Board hacked again

If you don't read these, it's your own fault. They will be enforced by the staff. You will also find Management Announcements & S2K Gatherings here

Moderator: S2k Moderators

Message
Author
bsidella
Tropical Wave
Tropical Wave
Posts: 6
Joined: Tue Aug 31, 2004 3:30 pm

Scumbag who did this needs the tar kicked out of them

#21 Postby bsidella » Wed Mar 02, 2005 11:59 am

I downloaded this POS as well. Can't print or turnoff/restart from the keyboard. If anyone has a fix please post. I don't have 8 hours to spare to reinstall my OS and all the files and programs.
0 likes   

User avatar
Windspeed
Tropical Storm
Tropical Storm
Posts: 129
Joined: Thu Jun 10, 2004 11:38 am

#22 Postby Windspeed » Wed Mar 02, 2005 12:01 pm

msbee: you need at least one csrss checked in your msconfic "start up." it is a run-time program that handles interface commands in your screens/windows. if you have multple csrss files, just deactivate any after the first one down the start up list.

also, you can't run netstat from "run" in your start menu. you must run a dos command prompt. click on applications, then select "command prompt" if you are using 2000 or xp.

if the only thing you're using right now is your broswer and yet you have a "Established" foreign connection through port 6667, that is a botnet and you are still being hacked. whoever did this knew what they were doing. i believe that is why they used this specific worm and also it's connection to the system registry and csrss start up files. that's a route for a port hack if someone is doing it through a bot net.

anyone else experiencing the same problems? i'm trying to back up files right now. i could not find a working solution because could not restore. my system is messed up but i'm still able to backup what i had not mirrored in the last six months. then i'm going to do those magical words "format" and "reinstall."
0 likes   

User avatar
msbee
S2K Supporter
S2K Supporter
Posts: 3010
Joined: Wed Jun 11, 2003 10:11 am
Location: St. Maarten

#23 Postby msbee » Wed Mar 02, 2005 1:36 pm

Hi'windspeed
I am running XP.
I clicked on accesories and saw command prompt there.
I clicked on that and the black box came up, all that it shows is:
c:\documents and settings\my name
I didn't see anything that said netstat
so does that mean I am ok?
by the wya, this topic is running over in hurricane hollow forum too and someone there said she can't print. I just tried to print and I couldn't either..'I thoguht I was ok..maybe I'm not..
what a mess!!!!!!!!
0 likes   
Too many hurricanes to remember

User avatar
NWIASpotter
Category 5
Category 5
Posts: 1961
Joined: Sun Jul 18, 2004 12:58 pm
Location: Terril, Iowa & Ames, Iowa
Contact:

#24 Postby NWIASpotter » Wed Mar 02, 2005 4:07 pm

Storm2k wasn't the only weather site hacked... It just happened again on the main weather board I'm apart of!!! :grr: :eek:
0 likes   

User avatar
therock1811
Category 5
Category 5
Posts: 5163
Age: 38
Joined: Thu May 15, 2003 2:15 pm
Location: Kentucky
Contact:

#25 Postby therock1811 » Wed Mar 02, 2005 5:35 pm

Son of a gun! I'll be darned!
0 likes   

User avatar
Skywatch_NC
Category 5
Category 5
Posts: 10949
Joined: Wed Feb 05, 2003 9:31 pm
Location: Raleigh, NC
Contact:

#26 Postby Skywatch_NC » Wed Mar 02, 2005 9:44 pm

NWIASpotter wrote:Storm2k wasn't the only weather site hacked... It just happened again on the main weather board I'm apart of!!! :grr: :eek:


The a-hole doing these hackings is truly a WHACKO!!! :grr: :grr:
0 likes   

User avatar
mf_dolphin
Category 5
Category 5
Posts: 17761
Age: 67
Joined: Tue Oct 08, 2002 2:05 pm
Location: St Petersburg, FL
Contact:

#27 Postby mf_dolphin » Wed Mar 02, 2005 10:46 pm

We found these instructions but I can't guarantee they will work. This is fairly involved but hopefully it will help some of you.

We have a serious problem. We were hacked. If you have downloaded the file PLUGIN_INSTALL.EXE that was a fake patch to your computer you must delete it asap. DO NOT INSTALL. If you have please follow the instructions below to remove it. I make no claims that this will help you or that you won't screw your computer up. This is what I did and it worked for me. Print or copy this immediately!!!!! Read all instructions BEFORE attempting. Make sure you understand them,

1. Remove your computer from the web. You should just unplug the network cable.

2. If you have system restore on...you must shut if off immediately.

3. Shut down your computer. You can ctr-alt-del and go to USERS. From there you can choose to logoff..then shutdown.

4. Reboot your computer and hold the F8 key. This will bring up a boot menu option from windows.

5. Choose SAFE MODE.

6. Search your computer for a file named sp2patch.exe

7. Go into c:/windows/system32/ and delete the folder (remember the folder name please) that sp2patch.exe was inside.

8. Go to the start button and click RUN.

9. Run REGEDIT

NOTE: Please be very careful here.
10. Do a search in regedit for the key,value, and date for CSRSS.EXE (note:this is a clone of a real windows component) Delete anything found with that key where the directory is from the folder in step 7.

