Results 1 to 3 of 3

Thread: Have i been hijacked or Hacked?

  1. #1
    Senior Member wannabgeek's Avatar
    Join Date
    Jan 2005
    Location
    Essex
    Posts
    723
    Thanks
    8
    Thanked
    1 time in 1 post
    • wannabgeek's system
      • Motherboard:
      • Asus M4A89GTD-Pro-USB3
      • CPU:
      • AMD x6 1055T Phenom @3.3ghz with Hyper 212+ HSF
      • Memory:
      • 4GB Corsair XMS3 (2x2GB) since upgraded to Corsair DD3 XMS3 8gb (2x 4gb) CMX8GX3M2A1600C9
      • Storage:
      • OCZ 120GB SSD / 250GB Samsung Spinpoint Sata H / 200GB Maxtor
      • Graphics card(s):
      • Powercolor HD 6850 1GB GDDR5
      • PSU:
      • Tx 650w Corsair PSU
      • Case:
      • Lancool K62
      • Operating System:
      • Windows 7 64 Ultimate (the cheapest)
      • Monitor(s):
      • Dell 19"
      • Internet:
      • Firefox & 20MB Sky max

    Have i been hijacked or Hacked?

    Hi i seem to be having some probs with Security issues, i hope you can help me as i am very worried !
    Today i did a adaware scan and it brought up 2 critical 'reg data windows software polices etc' which is really strange as i never get any criticals on any of my Security progs which are:Adaware,Spybot,Microsoft Antispy,spyblaster,cwsshredder,a-squared,ccleaner and of course i have a firewall (Kerio free) and a AV(norton) which are all regulary updated ! Any way when i found the 2 Criticals i Quaratined tham and ran all the Appliances and then cleaned up all old webpages,cookies,tracks etc with CCleaner SnD. But now when i tried to access my Bank home page nothing happens or another example is i tried to access my Catalogue website and got taken to another page! But what is really worrying is i looked into my trusted sites (where i keep the https secure urls) and my paypal address was changed to this: 'https://*.paypal.com ' ! By the way i use Firefox as my default Browser and also still use ie! Thanks for your help on this matter !
    If this IS Dodgy i may go back to ie as i never had no probs for years using that !
    PS i forgot to mention in spybot/ignore products i unticked 3 boxes: Newnet/Sidestep & mysearch i think they were in the PUPS section! Would that be the cause?
    Ps I have done a HT log if you want i can post it!
    Windows 7 64 Ultimate
    AMD x6 1055T Phenom @3.3ghz
    Asus M4A89GTD-Pro-USB3
    HD 6850 1GB GDDR5
    4GB Corsair XMS3 (2x2GB)
    Tx 650w Corsair PSU
    250GB Samsung Spinpoint Sata HD
    200GB Maxtor Dmax10 IDE
    LG Sata2 DVD/RW
    Lancool K62 Case

  2. #2
    Senior Member
    Join Date
    Aug 2004
    Location
    W Yorkshire
    Posts
    5,668
    Thanks
    85
    Thanked
    13 times in 11 posts
    First off, go to http://housecall.trendmicro.com in Internet Explorer and do a full virus scan, it will check for spyware etc too.

    Check your hosts file, located at:
    C:\WINDOWS\system32\drivers\etc

    its just called "hosts" no extension, open it in notepad. It should look like this:
    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost
    If not, just copy mine and replace it, then try again.

    (Oh and about the PayPal thing, it should be ok since HTTPS is secure, and it was on the paypal website)

  3. #3
    Senior Member wannabgeek's Avatar
    Join Date
    Jan 2005
    Location
    Essex
    Posts
    723
    Thanks
    8
    Thanked
    1 time in 1 post
    • wannabgeek's system
      • Motherboard:
      • Asus M4A89GTD-Pro-USB3
      • CPU:
      • AMD x6 1055T Phenom @3.3ghz with Hyper 212+ HSF
      • Memory:
      • 4GB Corsair XMS3 (2x2GB) since upgraded to Corsair DD3 XMS3 8gb (2x 4gb) CMX8GX3M2A1600C9
      • Storage:
      • OCZ 120GB SSD / 250GB Samsung Spinpoint Sata H / 200GB Maxtor
      • Graphics card(s):
      • Powercolor HD 6850 1GB GDDR5
      • PSU:
      • Tx 650w Corsair PSU
      • Case:
      • Lancool K62
      • Operating System:
      • Windows 7 64 Ultimate (the cheapest)
      • Monitor(s):
      • Dell 19"
      • Internet:
      • Firefox & 20MB Sky max
    Hi Thanks for your help! Sorry i didnt post sooner!

    I did just that with nothing found,but i also ran a2 and it found 2 Riskware errors :
    1/ C:\Program Files\Creative\SBAudigy2\Program\WDM\COMMON\killapps.exe RiskWare.Tool.KillApp.c "Would this be caused because i recently disabled 'CT HELPER' with Spybot"!

    2/C:\WINDOWS\system32\KILLAPPS.EXE RiskWare.Tool.KillApp.c

    I have removed them but do i need to instal another Audigy Driver? Although the sounds still sound fine and are in 5-1 mode!

    Also Antispy is coming up with 3 Activex errors:

    1/ Internet Explorer ActiveX Program OSInfo ActiveX Control Module by hiChannel has been denied permission to be installed. "I think this one is a Mobo prog i used in the past"
    2/ {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}
    This is an unknown ActiveX " Not sure of this!

    Appreciate your help!
    Windows 7 64 Ultimate
    AMD x6 1055T Phenom @3.3ghz
    Asus M4A89GTD-Pro-USB3
    HD 6850 1GB GDDR5
    4GB Corsair XMS3 (2x2GB)
    Tx 650w Corsair PSU
    250GB Samsung Spinpoint Sata HD
    200GB Maxtor Dmax10 IDE
    LG Sata2 DVD/RW
    Lancool K62 Case

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Did my router get hijacked?
    By speedy_s in forum PC Hardware and Components
    Replies: 13
    Last Post: 14-04-2005, 07:08 PM
  2. Aztech PCI 168 XP driver? or hacked to XP driver?
    By |{££|" in forum PC Hardware and Components
    Replies: 6
    Last Post: 10-01-2005, 12:27 PM
  3. help, i've been hijacked
    By starside in forum Software
    Replies: 4
    Last Post: 15-07-2004, 12:57 AM
  4. Reclaim a Hijacked IP address?
    By turkster in forum Networking and Broadband
    Replies: 6
    Last Post: 18-04-2004, 08:26 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •