Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

ghost's Avatar
0 0

I think some1 broke into my system because some1 changed my administrator right to no right at all. Cant acces Taskmanager and configuration options.

Could some1 help me get rid of him and give me back my admin right :S This ain't fun anymore.

Also it could be a program because my bro is into downloading alot


ghost's Avatar
0 0

well, do you think someone did it remotely or locally?


ghost's Avatar
0 0

remotely


spyware's Avatar
Banned
0 0

Are you a hacker or what? Hack back :D.

It's one of the oldest tricks in the book, getting admin rights on a Windows box. One google search and you have the information you need.

Ready, set, HACK!


ghost's Avatar
0 0

ain't that good of a hacker really , only know basic web hacking. Just learning about the common exploits some application have like buffer overflows and string formatting and stuff so i don't think il have the power to hack back although i would certanly do it if i could.


SET's Avatar

SET

Peumonoultramicroscopicsilico
0 0

Thats what i am talking about such vague information. one search on the google is all it takes. LOL do u think he knows what he is even looking for on google. be more helpful.


ghost's Avatar
0 0

If some1 is connected to my box could i see it on netstat ? or could they bypass that?


ghost's Avatar
0 0

Run a scan for trojans/virii and disconnect from the internet.

While offline, make sure your firewall blocks everything but the essentials from entering your computer (this INCLUDES ICMP (ping) requests).

Make sure no built-in accounts are running (Administrator, Guest, etc).

Recover your password locally using any of the various windows privilege escalation thingers people are always going on about.

And for fucks sake, tell your brother to take his shit off of your computer.


ghost's Avatar
0 0

should i be blocking port 80 too ?


ghost's Avatar
0 0

Well said lesserlightsofheaven.


ghost's Avatar
0 0

vytas wrote: should i be blocking port 80 too ?

unless you're running an HTTP server or something on that port, then yes, why not. make sure to just block INCOMING requests, though.

there's a great tool online called "nmapyourself". I forget where its hosted, but I'm sure you can find it with a few quick searches. you can use that to see what an intruder might see as he tries to assess your system.

if you block incoming ICMP pings, whether from within the firewall or the router (forgot to mention that, also check your router password strength and settings) then nmap is useless without the -P0 option. even with that, you should ideally be showing no ports or services on a scan.


ghost's Avatar
0 0

Well ok cya


ghost's Avatar
0 0

lesserlightsofheaven wrote: Run a scan for trojans/virii and disconnect from the internet.

While offline, make sure your firewall blocks everything but the essentials from entering your computer (this INCLUDES ICMP (ping) requests).

Make sure no built-in accounts are running (Administrator, Guest, etc).

In other words… read my article. B)


ghost's Avatar
0 0

Zephyr_Pure wrote: In other words… read my article. B)

True that. ;)


ghost's Avatar
0 0

Ophcrack?


ghost's Avatar
0 0

Folk Theory wrote: Ophcrack?

LOphtcrack?


ghost's Avatar
0 0

I've got a real pain in the ass trojan :S Ok i have no administrator rights on this computer right now. I had another acount wich still had administrator rights with a password. So i went to that acount wanted to change the rights of the other user but it said that it already had administrator right :o I logged in at this user again and wanted to login at the other acount with the password only it's changed.

What do i do know format my hard disk ? I terminated all procecces exept the ones needed to run windows. Or could some1 remote assist or hack my computer and change the rights back if you want that training please P.M. me for details.


ghost's Avatar
0 0

Run SUPERAntiSpyware Run Nod32 Suggest scanning your windir first, and maybe through safe mode, without internet. Many trojans will re-download components of themselves if parts have been removed.

Without specifics, it's hard to tell you what to do, but yes, zephyr's article is a great one, and listen to lesser and fritz. They know what they're talking about.


ghost's Avatar
0 0

you just need access? OPH it.


ghost's Avatar
0 0

if you dont have any admin access can you at least access the cmd prompt? if so do the system glitch open taskmanager type at xx:xx /interactive "cmd.exe" xx:xx bieng the time 1 minute after you type this cmd then close out the cmd box immediately after you type it and see job 1 added or similar

then end explorer.exe in the taskmgr wait 1 minute and a command prompt will pop up then type explorer.exe you should now see some system config options bieng done. wait till they finish and viola system access. now you can uninstall add admin accounts etc in a flash. then try removal techniques on that trojan

EDIT SORRY did not see task manager block well i guess then this wont work :/ but if you do somehow access it try it :/ sorry.