WTF!!! friends computer hacked!? no...a GHOST!?!? ...EDIT:possible backdoor virus..EDIT2:FIXED thanks hubris&boyblunder!

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

DanTMWTMP

Lifer
Oct 7, 2001
15,908
19
81
Originally posted by: Ketteringo
Originally posted by: DanTMWTMP
Originally posted by: Ketteringo
So, he unplugs his ethernet cable, does a complete reinstall, and still has this problem? Right...
rolleye.gif



My suggestion, stop smoking whatever you are smoking, stop drinking whatever you are drinking, and go to bed and see if this problem is still happening tomorrow morning
rolleye.gif
rolleye.gif
rolleye.gif
rolleye.gif

well, i hope someone puts a new backdoor on your ass...go fvck yourself...i don't need your comments

I was just saying that the statements you made were impossible. It is impossible for a backdoor or trojan or whatever you think you have to survive a complete reinstall. If you dont want my comments, fine, dont post this crap here. I dont get backdoors because I dont run .com email attachments I get in emails entitled 'barnyard babes get ridden by horses' or whatever you and your 'buddy' are in to.

it didn't survive the format. It was "installed" again when he reconnected his internet to download updates after the reformat.
 

Hubris

Platinum Member
Jul 14, 2001
2,749
0
0
Originally posted by: DanTMWTMP
Originally posted by: Ketteringo
Originally posted by: DanTMWTMP
Originally posted by: Ketteringo
So, he unplugs his ethernet cable, does a complete reinstall, and still has this problem? Right...
rolleye.gif



My suggestion, stop smoking whatever you are smoking, stop drinking whatever you are drinking, and go to bed and see if this problem is still happening tomorrow morning
rolleye.gif
rolleye.gif
rolleye.gif
rolleye.gif

well, i hope someone puts a new backdoor on your ass...go fvck yourself...i don't need your comments

I was just saying that the statements you made were impossible. It is impossible for a backdoor or trojan or whatever you think you have to survive a complete reinstall. If you dont want my comments, fine, dont post this crap here. I dont get backdoors because I dont run .com email attachments I get in emails entitled 'barnyard babes get ridden by horses' or whatever you and your 'buddy' are in to.

it didn't survive the format. It was "installed" again when he reconnected his internet to download updates after the reformat.

If that's the case, have hime d/l all Windows Updates (Available for standalone d/l on the Windows Update site), and also the latest virus defs from sarc.com (alaso available as strandalone d/ls) so he can update Windows and get his virus defs up to do date right away. Check the registry in Run and RunServices and look for anything suspicious.

Also, consider d/ling a better firewall than WinXP. And if he has a router, is he sharing the connection with someone else? Sounds like it could be a prank, depending on how good with computers the other person is.
 

TheBoyBlunder

Diamond Member
Apr 25, 2003
5,742
1
0
I'm going to take a wild shot at this...

1) try replacing the ethernet card. It's possible (somehow...I'm really stretching here) that the "hacker" has a program monitoring for a particular mac address at his IP so the "attacks" can resume. It might (probably won't) fool it if it sees a different mac address (if there's a program at all).

2) Assuming he has XP...tell him to format and don't download anything, just get everything ready to get online. Open up a program that monitors all opened ports* and confirm that none are open. Then plug in the internet cable and get a new list of ports. The culprit (assuming there is one) might be one of the ports that opened after the internet cable was plugged in.

3) Did you say he was on a router? If so, disconnect everyone else from the network (temporarily) and see if the "attacks" continue. If they don't, then it's time to worry. If they do, he's got a roommate's ass to kick.

4) Buy a new computer. That thing is cursed.

5) In any case, get a better firewall than that piece of crap that came with windows.

*for a simple program , go to the command prompt and type netstat. It's not terribly fancy, but it'll get the job done.
 

FuZoR

Diamond Member
Sep 22, 2001
4,422
1
0
rotflmao on the jack off part.... after reading that i could'nt take it seriously.

anyways.. thats just weird not sure what to say.
 

79Blazer

Golden Member
Nov 12, 2003
1,037
0
0
You're either a piss-poor liar, or your friend pulled a joke on you.

Personally i'm thinking your a piss-poor liar. Many of the things you described happening are impossible.

Oh and why the hell would you tell us he was going to watch pr0n and punch the clown?
 

mcveigh

Diamond Member
Dec 20, 2000
6,457
6
81
what other pc's are on the network?

when he reinstalled did he FORMAT or just install on top of windows.

did he setup the ame username and password?

 

KeyserSoze

Diamond Member
Oct 11, 2000
6,048
1
81
Eh, I don't know about this one.

IF in fact you aren't pulling anything on us, I'm gonna take one more guess here. You said the program got "reinstalled" after the reformat? Does he use "cracks/patches" for software? If he's using the same crack that in fact HAS a virus, then it's a posibility. But IF he has ANTI-VIRUS that is fully updated, then I'm clueluess.

And the spankavision part....dude, we REALLY didn't need that.




KeyserSoze
 

cliftonite

Diamond Member
Jul 15, 2001
6,900
63
91
Originally posted by: DanTMWTMP
EDIT
there's no wireless.....

i think after the ethernet is pulled, the backdoor virus which is undectectable puts down random strings of text and random actions in place of the actions that should come from the originator.

The culprit knows some of his personal info (probably grabbed from looking @ his emails).

