Adblock breaks this site

The fuck is this?

Discussion in 'RuneScape 3 General' started by Royal Noobi, Mar 31, 2011.

  1. Royal Noobi

    Royal Noobi Forum Addict
    Banned

    Joined:
    Dec 13, 2010
    Posts:
    297
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    Has anyone had this fag log onto their account? i've been getting hacked alot lately, and it's starting to piss me off.

    [​IMG]

    Why am i being hacked? have i got a keylogger?
    I changed my passord 2 days ago so why.

    I will update the thread with hackers' ip adresses if i get hacked again

    i did a virus scan and it picked nothing up.

    AHA! so this is the fuck that has been plaguing my computer! He hacked into like 4 of my accounts! Anyone who lives near this guy put a brick in his window and rape him!

    [​IMG]
     
  2. blazee

    blazee Guru
    Mudkips

    Joined:
    Mar 28, 2011
    Posts:
    1,791
    Referrals:
    0
    Sythe Gold:
    8
    Pokémon Trainer
    The fuck is this?

    pm a global to run a IP check with sythe users.
     
  3. Royal Noobi

    Royal Noobi Forum Addict
    Banned

    Joined:
    Dec 13, 2010
    Posts:
    297
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    I've been hacked by several people. I will trace Every sngle IP that hacks me tho
     
  4. PlayerOne

    PlayerOne Apprentice

    Joined:
    Mar 24, 2011
    Posts:
    783
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    Get a global mod to cOmpare a screenshot of their IP to a sythe user.

    Download avira antivirus premium. You can get it for 30 day trial. Then scan your computer

    Download malwarebytes anti malware. Clean your computer.


    You have multiple keyloggers. They work by matching your key strokes.. so becareful now.
     
  5. ShockWaveee

    ShockWaveee Apprentice
    Banned

    Joined:
    Nov 29, 2009
    Posts:
    869
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    Most likely have a keylogger/RAT that is FUD. The only way to be 100% sure you've removed it is to reformat, unfortunately.
     
  6. blazinfasstt

    blazinfasstt Guru

    Joined:
    Feb 5, 2011
    Posts:
    1,132
    Referrals:
    0
    Sythe Gold:
    0
    Discord Unique ID:
    143831236278747136
    Discord Username:
    blazinfasstt
    The fuck is this?

    run malwarebytes to pick up any keyloggers you may have
     
  7. Tyrant Bonaparte

    Tyrant Bonaparte Apprentice
    Banned

    Joined:
    Jan 25, 2007
    Posts:
    849
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    U probably just change the pass without realiizing u still have the keylogger
     
  8. malakadang

    malakadang Hero
    malakadang Donor Retired Global Moderator

    Joined:
    Jan 1, 2011
    Posts:
    5,679
    Referrals:
    0
    Sythe Gold:
    900
    Discord Unique ID:
    220842789083152384
    Discord Username:
    malakadang#3473
    Two Factor Authentication User Easter 2013 Doge Community Participant
    The fuck is this?

    IP traces to Long Jetty - Australia; near Sydney.

    Do you live near there, know anyone living near there?

    If not, then most likely you have a keylogger/virus/been phished.
    Do what the above have said, run Malwarebytes etc.
     
  9. Royal Noobi

    Royal Noobi Forum Addict
    Banned

    Joined:
    Dec 13, 2010
    Posts:
    297
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    I live in melbourne, but fuck it, wiping my computer IDC What the fuck happend, and How the fuck it happened, but i am gonna wipe my comp.

    Fucking hackers, lost my 35M bank and void to them

    Logged off my runescape accounts and im gonan change all my passwords
     
  10. O_R_L_Y

    O_R_L_Y Sniper No Sniping!
    Banned

    Joined:
    Aug 6, 2008
    Posts:
    1,283
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    bank PINs go a long way :O change your passwords with an onscreen keyboard and login with them aswell.
     
  11. Royal Noobi

    Royal Noobi Forum Addict
    Banned

    Joined:
    Dec 13, 2010
    Posts:
    297
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    Changed all my passwords and crap on another computer, hopefully that will have me safe.
     
