PDA

View Full Version : My Yahoo was hacked


BBWMoon
11-07-2005, 02:39 AM
Please delete allie_Catz from your yahoo messenger.
I was hacked this weekend :mad:

Terrible feeling... :( At least Yahoo disabled it for me.


~Allie

Gordo Mejor
11-07-2005, 08:39 AM
Please delete allie_Catz from your yahoo messenger.
I was hacked this weekend :mad:

Terrible feeling... :( At least Yahoo disabled it for me.


~Allie


What alerted you to that? What happened?

eljay
11-07-2005, 01:21 PM
eeek, that does indeed suck!

It is important you find out how it happened if you can - especially if you use your computer for anything "important".

I havn't found any info on exploits for the later versions of yahoo. Best case scenario is that someone has managed to get hold of you Yahoo password... worst case is you have some nasty on your machine which is currently forwarding stuff you type to a norty hacker.

If you have *definitely* been hacked i recommend you disconnect from the net and get some tech-savvy aid (assuming you're not tech savvy yerself!)

Luck!

Totmacher
11-07-2005, 01:54 PM
Run a spyware scan, run a virus scan, change your password, and please get right back on the horse. I like to live in my own little world where everyone can solve all their problems themselves and anyone who thinks otherwise is just being silly. I might be wrong, but in my experience it's eljay's best case scenario.

Les Toil
11-07-2005, 09:30 PM
What happened Aly? I bet they attached porn pop-ups to your site, right? They did that to my pin-up gallery. I was furious.

BBWMoon
11-08-2005, 04:13 AM
Because I use DSL, I'm assuming someone located me. While I was playing a game site that I'm often on, or while I was on yahoo. They sent through an exe file, or viewed the screen I was on, or sent me to a duplicate log on page for yahoo. I'm not certain.
I believe it's called Adtomi, if it is an exe.

I've cleaned, used spyware, and what I block most is Adtomi.
Not certain how I get rid of it.

The perp was able to get into my yahoo and change the password, so it's bad. And now I have 50 cent as my profile pic, and they claim I'm pwned.
Oh well. I'm just upset that they were able to get into my email. But, this means they have my address... jet blue info, etc. So not a good feeling.

Anyone hear of Adtomi? I'm going to google it, next...

~Allie :mad:

fatlane
11-08-2005, 05:15 AM
For everyone on DSL or cable: get a firewall/hub to plug into your router. Linksys makes excellent products in the "cheap" range that keep that shtuff blocked.

Totmacher
11-08-2005, 12:18 PM
A cheap firewall probably wouldn't have helped if the problem was adtomi. Adtomi is a program people usually install themselves when forty trillion popups occur, one or more asks you to install something, and you accidentally hit OK. Then the proggie's downloaded and installed before you know what hit you. I don't recall adtomi having a keylogger or backdoor feature, but it's not altogether unlikely. A software firewall might have noticed something funny when the backdoor program started broadcasting whatever it was set to broadcast, but, last I checked, router firewalls don't recognize that sorta thing. My money's on it being another backdoor program or a duplicate login screen, but I'm not betting too much ;)

eljay
11-08-2005, 01:59 PM
I don't recall adtomi having a keylogger or backdoor feature, but it's not altogether unlikely. ...

... My money's on it being another backdoor program or a duplicate login screen, but I'm not betting too much ;)...

Agreed, i don't think adtomi will have installed a backdoor based upon the description symantec have on their site - they call it simple adware.(however it could be possible that it is an altered/doctored version??)

If someone sent you an exe it is likely you would have had to open it. Can you remember doing so...installing anything?

From what you have described it does sound quite bad. No 1 concern should be - do they have access to any of your other accounts?

I recommend : go to http://www.protect-me.com/freeware.html and download a copy of "active ports". This program will run and tell you what active connections to the internet you have. when its running open up a browser and go to google - see the new connections opening? Now close down everything that connects to the web - msn, etc... Now, is there anything left trying to establish a connection out? If so you might have a trojan on your PC - which would be how they got your passwords etc.

If not, you are safe to log into other accounts and change your passwords. Do so. If you cannot log into anything, especially e-mail then the perp may have changed the password. In which case report it to your ISP to get it changed. (if possible). If you have recently used any internet banking, check your accounts (from another machine) and again, change passwords etc. I am assuming the worst case scenerio here - it might be that they just hacked the yahoo client somehow, but i think you need ot assume the worst until you know otherwise.

If in doubt i would recommend a re-install to be sure.

ON THE PLUS SIDE:

It is not some kind of professional hacker - you have been targetted by a script kiddie who has no idea who you are and probably has little interest.

If you need advice/assistance do not hesitate to ask.

fatlane
11-08-2005, 02:04 PM
Well, I never click on anything... task manager does my process killing...

1300 Class
11-08-2005, 02:17 PM
I find that usually anything involving Yahoo ends up either being spammed to bits or hacked to bits.

fatlane
11-08-2005, 04:53 PM
Which is why I moderate the hell out of my Yahoo image prison. It ain't no group, in the sense of a community...

tankgirl
11-08-2005, 07:13 PM
Yahoo image prison

*cracks up hysterically*

And beware crap like Kazaa or toolbars. Don't use toolbars. Fun, but trashy.

1300 Class
11-09-2005, 01:02 AM
Tacky is more appropriate, however I use Opera, so its nice enough.

fatlane
11-09-2005, 06:43 AM
Kazaa Lite is the way to go, but don't tell the RIAA I said that...

BBWMoon
11-09-2005, 07:04 AM
I've used the cleaner, ad-aware, aol spyware, and avg.
There's no trojons. There was a lot of spyware, but I'm usually good at cleaning that out, and deleting my cookies, etc.

I think something popped up while I was playing my game... I know I was saying no to a lot of exe's around that time. Why I would hit OK, is beyond me.

Or It could still be that I logged into Yahoo on someone's trick duplication page. I'm usually go through my favorite places rather quickly. It could have blindsided me.

----------------------------------------------------
NOW here's the GOOD news:

I decided to go into my add/delete hardware and poke around. I was able to delete my SOUND. How wonderful.
I no longer have sound. I deleted my multimedia sound controller, whatever that was attached to.

GEEZ....

AND my scroll bar is in slow motion. Which, I don't know how to fix.
It's just HEll....

As I scroll down, it duplicates the screen\really freaky like.
I'm wondering if this is part of the hacker's procedure?

Y U C K

~Allie

SoVerySoft
11-09-2005, 11:12 AM
Allie - do you have Windows XP? if so, maybe you can use the roll-back feature to restore your computer to the pre-hacked state.

I don't know much about doing this, tho. Can anyone else help?

BBWMoon
11-09-2005, 02:26 PM
Allie - do you have Windows XP? if so, maybe you can use the roll-back feature to restore your computer to the pre-hacked state.

I don't know much about doing this, tho. Can anyone else help?


Yes, SVS... I have windows XP. I haven't heard of roll-back?

Thanks for your help, guys!

~Allie

BBWMoon
11-09-2005, 02:27 PM
Unfortunately my back is really bad today, so as soon as I get home from work, I'm going to bed.

I won't be online tonight... but thanks for your ideas, I'll look into it on Thursday night.

Thanks again! :)

~Allie

1300 Class
11-09-2005, 03:59 PM
Try "spybot: search and destroy", "adaware", and get "zone alarm" for a whilewall, which stops most stuff.

big_ass_annie
11-09-2005, 04:15 PM
Allie - do you have Windows XP? if so, maybe you can use the roll-back feature to restore your computer to the pre-hacked state.

I don't know much about doing this, tho. Can anyone else help?



Hi there~
Here's how you do it...
Click on START
Then: ALL PROGRAMS
ACCESSORIES
SYSTEM TOOLS
SYSTEM RESTORE
Then follow the steps....
Works great! Good Luck.
annie

SoVerySoft
11-09-2005, 04:17 PM
Yes, SVS... I have windows XP. I haven't heard of roll-back?

Thanks for your help, guys!

~Allie

Allie,

I looked into it and if you go to the start menu, then help and support, what you want is "system restore". You can get it to roll your system back to the day before your problem. I don't think it will change the fact that someone hacked your password, etc, but it will correct any problems that have cropped up on your computer.

eljay
11-09-2005, 04:22 PM
Careful it does not restore any evil nasties also... make sure you go back a whee while...

BBWMoon
11-10-2005, 07:41 AM
Thanks for the information, Everyone!
But it would only allow me to go back to the 8th. The damage and loss of sound, and snail scrollbar happened 6-7th.

I may have to take it to a Comp. Dr.

Oh well, life happens!

~Allie

31mike
11-11-2005, 07:58 PM
Hey Allie

There is a SYSTEM RESTORE function in Win XP go to start...all programs...accessories...system tools...SYSTEM RESTORE

Let me know if that helps...feel better :)