Did I get hacked?

Heraclitus

Member
Jul 30, 2001
159
0
0
I turned on my girlfriend's computer this morning, and the Windows registry checker came up and told me that there was an error in the registry and that a backup version would be used. I okayed it and the computer restarted. Windows loaded and told me that it couldn't find a file that the registry was looking for. No problem, right? I told it to continue.

Windows then detected and reloaded my network card. Okay. Then Windows started:

* It loaded a Theme (Golden Age, if you're curious) that we've never used.
* Drive sharing was turned on (it had been off before) and both hard drives were shared.
* The documents list in the start menu was reset.
* Norton Antivirus and System Works had been disabled, and couldn't be started.
* I browsed through the My Documents folder and found suspicious temp files (e.g. temp files of old Word documents that had the word "Repayment" or "Pay" in the titles.

We're connected to a network: more specifically, we're sharing a DSL internet connection with a bunch of other people, people we don't know. We're running ZoneAlarm as a firewall; however, the default settings for ZA are high security for internet but only medium security for the local network, and that's what we were running. I don't really recall the specifics of these settings, except that the local setting was supposed to preserve sharing permissions or whatever, and clearly that's been compromised.

Basically, this is my mystery: did a malicious person, presumably on the network rather than over the internet, hack us, causing the registry problem and the other changes? Or was this an innocent registry corruption/error, and did Windows make all those peculiar changes (sharing my drives, changing my theme, etc.) when it repaired the registry? How can I tell? And if my computer was compromised, is there any way I can tell what was done, or accessed? And how can I prevent this in the future?

Thanks in advance for any helpful replies; I'm a bit out of my depth here.

 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
It sounds worse than an innocent registry error. My recommendation would be to format and reinstall. Then before getting on the internet load all patches and zone alarm keeping the settings much more secure, virus protection, and maybe even tripwire for extra help.
 

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76
Before you format/reinstall:

Go to Start-->Run-->type msconfig. Check the "startup" tab (I think, its the last one on Win9x. second to last on WinME). See if there is anything suspicsous there. You might want to compare it to a non-suspect PC to see what should be running. If you've got a question about a process, post the name of it here and all the info from that line, and we'll try and figure out what it does.

 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<< Before you format/reinstall:

Go to Start-->Run-->type msconfig. Check the "startup" tab (I think, its the last one on Win9x. second to last on WinME). See if there is anything suspicsous there. You might want to compare it to a non-suspect PC to see what should be running. If you've got a question about a process, post the name of it here and all the info from that line, and we'll try and figure out what it does.
>>



If they are going to be doing this they need to check the other places these startup processes can be stored. win.ini, registry, etc. Even if they are just having troubles with the system, a format/reinstall would fix it.
 

Sleater

Senior member
Feb 16, 2001
466
0
0
What do you mean when you say your on a LAN with people you don't know?

Is it possible that one of these people physically got on your computer and changed those settings so they could access you remotely later?