I got hacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by gothichero, Nov 16, 2007.

  1. gothichero

    gothichero Private E-2

    I was chatting on an instant messenger. This guy got all pally pally and finally started giving out my personal info. He even knows my credit card information. And he is a complete stranger. Later he said he hacked into my accounts and did not tell which ones. I keep the same password for almost all the accounts. How can he harm me. He said he is an ethical hacker and that he wont use my information. I asked him how I can protect my account he asked me to change my birthdate on the accounts and delete all the email I consider private. I cant possibly delete email right? And I couldn change my birth date anywhere. I have been changing my passwords everywhere now. It is so scary. I mean I feel intruded upon and so naked. Is there any anti hacking software? How do I make sure he doesn't get access to any of my information:boxing:box:mading:boxing:mad:mad:mad:mad:mad:mad:mad:mad:mad:mad:mad
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    There is always the possibility that he was lying to you...but if he actually did hack you (and you would have had to click on something in an email or in the chat room) changing your passwords while still hacked will do no good.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. gothichero

    gothichero Private E-2

    I have attached the files in the same order
     

    Attached Files:

  4. gothichero

    gothichero Private E-2

    Here is the rest of the files which you need. I did not have any problems going through the procedures except that I could not connect to internet while in safe mode so I had to do the online scanning in normal mode. Panda scan reported 3 hacking tools. I managed to find the identity of the hacker. He has a profile on a social networking site: <snip>

    When he started chatting with me that day, he sent me a file, an htm file which I naively accepted and opened and that is when I got hacked I think. The htm file took me to this website. <snip>

    He is a professional hacker and seems to know a lot about hacking, looking at his orkut profile and also the site. He is a muslim and I don't want to sound narrow minded or islamophobic but in my country they are usually engaged in crime and terrorism. He has all my personal information and may use it for any purpose. He calls me up on my cellphone and talks like a buddy. He even requested details of a company based in the town a reside. I sneered at him saying since he is a hacker it shouldn't be difficult for him to find any information. He became aggressive after that. I feel stalked. In my country, sexual preference leads to imprisonment. And he knows mine. He could even be reading all that I post here now.

    In my town there is a cyber crime cell whose website is : <snip>

    They have listed hacking, cyber stalking as crimes for which one could get imprisoned. However, watching porn, using P2P networks are also seen as crimes. Since I have some porn and also download music through P2P networks, I cant even approach them. Is there any way I can block his IP address? Is there any way I can stop people from viewing my personal details in emails. I changed all the passwords of my accounts but I know that would not help. How do I protect my email accounts and other online private information. Is there any software that I could buy or is there a freeware? To protect myself from hackers?

    Also, my computer shuts down automatically at random times. I'm not able to attach newfiles.txt its too big. So i'll attach in a different reply
     

    Attached Files:

    Last edited by a moderator: Nov 18, 2007
  5. gothichero

    gothichero Private E-2

    I'm sorry but I don't know how the file got so big. It seems to be filled with tmp files. Where do they come from. How do I stop the tmp files and what are they anyway? I have broken the file into five smaller files. If they are not of any use, I really do not know what I must do. :-(
     

    Attached Files:

  6. gothichero

    gothichero Private E-2

    The rest of newfiles and I have also put that in a zip file. Its not my idea to bump but I'm not able to attach since the file is too big.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's remove those temp files (since I assume CCleaner did not):

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the logs for:
    ShowNew
     
  8. gothichero

    gothichero Private E-2


    I did it this time... I ran the above program before running shownew. BUt I still have tmp files though they are only today's. However, the size of the file this time is very small. Help me get rid of that hacker please
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the log from the Panda scan so I can see where it is reporting the virus ....also:
    Download this file to your desktop - Combofix.exe
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  10. gothichero

    gothichero Private E-2

    Hi, I could not run combofix.exe. When I download and run it, it says it is outdated and the latest version needs to be used and uninstalls and leaves behind an internet explorer icon on desktop which I deleted. I ran pandascan again last night but before it could finish there was a power failure and i lost the report. it had found 5 hacker tools and rootkits. today I ran it again but it found only three. however I have attached it here.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Here is the workaround for ComboFix:

    If you get a message from ComboFix saying it has expired, change the current date on your PC back to mid October 2007 and then try again. After getting ComboFix to run, set your date back to normal.

    Attach that log.
     
  12. gothichero

    gothichero Private E-2


    I downloaded again from the link provided above and ran the program. It starts to scan file but closes within a few seconds abruptly. But it does not uninstall like before
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. gothichero

    gothichero Private E-2

    HI... I shall install that after college.. Could you please tell me how to remove those hacking tools abnd rootkits which pandascan found? thank you
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post the log from Panda scan so that I can see where it is reporting them - what is reported in the activescan log are not problems.
    Also, did you turn back your system clock to mid-Oct. before running the ComboFix?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds