Bay 12 Games Forum

Please login or register.

Login with username, password and session length
Advanced search  
Pages: 1 2 [3] 4 5

Author Topic: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)  (Read 5094 times)

Stargrasper

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #30 on: January 05, 2012, 10:07:46 pm »

It appears as if the alerts are coming from Whalesdev. It only seemed like it was from B12 because my scanner was terminating Whalesdev.

Do you know what about Whalesdev is causing the problem?  The only thing on the page of particular note is the embedded IRC client.

*sigh*
I wish people didn't make viruses.
or try and hack.
or be dicks in general.

all I can do is wish you luck. it seems that everyone else here has a better PC knowledge than me.

People will do these things.  They're just trying to make money.  If you had the chance to make that much money, you'd probably take it.

People here have strong computer knowledge because DF is an ASCII game.  That kind of thing is going to attract this kind of audience as its core playerbase.  Of course, if you've made it this far, becoming a strong computer user is easy; learn the standard tech support process and pay attention to how we fix things.  You'll learn fast.
Logged

optimumtact

  • Bay Watcher
  • I even have sheep
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #31 on: January 05, 2012, 11:20:14 pm »

Don't panic, it looks like you have something thats trying to drive traffic towards certain sites

http://www.robtex.com/ip/77.247.179.135.html

These are the sites coming off 77.247.179.135
http://www.robtex.com/ip/91.197.128.225.html

and again for 91.197.128.225

These look like dodgy domain names (barring the fact they're hosted in the netherlands and the ukraine and it sounds like you do have something running that's malicious. You should use the Task Manager and see if you can identify anything that looks out of place. I think your best bet at this point would be to boot into safemode and run a full scan with your a/v. As in safemode most processes won't start and so the av should have a better chance of finding it.

edit: looking at those port numbers thats definitely not standard behaviour, IE should only be connecting on port 80 or 8080(in some cases).
You might also want to think about getting malware bytes anti malware as well (as that specifically targets certain types of malware (such as that which might attempt to hijack the browser)) the free version will let you run a scan so do that in safe mode as well.
« Last Edit: January 05, 2012, 11:28:04 pm by optimumtact »
Logged
alternately, I could just take some LSD or something...

Stargrasper

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #32 on: January 05, 2012, 11:28:19 pm »

You know, just because it looks like it hasn't been mentioned in this particular thread...

If you have a virus/worm/etc that you simply can't remove, a fairly surefire way to kill it is to format (whip) the whole machine (or relevant partitions) and reinstall everything.  Just start over from scratch.  Mind this is a last resort desperation tactic.  You backup everything important and then make absolutely certain your backed up data is clean before you transfer it back to the machine.

This does a great job of temporarily defeating a cracker, but doesn't stop them from cracking your computer all over again.  You'll have to be careful.
Logged

Angel Of Death

  • Bay Watcher
  • Karl Groucho?
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #33 on: January 06, 2012, 12:51:45 am »

No malicious objects have been found. And the hacking messages don't pop up unless I go on Whalesdev... Maybe Whales has been hacked?
Logged
99 percent of internet users add useless, pulled out of arse statistics to their sig. If you are the 1%, please, for the love of Armok, don't put any useless shit like this in your sig.
Hidden signature messages are fun!

Stargrasper

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #34 on: January 06, 2012, 12:53:26 am »

No malicious objects have been found. And the hacking messages don't pop up unless I go on Whalesdev... Maybe Whales has been hacked?

Possible.  Report it to Symantec and McAfee to look into.  We'll find out soon enough what's happening.
Logged

Angel Of Death

  • Bay Watcher
  • Karl Groucho?
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #35 on: January 06, 2012, 02:17:00 am »

No malicious objects have been found. And the hacking messages don't pop up unless I go on Whalesdev... Maybe Whales has been hacked?

Possible.  Report it to Symantec and McAfee to look into.  We'll find out soon enough what's happening.
How do I do that?
Logged
99 percent of internet users add useless, pulled out of arse statistics to their sig. If you are the 1%, please, for the love of Armok, don't put any useless shit like this in your sig.
Hidden signature messages are fun!

Angel Of Death

  • Bay Watcher
  • Karl Groucho?
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #36 on: January 06, 2012, 04:30:31 am »

must. resist. TEMPTATION!
greatorder has become a hacker!
AoD plays some Anti-Hacker music!

Greatorder gains heart!

Greatorder questions his beliefs

The hackomaton has been enlightened! Your anti-hacker ranks are swelling!
Logged
99 percent of internet users add useless, pulled out of arse statistics to their sig. If you are the 1%, please, for the love of Armok, don't put any useless shit like this in your sig.
Hidden signature messages are fun!

Angel Of Death

  • Bay Watcher
  • Karl Groucho?
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #37 on: January 06, 2012, 08:19:30 am »

Shit. It happened again. And the only websites up were B12 and Youtube.
Logged
99 percent of internet users add useless, pulled out of arse statistics to their sig. If you are the 1%, please, for the love of Armok, don't put any useless shit like this in your sig.
Hidden signature messages are fun!