  12. Wake n Bake

    Wake n Bake Apprentice
    Banned

    Joined:
    Feb 12, 2011
    Posts:
    862
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    You probably keep getting drive-by'd.
    Or its the same hacker and their changing their IP or putting a proxy.
     
  13. Wake n Bake

    Wake n Bake Apprentice
    Banned

    Joined:
    Feb 12, 2011
    Posts:
    862
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    Also, that does nothing. Because if you still log in on that account on the infected computer it will still send the logs to him/her.
     
  14. Li

    Li Active Member

    Joined:
    Apr 21, 2005
    Posts:
    135
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    Use an onscreen keyboard. Also, there are keyloggers that are fully undetectable so you might want to back up some data and then wipe you hard drive and start over fresh.
     
  15. Fu S E

    Fu S E Apprentice
    Banned

    Joined:
    Oct 25, 2009
    Posts:
    629
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    On screen keyboard, back up data, wipe hard drive, repeat.
     
  16. Royal Noobi

    Royal Noobi Forum Addict
    Banned

    Joined:
    Dec 13, 2010
    Posts:
    297
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    Very constructive comment. I'm sure that will help me be rid of my keylogger. Stupid noobs with a March 2011 join date.

    Anyway, for those why are willing to help, i got a logfile of my system processes, is it clean?

    Running processes:
    C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Windows\vVX1000.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\BitTorrent\BitTorrent.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
    C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
    C:\Users\Noob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JavaLoad.exe
    C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
    C:\Users\Noob\AppData\Roaming\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\taskeng.exe
    C:\Users\Noob\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: HyperCam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
    O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
    O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Windows Installer] C:\Users\Noob\AppData\Roaming\Microsoft\Security\scvhost.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [] C:\Windows\system32\scvhost.exe
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -update plugin
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - Startup: JavaLoad.exe
    O4 - Startup: jupdate.jar
    O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
    O4 - Startup: winlogin.exe
    O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
    O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
    O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
     
  17. Royal Noobi

    Royal Noobi Forum Addict
    Banned

    Joined:
    Dec 13, 2010
    Posts:
    297
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    Bump as i found another hacker.

    [​IMG]
     
  18. Seanly

    Seanly Guru
    Banned

    Joined:
    Nov 9, 2008
    Posts:
    1,073
    Referrals:
    1
    Sythe Gold:
    0
    The fuck is this?

    This has to be my personal favorite part.

    You highlighted the fact that you have changed your password a few times, and continue to be hacked.
    You are probably infected by a RAT/FuD keylogger - Meaning, it is undetectable.
    You may need to re-format your pc.
     
  19. HappyFace01010

    HappyFace01010 <--- Tis a Happy Face
    Banned

    Joined:
    Aug 27, 2010
    Posts:
    659
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    That's where the ISP datacenter routes though. As for the keylogger, run malwarebytes like I said in your last topic and look in C:\Users\*YOUR USERNAME*\AppData\Roaming and C:\Users\*YOUR USERNAME*\AppData\Local

    Delete any dodgy looking files such as if you find something like log.dat or almost any .dat file.

    Lastly, go and open MSCONFIG chose the startup tab and disable any dodgy looking programs and restart your computer.

    Also, go to http://formyip.com and make sure it isn't your IP that you are posting.

    Good Luck!
     
  20. PlayerOne

    PlayerOne Apprentice

    Joined:
    Mar 24, 2011
    Posts:
    783
    Referrals:
    0
    Sythe Gold:
    0
    The fuck is this?

    I beleive some dodgy chinese kid behind a computer in Australia is constantly raping you. He has Optus Internet if you havent realised. You can try calling them and asking for the owner of that IP addresses information but i highly doubt it.

    I suggest. You reformat your computer immediately. Fuck all your files, back them up now on a portable hdd then do a reformat. screw rs for a week. one week isnt long. you gotta get rid of that shit.
     
< What to do with this? | check in/need help/hacker hacked to my comp screen >


 
 
Adblock breaks this site