PDA

View Full Version : Hacking (WXP-Home)



tulsagirl
10-06-2003, 09:04 AM
I am having this problem with someone getting into my computer. Everytime I check it they have changed the registered to name in the system properties. I have also installed Zone Alarm and that didnt stop them either, in fact they sent a message on my computer that pops up everytime I restart my computer that says "I can get through your firewall no matter what"...I am running windows xp home with DSL and router with four other computers in my home, if anybody can help me stop this please reply. Ive got everything set on my computer to high security but its not stopping them.

Thanks,

beginner
10-06-2003, 10:59 AM
First disconnect from the internet ... goto HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run could be the same with HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run
Then delete all the entries …. After that search in C: for *.bat and check them all to see if a file “.bat” in calling a .exe to be run or something like that …and then delete that “.bat” file and delete also the “.exe” he’s calling ...the ".exe" could be in C:\ or in the systemroot or wherever ... and then of course reboot ur PC.
Try this and then we'll c ......

adg
10-06-2003, 12:35 PM
ZA and your router should be stopping it. Go to Services and disable the Messenger Service and see if that stops the pop-up message you are getting - my guess is that it's just a smartass trying to frighten you.

Allan
<a target="_blank" href=http://www.tweakdatabase.com/idealbb>tweakxp.com</a>

tulsagirl
10-06-2003, 02:48 PM
Well...I tried it and it didnt work. Any other suggestions?

adg
10-06-2003, 03:09 PM
I apologize tulsagirl, I missed the part in your original post about the registered name changing. Clearly someone is gaining access. I'd immediately contact my ISP and let them know. They may be able to put some sort of trace on the line.

Allan
<a target="_blank" href=http://www.tweakdatabase.com/idealbb>tweakxp.com</a>

Xavier_Ao
10-06-2003, 09:03 PM
Knowing where that info lies in the reg, could it still be executed locally by a script, .exe or something else as such, hiding somewhere obscure in the registry or startup, but as of yet, not found?

I'd go with Allan's recommendation though, just to be on the safe side. See what they can come up with.
You said that you installed ZoneAlarm, did it have any alerts that may have provided an IP address or some other piece of info you could provide your ISP if you contact them? Any extra info would help.

Always glad to help!
Josh /images/forums/icons/smile.gif

You know why they called it <font color=blue>Windows</font color=blue>?
Because as soon as it opens, all the bugs get in.

adg
10-07-2003, 05:31 AM
Xavier_Ao - Didn't recognize you at first. Are you travelling incognito? Why the new moniker?

Allan
<a target="_blank" href=http://www.tweakdatabase.com/idealbb>tweakxp.com</a>

tulsagirl
10-07-2003, 06:42 AM
Ive already tried what Allen said to do and that didnt stop him either.

I dont know what else to do or if reformatting my computer would get rid of anything that he might of installed prior to putting on Zone Alarm.

Ive also been thinking about going back to Windows Me, I dont know if I like XP that well or not. It really slows down my system and seems to be alot of bugs in it still.

But Im sure that if I decided to do that its NOT going to keep him out...

He is "VERY" persistant!!!

Ill keep checking this forum for any ideas.

Paul S
10-07-2003, 06:58 AM
Hi

I suspect, as has already been suggested there is something running locally.

Here is a link to a piece of software that monitors your open ports and provides and IP Address.

<a target="_blank" href=http://www.protect-me.com/freeware.html>http://www.protect-me.com/freeware.html</a>

Hope this helps...

<font color=green>Paul</font color=green>

<font color=blue>mailto:paul@winguides.com (paul@winguides.com)</font color=blue>

rjmac
10-08-2003, 05:35 AM
Hi,
You could also post a HijackThis log and we could have a look at everything that is running to see if something out of the ordinary shows up.
Go to Bulldog@TweakXP (http://tomcoyote.org/hjt/>http://tomcoyote.org/hjt/</a>)

Xavier_Ao
10-08-2003, 06:16 AM
Allan,
I'm the same me that I've always been.
Are you getting me confused with the other Josh? /images/forums/icons/laugh.gif

Always glad to help!
Josh /images/forums/icons/smile.gif

You know why they called it <font color=blue>Windows</font color=blue>?
Because as soon as it opens, all the bugs get in.

adg
10-08-2003, 06:18 AM
That's the same name you've always used (Xavier_Ao)? Wow - this getting older stuff is tough /images/forums/icons/frown.gif.

Sorry Josh, guess I'm just confused (which is not an abnormal state for me /images/forums/icons/frown.gif). Well, hi anyway /images/forums/icons/smile.gif

Allan
<a target="_blank" href=http://www.tweakdatabase.com/idealbb>tweakxp.com</a>

Xavier_Ao
10-08-2003, 06:26 AM
Yup. Ever since I registered months ago.
No problem though, just one too many Joshes? /images/forums/icons/laugh.gif

Then there's also jdharm, but he's been here longer...

Always glad to help!
Josh /images/forums/icons/smile.gif

You know why they called it <font color=blue>Windows</font color=blue>?
Because as soon as it opens, all the bugs get in.