Stargrasper

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #38 on: January 06, 2012, 01:43:17 pm »

Virus removal steps:
  • Malware Scan
  • Virus Scan
  • The Same in Safe Mode
  • Muck around with techie tools in Safe Mode
  • System Restore
  • Format & reinstall
Skip #4 if too difficult.

You have done all of these except the last, right?
Logged

bombzero

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #39 on: January 07, 2012, 05:54:43 am »

SO... not that i would EVER suggest anything at all illegal... you could find a friend of your who know how to hack and have him back trace it and shut down whoever it is hacking you...

i would do it but... well i generally dont care about others enough to put my computer at risk.. sorry.
Logged

celebrinborn

  • Bay Watcher
    • View Profile
Re: Need a good virus scanner/antivirus program
« Reply #40 on: January 07, 2012, 06:49:24 pm »

Norton Internet Security 2012 is first.
I refuse to use anything beginning with Norton. The infernal piece of crap that is Norton has caused me so many computer issues before.

Also, Malwarebytes keeps on saying something like "Blocked a potentially malicious [something] (random numbers) from Internet Explorer. I've only got Bay12 up. Could this be something sinister or is it just Malwarebytes dicking up?

[EDIT] Here's the log from the IP blocking

2012/01/04 22:43:34 +1030   ACOMP   A.Dude   IP-BLOCK   91.211.117.70 (Type: outgoing, Port: 54053, Process: iexplore.exe)
2012/01/04 22:51:39 +1030   ACOMP   A.Dude   IP-BLOCK   91.197.128.225 (Type: outgoing, Port: 54328, Process: iexplore.exe)
2012/01/04 22:51:39 +1030   ACOMP   A.Dude   IP-BLOCK   91.197.128.225 (Type: outgoing, Port: 54329, Process: iexplore.exe)
2012/01/04 22:51:39 +1030   ACOMP   A.Dude   IP-BLOCK   91.197.128.225 (Type: outgoing, Port: 54330, Process: iexplore.exe)

Norton broke my last computer and would not allow me to uninstall it. I've had fewer problems with actual viruses than with Norton.
Logged

Stargrasper

  • Bay Watcher
    • View Profile
Re: Need a good virus scanner/antivirus program
« Reply #41 on: January 07, 2012, 07:29:08 pm »

Norton Internet Security 2012 is first.
I refuse to use anything beginning with Norton. The infernal piece of crap that is Norton has caused me so many computer issues before.

Also, Malwarebytes keeps on saying something like "Blocked a potentially malicious [something] (random numbers) from Internet Explorer. I've only got Bay12 up. Could this be something sinister or is it just Malwarebytes dicking up?

[EDIT] Here's the log from the IP blocking

2012/01/04 22:43:34 +1030   ACOMP   A.Dude   IP-BLOCK   91.211.117.70 (Type: outgoing, Port: 54053, Process: iexplore.exe)
2012/01/04 22:51:39 +1030   ACOMP   A.Dude   IP-BLOCK   91.197.128.225 (Type: outgoing, Port: 54328, Process: iexplore.exe)
2012/01/04 22:51:39 +1030   ACOMP   A.Dude   IP-BLOCK   91.197.128.225 (Type: outgoing, Port: 54329, Process: iexplore.exe)
2012/01/04 22:51:39 +1030   ACOMP   A.Dude   IP-BLOCK   91.197.128.225 (Type: outgoing, Port: 54330, Process: iexplore.exe)

Norton broke my last computer and would not allow me to uninstall it. I've had fewer problems with actual viruses than with Norton.

Everyone has problems with Norton.  There's a reason most of us refuse to use it and have a hard time because it comes with practically every Windows computer.  You know, you actually need a special tool to remove Norton.  You can get it from MajorGeeks.  Speaking of which, it probably has tools that would help Angel of Death.  I desperately need to complete another chapter worth of homework before midnight, but when I finish, I'll glance over the site for you.
Logged

eerr

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #42 on: January 07, 2012, 08:08:13 pm »

Norton is heavier than the majority of viruses.
Logged

optimumtact

  • Bay Watcher
  • I even have sheep
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #43 on: January 08, 2012, 01:37:43 am »

Spoiler (click to show/hide)

Is this a "I backtraced it" joke because it's not as easy as your making it out to be.
Logged
alternately, I could just take some LSD or something...

Stargrasper

  • Bay Watcher
    • View Profile
Re: Help! Some Amsterdam dude is hacking me! (previously virus scanner thread)
« Reply #44 on: January 08, 2012, 02:12:25 am »

Spoiler (click to show/hide)

Is this a "I backtraced it" joke because it's not as easy as your making it out to be.

Let him dream.  Personally, I find it funny that people don't understand what crackers can and can't do easily.
Logged
Pages: 1 2 [3] 4 5