Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Operating Systems » Windows XP/2000
Register for a Free Account

Windows XP/2000 - MSN Hacked - Error 80048823 posted in the Operating Systems forums; Hey Guys, me again. I had a contact on MSN (removed email address), I know its wrong to put his email, but he has hacked me. Well..Frozen me atleast. He ...


Reply
Recommended Driver Scanner
Old 10-01-2006   #1
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default MSN Hacked - Error 80048823

Hey Guys, me again.

I had a contact on MSN (removed email address), I know its wrong to put his email, but he has hacked me. Well..Frozen me atleast.

He asked me to try and sign into MSN, I knew he had done something, and I knew he had great knowledge in computers. I blocked him, and deleted him, and then tried to sign out and in.

I got the following error.



So, I was like "Oh my God", I went to Hotmail.com and attempted to log into my email address, but it said that too many people had tried to sign in. and took me to a screen where I had to put in a image verefication code. I did so, and it said that my account was locked. Because people are accessing it.

I see that I have a program on my email, that mass spams my email login, so I cant login, and freezes my MSN Messenger Account.

I looked on Google, but noone knows what the heck it is..

I really need this email, it has all my schoolwork etc on it. I would really appreciate your help.

----------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 09:35:32, on 01/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\Go ogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ashley\My Documents\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = vGaming - Forum Index
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\Go ogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

---------------------------------------------------------------------
I will repost my Ewido scan as its taking ages.

Last edited by GaRHaR; 10-01-2006 at 09:47 AM.
Slow2die is offline   Reply With Quote
Advertisement - Register to Remove
Old 10-01-2006   #2
Tech Member
 
GaRHaR's Avatar
 
Join Date: Jul 2006
Location: Western Australia
Posts: 6,068
PC Experience: Elite PC Guru
Default

Hi there,
I removed the email address out of the post.

One of the security team will be along shortly to give you a hand.

Until then have you tried to get your password reset?
GaRHaR is offline   Reply With Quote
Old 10-01-2006   #3
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 09:58:19 01/10/2006
+ Scan result:

C:\Program Files\iCodecPack -> Adware.Generic : No action taken.
HKU\S-1-5-21-1547161642-1592454029-839522115-1004\Software\Internet Security -> Adware.IntCodec : No action taken.
C:\Program Files\Multi Theft Auto\MTAClient.exe -> Heuristic.Win32.Morphine-Crypted : No action taken.

::Report end
Slow2die is offline   Reply With Quote
Old 10-01-2006   #4
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

Originally Posted by GaRHaR
Hi there,
I removed the email address out of the post.

One of the security team will be along shortly to give you a hand.

Until then have you tried to get your password reset?
It doesnt let you. You can't access anything near your email.
Slow2die is offline   Reply With Quote
Old 10-01-2006   #5
Tech Member
 
GaRHaR's Avatar
 
Join Date: Jul 2006
Location: Western Australia
Posts: 6,068
PC Experience: Elite PC Guru
Default

I don't think there's any way this person could block you out of your email without actually getting access to it and changing the password.

Unless they were a Microsoft employee who had access to the users database, and reset your password to something simple.

I could be wrong...as i said, we'll have to wait for the security team to get here.
GaRHaR is offline   Reply With Quote
Old 10-01-2006   #6
Tech Member
 
GaRHaR's Avatar
 
Join Date: Jul 2006
Location: Western Australia
Posts: 6,068
PC Experience: Elite PC Guru
Default

Been checking on google...alot of people have had this issue so it doesn't seem to be "hacked" related.

Have you tried all their suggestions?

Originally Posted by Other sites
1. The date on your computer needs to be set properly -- double click the clock verify that

the time and date are set.


2. If your password information is not saved, verify that you are typing it in with the

correct case (uppercase or lowercase).

3. Change your password @ https://login.passport.com/ChangePW.srf to

something smaller (under 10-12 characters), then try signing in again.

4. If you use a firewall (like ZoneAlarm, Norton Internet Security etc. ), it's possible

that Messenger doesn't have the correct rights to access the Internet, especially since you

upgraded. You may need to re/add Messenger to the allowed list of programs in your firewall

if this is the case.

5. If you disabled your firewall in the past, it still may be blocking Messenger -- try

restarting it and see if that helps the situation. You also might try uninstalling an

installed firewall, to verify that it isn't causing a problem (even if it is disabled).

6. Clear your IE cache and cookies -- open Internet Explorer, click the Tools menu, then

Internet Options, then click the Delete Files button, and when that's complete click the

Delete Cookies button.

7. Check your IE Security settings -- open Internet Explorer, click the Tools menu, then

Internet Options, then Advanced tab, scroll to the Security section, and verify that "Check

for server certificate revocation" is unchecked. Also verify that 'Use SSL 2.0' and Use SSL

3.0' is checked, then click OK.

8. Click Start, then Run, and enter the following:

regsvr32 softpub.dll

then click OK

and do the same for the following:

regsvr32 wintrust.dll

regsvr32 initpki.dll

regsvr32 MSXML3.dll
GaRHaR is offline   Reply With Quote
Old 10-01-2006   #7
Bronze Member
 
Join Date: Aug 2006
Posts: 79
Default

Yes, done all that.
Slow2die is offline   Reply With Quote

Reply


Bookmarks

Tags
error, hacked, msn

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 08:32 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2