[x]
We are happy to see you on AH
AH - AndhraHackers is a place to entertain as well to spread knowledge around.
One of the most exciting Indian Community over Internet.

We would like you to Join AH Forum Today.

Why to JOIN AH forum ?
Pages: [1]   Go Down
  Print  
Author Topic: my PC is under attack  (Read 468 times)
0 Members and 1 Guest are viewing this topic.
sravana
Jr. Member
**

Karma: +3/-1
Offline Offline

Posts: 79



« on: October 26, 2009, 04:15:41 AM »

my PC is under attack
how to protect my self ...........
the attacker is hacked my yahoo a/c and he is  accessing my pc remotely 
plz try to help me out  and iam unable to run task manger and right click also
but iam suer my PC is under attack plz help me
Logged
Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
« on: October 26, 2009, 04:15:41 AM »

 Logged
Hackuin
Location: /home/hackuin
ICW Manager
Sr. Member
********

Karma: +17/-0
Online Online

Posts: 362


Exploit Code Not People!


« Reply #1 on: October 26, 2009, 04:49:22 AM »

Sravana,
Don't get panic.
First thing, breaking into your messenger is another thing and breaking into your PC is other thing, If he/she has managed to get remote access to PC then he/she might have set the key-logger to get your messenger password or there is pretty much nothing left when he can access your PC remotly.

Anyways, what do you exactly mean by "accessing my pc remotely"? still, here are the thing, which may be helpful to you.

1. Check for startup services. (RUN --> "MSCONFIG") and check start up services.
2. Disable un-necessary running services or remove the suspected services.
3. Use a decent firewall, I recommend you to get "Live One Care" which is available for trail version of 90 days.
4. Give a complete scan, it is well effective firewall/anti-virus program for windows OS.

Note:
The common way is to get the back-door work is make a backdoor servers port in a listening mode and, check for common back-door ports. Scan you system either by port-bunny or Nmap.
Also, you can use Netstat for current active ports and to whom they are connected to.
For enabling/disabling Task manager, use either registry or use Microsoft Management Console (MMC) [ start --> run --> "MMC"]
Logged

"Free software" is a matter of liberty, not price. To understand the concept, you should think of "free" as in "free speech," not as in "free beer."
"Microsoft is not the answer. Microsoft is the question. NO (or Linux) is the answer."
"Unix, MS-DOS, and Windows NT (also known as the Good, the Bad, and the Ugly)." &
"Ubuntu - Linux For Human Beings."


Currently reading books:
Just say No to Microsoft [how to ditch Microsoft and why its not as hard as you think] -- by Tony Bove
How to cheat at Securing Linux -- by James Stanger
d3c0d3r
ICW Team Member
Full Member
*****

Karma: +9/-0
Offline Offline

Posts: 233


y0


« Reply #2 on: November 14, 2009, 03:00:36 AM »

HM NICE INFO
Logged
ÄŋőήŷMŎǙŜ
Global Moderator
Sr. Member
*

Karma: +19/-0
Offline Offline

Posts: 475

A Only Non-Hacker in AH TeAm


WWW
« Reply #3 on: November 17, 2009, 02:22:58 AM »

to enable task manager, registry editor  just download the below uploaded by me and read the text file before using

Code:
http://www.mediafire.com/download.php?fvzwnyznhng
Logged

Sm4rt_Hax0r
Global Moderator
Full Member
*

Karma: +4/-1
Offline Offline

Posts: 193



WWW
« Reply #4 on: December 14, 2009, 02:18:33 AM »

Congrats!!! for being attacked!

If I would be you, I would not rack my brains over this and get back up of my data... Do debug, format and re-install the stupid windows...
Enjoy Smiley
Logged
sravana
Jr. Member
**

Karma: +3/-1
Offline Offline

Posts: 79



« Reply #5 on: December 14, 2009, 04:37:56 AM »

10x 4 ur advice ,
n i learn positiveness from u........
"If I would be you, I would not rack my brains over this and get back up of my data... Do debug, format and re-install the stupid windows..." these words make me to think and do further things........... 
Logged
shadowwwclone™
Full Member
***

Karma: +2/-0
Online Online

Posts: 246


shadowwwclone™


WWW
« Reply #6 on: March 31, 2010, 08:16:52 AM »

I really agree wid u Sm4rt_Hax0r iagree iagree
Logged

shadowwwclone™
hellboy
Jr. Member
**

Karma: +3/-0
Offline Offline

Posts: 81


I'm unleashed from Hell.


