my friend got hacked

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
He was wondering why he was so low on HD space... it turns out someone dupmed gigs of stuff in his System Volume Information folders, including The Core (german version), 4 other movies, a couple gigs of porn, and some games. Unfortunately we can't figure out how he got hacked, but disconnected his machine from the network to be safe.

He now has a service "Fvck-U" which calls itself "Windows Logon" to disguise itself. I can't find any info on google. Think we can clean it up, or should he format? There was an autoexec.bat in his root directory that started a bunch of services including a "net start fvck-u".

(note that the v in fvck is a u in both cases mentioned above)
 

TubStain

Senior member
Apr 19, 2001
935
0
0
I would do a clean format, since they might have installed a backdoor.

If you are running windows 2000, make sure you set a windows Administrator password. Many ppl leave it blank, making you vulnerable. Hackers, generally sweep entire networks looking for multiple vulnerabilites. College networks are some of their favorites becuase of the high speed connections. So beware.
 

yellowperil

Diamond Member
Jan 17, 2000
4,598
0
0
Just to be safe I would do a zero-fill format in case he got into the boot sector. Most hard drive manufacturers have utilities on their website to do this, or you can create an MS-DOS bootdisk and use an old IBM program called Wipe.
 

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
Originally posted by: yellowperil
Just to be safe I would do a zero-fill format in case he got into the boot sector. Most hard drive manufacturers have utilities on their website to do this, or you can create an MS-DOS bootdisk and use an old IBM program called Wipe.

Windows aggressively destroys the boot sector when you install... as many linux users know from experience ;)
 

wnied

Diamond Member
Oct 10, 1999
4,206
0
76
First, Download, install and update Spy-Bot. They have a few of those style names on their list of things to look for. If it finds nothing, then you need to format and reinstall your OS. My guess would be your friend downloaded a trojan unknowingly and it got opened and delivered its payload, essentially rendering your machine an extension of someone elses.

~wnied~
 

Anubis

No Lifer
Aug 31, 2001
78,712
427
126
tbqhwy.com
Originally posted by: CTho9305
Originally posted by: yellowperil
Just to be safe I would do a zero-fill format in case he got into the boot sector. Most hard drive manufacturers have utilities on their website to do this, or you can create an MS-DOS bootdisk and use an old IBM program called Wipe.

Windows aggressively destroys the boot sector when you install... as many linux users know from experience ;)
yea i know that 2000 does that amd im sure XP does also. learned that the hard way
 

Derango

Diamond Member
Jan 1, 2002
3,113
1
0
Originally posted by: TheEvil1
Originally posted by: CTho9305
Originally posted by: yellowperil
Just to be safe I would do a zero-fill format in case he got into the boot sector. Most hard drive manufacturers have utilities on their website to do this, or you can create an MS-DOS bootdisk and use an old IBM program called Wipe.

Windows aggressively destroys the boot sector when you install... as many linux users know from experience ;)
yea i know that 2000 does that amd im sure XP does also. learned that the hard way

95, 98 and ME do it too :)

 

dfi

Golden Member
Apr 20, 2001
1,213
0
0
Take out the hd, put it on the backyard lawn, and put some big bullet holes in it, all the while shouting "fvck YOU, fvck YOU!"

dfi