11. Do a search for sp2patch.exe in regedit as well. DELETE any entries found.

12. Reboot into normal windows mode.

13. If you reboot and do not get any errors then you may have been successful. If you ctr-alt-del you can see the system processes. If you see only 1 csrss.exe then you have it.

14. Shut down, attach your network cable again and reboot.
0 likes   

User avatar
NWIASpotter
Category 5
Category 5
Posts: 1961
Joined: Sun Jul 18, 2004 12:58 pm
Location: Terril, Iowa & Ames, Iowa
Contact:

#28 Postby NWIASpotter » Thu Mar 03, 2005 10:05 am

Skywatch_NC wrote:
NWIASpotter wrote:Storm2k wasn't the only weather site hacked... It just happened again on the main weather board I'm apart of!!! :grr: :eek:


The a-hole doing these hackings is truly a WHACKO!!! :grr: :grr:


Yes, Eric he is... or maybe it is them... Whatever, I'm dissapointed!!!
0 likes   

bsidella
Tropical Wave
Tropical Wave
Posts: 6
Joined: Tue Aug 31, 2004 3:30 pm

tried the fix

#29 Postby bsidella » Thu Mar 03, 2005 1:16 pm

I tried the fix. It appeared to work however I still cannot print. Any suggestions???
0 likes   

User avatar
chadtm80
Category 5
Category 5
Posts: 20381
Age: 43
Joined: Tue Oct 08, 2002 8:35 am
Location: East Central Florida
Contact:

Re: tried the fix

#30 Postby chadtm80 » Thu Mar 03, 2005 2:12 pm

bsidella wrote:I tried the fix. It appeared to work however I still cannot print. Any suggestions???

what happens when you try and print?
0 likes   

User avatar
Lindaloo
Category 5
Category 5
Posts: 22659
Joined: Sat Mar 29, 2003 10:06 am
Location: Pascagoula, MS

#31 Postby Lindaloo » Thu Mar 03, 2005 2:51 pm

Have you tried reinstalling your printer software?
0 likes   

bsidella
Tropical Wave
Tropical Wave
Posts: 6
Joined: Tue Aug 31, 2004 3:30 pm

Cannot print

#32 Postby bsidella » Thu Mar 03, 2005 3:08 pm

I've tried 3 times to reinstall the drivers but nothing. When I go to print it just hangs up and then says unable to print. I'm printing remotely to my main pc in my house off of a laptop. Does anyone have any ideas?
0 likes   

User avatar
Windspeed
Tropical Storm
Tropical Storm
Posts: 129
Joined: Thu Jun 10, 2004 11:38 am

Unfortunately, I had to do a format and reinstall...

#33 Postby Windspeed » Fri Mar 04, 2005 3:57 am

I just had too much stuff messed up, too much file corruption I couldn't entirely locate and clean up, so it just kept breaking stuff on reboot. I also couldn't successfully restore. So I had to choose the last and final option. Start from scratch. But it is nice to have piece of mind. I finally have everything back to pre-chaos. Lessons learned. It doesn't matter how great your firewall or your anti-virus protection is if you almost obliviously download an .exe file of which you are unfamiliar. Sometimes paranoia is a good thing. :roll:

msbee:

I clicked on accesories and saw command prompt there.
I clicked on that and the black box came up, all that it shows is:
c:\documents and settings\my name
I didn't see anything that said netstat
so does that mean I am ok?


Actually, you access the command prompt just as you did there. However, you actually have to _type_ in the command. Command prompt is a prompt line for text functions, like dos, linux, etc. Netstat is a program you can only run in command prompt. So you must type netstat at the command prompt line. That will allow you to see what foreign connections are in your computer. Now keep in mind, you're obviously going to see "good" foreign connections (or you wouldn't be on this webpage, or online, etc.); however, if you see anything attached to port: 6667, that may still be this hack that occurred in association with the .exe file that folks unfortunately downloaded from this page. Folks like me. :roll:

Anyway, I am all clean. I was able to backup all my personal stuff. Actually, now that I have everything back to normal, I don't mind having done this reinstall. There's just something nice about a fresh windows install. (Stuff hasn't had enough time to start screwing up on its own yet! :lol: ) But my firewall and anti-abuse software is up to date and working. So I should be good to go for a while, unless I pull another brainfart and download an erroneous .exe file from an unauthorized source. :grr:
0 likes   

User avatar
george_r_1961
S2K Supporter
S2K Supporter
Posts: 3171
Age: 62
Joined: Sat Oct 12, 2002 9:14 pm
Location: Hampton, Virginia

#34 Postby george_r_1961 » Fri Mar 04, 2005 6:42 am

Marshall I had to go thru a similar process with my laptop when it got infected by a trojan and starting send out obscene IM's on MSN messenger. Make one mistake in the registry your computer gets transformed instantly into an oversized paperweight. Yes I found that out the hard way lol
0 likes   


Return to “Storm2K Rules & Announcements”

Who is online

Users browsing this forum: No registered users and 49 guests