hacked

01/18/2009 01:32 ShyroN1337#1
well a glavier got hacked, i dont know how, butmaybe u can tell me the best way to find out if theres a keylogger on my pc - please dont say "reinstall windows" thx
01/18/2009 01:34 TheOwnWay#2
Sollte weiter helfen:

[Only registered and activated users can see links. Click Here To Register...]
01/18/2009 01:41 ShyroN1337#3
Quote:
Mein Tipp: Formatier deine Festplatte und setz Windows neu auf, danach das machen was hier steht, dann klappt es auch mit dem Computer.
najaa^^
Quote:
please dont say "reinstall windows" thx
01/18/2009 01:45 TheOwnWay#4
Ist halt nur der Tipp, welchen ich im übrigen auch empfehle.
Sonst befolge halt die anderen Sachen..
01/18/2009 01:47 ShyroN1337#5
mein prob is das ich immer fehler kriege
dateien werden expandiert (0%..)
dann kommt ein fehler(code) 0x80070017 / 0x8007045D
hab beide gegooglt, aber hat nicht geholfen
habe auch eine original cd/key
01/18/2009 01:49 TheOwnWay#6
Wobei? Beim formatieren oder was?
01/18/2009 01:51 ShyroN1337#7
jap
01/18/2009 01:55 TheOwnWay#8
Ich adde dich mal in ICQ, geht dann wohl einfacher.

edit: olol bis ja schon drin ;f
01/18/2009 02:43 lolrko#9
i really can't understand all posts , just the main post ..
once i got keylogggers on my pc i used Malwarebytes' Anti-Malware
it is really a good program , just when u are running scanner , make it perform the general scan [not the quick one]
i hope everything will be fine soon
01/18/2009 10:06 ShyroN1337#10
Okay im scanning with the malwarebytes software, after that ill reboot and scan again and post here / edit the result
01/18/2009 10:22 audi0slave#11
or stop entering pron sites xd

btw scan the downloaded files online.dont ever execute a .exe program without scanning it.
01/18/2009 10:40 ShyroN1337#12
Quote:
Originally Posted by InDaClub View Post
or stop entering pron sites xd

btw scan the downloaded files online.dont ever execute a .exe program without scanning it.
well maybe it wasnt even a keylogger or trojan, just bruceforced or something like that

the scan needs really long already 2 hours and 130.000 files checked
01/18/2009 11:04 audi0slave#13
yea as you saw in the other thread,people are trying to bruteforce silkroad accounts.

best thing you can do is provide your accounts with strong passwords
01/18/2009 12:19 ShyroN1337#14
Quote:
Originally Posted by HijackThis v2.0.2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:23, on 18.01.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [Only registered and activated users can see links. Click Here To Register...]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Only registered and activated users can see links. Click Here To Register...]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Only registered and activated users can see links. Click Here To Register...]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Only registered and activated users can see links. Click Here To Register...]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Only registered and activated users can see links. Click Here To Register...]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Only registered and activated users can see links. Click Here To Register...]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O13 - Gopher Prefix:
O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 4973 bytes
Quote:
Originally Posted by Malwarebytes' Anti-Malware 1.33
Malwarebytes' Anti-Malware 1.33
Datenbank Version: 1663
Windows 6.0.6001 Service Pack 1

18.01.2009 11:42:12
mbam-log-2009-01-18 (11-42-12).txt

Scan-Methode: Vollständiger Scan (C:\|)
Durchsuchte Objekte: 198296
Laufzeit: 2 hour(s), 51 minute(s), 15 second(s)

Infizierte Speicherprozesse: 0 -> nothing found
Infizierte Speichermodule: 0 -> nothing found
Infizierte Registrierungsschlüssel: 0 -> nothing found
Infizierte Registrierungswerte: 0 -> nothing found
Infizierte Dateiobjekte der Registrierung: 1 -> deleted
Infizierte Verzeichnisse: 0 -> nothing found
Infizierte Dateien: 0 -> nothing found

Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden) -> nothing found

Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden) -> nothing found

Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden) -> nothing found

Infizierte Registrierungswerte:
(Keine bösartigen Objekte gefunden) -> nothing found

Infizierte Dateiobjekte der Registrierung:
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden) -> nothing found

Infizierte Dateien:
(Keine bösartigen Objekte gefunden) -> nothing found
Currently running Spybot, I'll edit this post and show the result.
01/18/2009 12:33 ShyroN1337#15
file to long :D

Im clean