Should we call the cops on this one?

also, This is happenning right now. If you don't believe me fine...But I've never lied in these forums, and I never will; and I am only trying to get assistance as to what I should do. I despise liers in this forums (aimster, dennifloss, etc...). some of you know me personally, so why the hell should i lie about this?

I'm trying to get rid of this virus/backdoor/trojan/whatever it is...so if any of you have any info or experience on this, I'd greatly appreciate the advice.
i'm having jeff to get his isp to change his ip right now

------------------------------



(long but wierd strange story...SCARY stuff!)
First off, my friend (let's call him jeff) has a legit copy of norton antivirus 2003 that's updated and his subcription has still about 7 months left in it.

He does his usual weekly autoscan every friday night, and the program updates itself of definitions. He has all the windows critical updates.

He is protected by both a hardware firewall (router) and a software firewall (windows xp's standard firewall)


This sounds like a case of a backdoor virus...

Ok so a week ago, jeff is typing up some email, and all of a sudden the computer starts talking to him saying "hey sups you're jeff right? and your roommate's kevin right?" (this info is correct) My friend goes WTF and closes his email right away. His icons now get selected and are moved to the trash can by themselves. He opens up AIM and everytime there's a text field, the mysterious guy talks to him.


jeff gets pissed, so he disconnects the internet cable, but the dude is still talking to him!...While the computer is attempting to do a virus scan, in the background, this dude attempts to delete his icons and continues to pester him about pr0n and such in his computer (jeff has lots of it). Jeff ignores this thinking the virus scanner will pick something up.

While the virus scan is running, jeff decides to watch pr0n and jack off...only to have the video interrupted by pauses and stoppages. He gets mad and starts to watch TV via TV tuner on his computer. As he's watching TV, the TV starts switching channels on its own!!...


The virus scanner finishes and picks up NOTHING.


fast fwd a week..Jeff informs me of what happens...

He tells me he has already reformmated the comp. I told him to reformat again, this time w/ the windows update CD (burned setup files from the other windowsupdate site...where you can dl 'em individually).

after reformatting and connecting to the internet to download nessasary virus updates (for his nortons) and AIM, the culprit is at it again. He now recieves a bunch of jibberish on any text field that seems to be open. (ex: a;slkdjf;aklsdjfsafaawwwwwwwwwwwwwadffffffffwasdffffffffff...stuff like that). He immediately disconnects the ethernet cable.

he turns on his TV and boom the channel starts to flip on its own. Icons start moving towards the trashcan.


remember this is AFTER A REFORMAT AND A MERE DOWNLOAD OF AIM AND VIRUS SCAN UPDATES. he already has all the windows updates that deal w/ the recent string of viruses.


what's going on?!...is it even possible for someone to talk to him still even w/ the ethernet cable disconnected?...Is it possible to hack through the coax cable that's connected to his TV tuner card?..



damn this is nuts..


cliff notes:
-friend supposedly gets hacked...he gets wierd msgs from someone from any text field that may be on the screen....even after the ethernet cable is disconnected, a conversation still carries on.

-friend has all virus updates and windows updates, firewalls etc..and this still happens..

-after a reformat w/ updates, and even connecting to the internet to download AIM and nortons updates, the virus/attacker hits again....even after the ethernet cable is detached.

thats wierd
 

dquan97

Lifer
Jul 9, 2002
12,010
3
0
I wonder if his roomate installed VNC in his computer without him knowing...then reinstalled it after the format
 

DanTMWTMP

Lifer
Oct 7, 2001
15,908
19
81
Originally posted by: TheBoyBlunder
I'm going to take a wild shot at this...

1) try replacing the ethernet card. It's possible (somehow...I'm really stretching here) that the "hacker" has a program monitoring for a particular mac address at his IP so the "attacks" can resume. It might (probably won't) fool it if it sees a different mac address (if there's a program at all).

2) Assuming he has XP...tell him to format and don't download anything, just get everything ready to get online. Open up a program that monitors all opened ports* and confirm that none are open. Then plug in the internet cable and get a new list of ports. The culprit (assuming there is one) might be one of the ports that opened after the internet cable was plugged in.

3) Did you say he was on a router? If so, disconnect everyone else from the network (temporarily) and see if the "attacks" continue. If they don't, then it's time to worry. If they do, he's got a roommate's ass to kick.

4) Buy a new computer. That thing is cursed.

5) In any case, get a better firewall than that piece of crap that came with windows.

*for a simple program , go to the command prompt and type netstat. It's not terribly fancy, but it'll get the job done.

after a 3rd reformat and installing all updates from a CD (thanks for the link hubris for the virus updates!)
I changed all the ports and such like you told me boyblunder.

The isp changed the ip address, and I used a different ethernet card so the mac address is different.

Seems like that did the trick. He can now do his please his johnson w/ ease lol :p

thanks hubris for the virus link and boyblunder for the suggestions! much appreciated :)
 

DanTMWTMP

Lifer
Oct 7, 2001
15,908
19
81
Originally posted by: TheBoyBlunder
Glad to help stop the attacks. Did you ever figure out what or who was causing them?

couldn't figure that one out. I'm not a l33t hax0r so there was probably no way i can find that out. Usually there's 3-4 SVCHOST.exe's running..he had 6 of them running in the background...so i assume it was one of the SVCHOST.exe's ....