« Reply #7 on: May 06, 2010, 09:08:36 PM »

What a smart answer... "Reinstall windows"... Don't take it as an offend, but its like when someone asks you for a medicine for cold and you suggest Ice cream.

Lol. The last time i formatted my PC is 1 year back and that too for installing a fresh copy of windows 7 when i switched from XP.

Next time when someone approaches you for a help removing keylogger, first suggest them to install a HIPS to prevent keylogger from sending logs temporarily.
Next ask them to run a malware scan using MBAM or SAS in safe mode. If they can't install an anti-malware, just ask them to rename the installer.

If the keylogger still proves to be FUD, then lookup for any suspicious files in startup folder and upload a sample to your AV vendor. Let them analyse it and reply back.

But most of the conventional keyloggers can't go beyond malware scan.

Reinstalling OS is the first chance for noobs, but it should be the extreme thing for us.
Logged
ÄŋőήŷMŎǙŜ
Global Moderator
Sr. Member
*

Karma: +19/-0
Offline Offline

Posts: 475

A Only Non-Hacker in AH TeAm


WWW
« Reply #8 on: May 06, 2010, 09:55:58 PM »

run the hijackthis and post the report here, we can try to solve your problems
Logged

VIPS
Full Member
***

Karma: +3/-0
Offline Offline

Posts: 159


Proud to be Indian.


« Reply #9 on: May 11, 2010, 07:58:55 AM »

hi sravana,
ok, first of all, get a good and updated antivirus and completely scan and fix the virus issues.
Not being able to open task manager and right click are the issues caused by changes in the registry.
to fix them, copy the following code in a notepad and save the file with a ".reg" extension. After saving, simply launch the file.
Code:
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoViewContextMenu"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=-
This will fix the right click and task manager problem.
Even i recommend having a firewall which can block the connection between your pc and the attacker.
Finally, about the yahoo account. When both av and firewall are installed on your pc, then go to yahoo.com and simply follow the instructions in 'change your password'. Please dont keep the password similar to previous one. Also, it should not be a weak password.
This may explain what is weak and what is strong password.
Code:
http://onemansblog.com/2007/03/26/how-id-hack-your-weak-passwords/
I hope i helped u in some way.
Logged

Error 404 : Signature not found.
charan177
n00b
*

Karma: +0/-0
Offline Offline

Posts: 10


« Reply #10 on: July 27, 2010, 05:26:32 AM »

k frnd since ur system attacked out 65535 some of ur ports are connected to his computer do netstat -n with out opening anything the port which is listening its his computer ip so note tht ip n report to any andhra hacker dnt live him simply ,now to protect pc simply use lockdown2000 fire wall it blocks un necessary data goning out ,or
as other said follow msconfig method    all the best You_Rock_Emoticon
Logged
Black-Cobra
Jr. Member
**

Karma: +0/-0
Online Online

Posts: 88


Want to Explore more and more and more...........


WWW
« Reply #11 on: July 27, 2010, 09:31:02 AM »

k frnd since ur system attacked out 65535 some of ur ports are connected to his computer do netstat -n with out opening anything the port which is listening its his computer ip so note tht ip n report to any andhra hacker dnt live him simply ,now to protect pc simply use lockdown2000 fire wall it blocks un necessary data goning out ,or
as other said follow msconfig method    all the best You_Rock_Emoticon

charan, there are keyloggers that do not send the data directly to attacker. But it will send the data to any website configured at port 80 and accepting the data. Just a hint, explore more about POST method.

I also want to add here that I do not agree with the statement of hellboy that keylogger do not get beyond of malwares. I dont want to show off here but my keylogger is UD by all AV/malwares/ except dr web. But how may users use it. The point is if AV have the signature in the database , its detected otherwise not. Think of completely encrypted app which unload the AV drivers(sys) and then inject its dll in the AV process to bypass it. I know its very difficult but no impossible Smiley
« Last Edit: July 27, 2010, 09:35:14 AM by Black-Cobra » Logged

Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
   

 Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  


whitec0de.com | Techian.com | GfxLovers.com | CDN Pic | Inj3ct0r Exploit DB | Garage4Hackers
Page created in 0.127 seconds with 26 queries.