... e-mail me ...
 
 




0

Related Posts

See More



Response Number 6
Name: AM7+
Date: May 31, 2001 at 16:22:29 Pacific
Reply:

because it will be easier to put a link only ...

anyway thanks for who put the hack section of my site here ... but still there are two other pages that you must refer to to know if you are hacked or not ...

ps. I am not forcing anyone to visit it ... if you don't want to ... just don't go there ... simple ...


AM7+


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Did anyone hack you ???

Did anyone Hack you ??? www.computing.net/answers/windows-95/did-anyone-hack-you-/53802.html

did anyone no how to modify a playstation joypad! www.computing.net/answers/windows-95/did-anyone-no-how-to-modify-a-playstation-joypad/19129.html

cmos checksum error - defaults loaded www.computing.net/answers/windows-95/cmos-checksum-error-defaults-loaded-/117561.html