I think someone is access my computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by JamesDean, Dec 4, 2009.

  1. JamesDean

    JamesDean Private E-2

    It started when I was downloading a movie...(I know). My bandwidth dropped to 0 and the computer froze up. After I restarted it my desktop had gone grey and I couldn't access the windows malware remover tool, and antivirus was shut down, even windows defender. (still cant run MRT) When I tried to open it says "windows cannot access the specified device, path, or file. You may not have the appropriate permissions. I am logged in as the Administrator. There has been a bunch of changes to my system as well, files refering to windowsNT that i dont recall being there before. I am not on any network, but it appears as though one has been setup on my computer from a remote computer. I checked the log for my router and several times the ports have been scanned. I have tried countless websites and scans, all claiming to have found and removed various viruses, but was never actually fixed. I went through your "Do this First" list as specified and now the grey background has returned to normal (thank you so much) but I still believe I am part of this unknown network. When I run Bit Comet my IP address comes up as someone elses, with impossibly tight security. Says no ports are open on my machine but that is impossible. I am being redirected through this other computer I think. I am attatching the requested logs, any help would be greatly appreciated. James
     

    Attached Files:

  2. JamesDean

    JamesDean Private E-2

    Here are the other requested logs. Sorry I added the wrong one on the last post
     

    Attached Files:

  3. JamesDean

    JamesDean Private E-2

    there are also a number of other programs on my system that i dont remember seeing before, one was a tool box with an upload software, I removed this. There is also visualC++ and openoffice.org installer version1, (should these be here?).
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the requested log from SUPERAntispyware and then do the below while I look thru your other logs.

    • Please save Win32kDiag file to your desktop.
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    "%userprofile%\desktop\win32kdiag.exe" -f -r

    You also need to put ComboFix.exe on your Desktop as instructed. You have it as below:
    c:\documents and settings\Amanda Lunn\My Documents\ComboFix.exe
     
  5. JamesDean

    JamesDean Private E-2

    I havve re downloaded Combo fix to the desktop, and attached the 32log you asked for. I am not sure where to find the SAS log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can find it here:
    Code:
    "C:\Documents and Settings\Amanda Lunn\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Dec  4 2009         571  "SUPERAntiSpyware Scan Log - 12-04-2009 - 11-09-24.log"
    
    The main part of your infection appears to have been removed.

    What are the below folders for?
    Code:
    2009-11-21 03:35 . 2009-11-21 03:35 -------- d-----w- C:\sadt10
    2009-11-21 03:26 . 2009-11-21 05:54 -------- d-----w- C:\stdtsa
    You appear to be using several programs to control startup services and processes. You have many things trapped in MSconfig registryt keys including left overs from McAfee which I assume you have uninstall since it does not show in your logs as being installed anymore. We will fix some of these registry enties.

    But first you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. JamesDean

    JamesDean Private E-2

    I have no idea what those folders are that you asked about. I am not aware of any programs using the start-up either. I have uninstalled McAfee about a month ago when all the trouble started, I figured it wasn't working anyway or I wouldn't have this trouble. For the lst while I was using it, it had always told me my computer wasnt protected and to click the button to repair. Well I clicked the button but it still told me the same thing, so I uninstalled it.
    I copied and ran the registry files you told me to. When I double clicked the file it said it was successful. Thank you so much for helping me thus far, I have been trying everything I could for the last 3 weeks or so to try and figure this out, but have been failing miserably thus far. After I send this to you I am going to reboot the machine so I can let you know what happens next time we speak. Thanks again!
     

    Attached Files:

  8. JamesDean

    JamesDean Private E-2

    Hi, when I rebooted the machine I was able to run the windows malicious software remover tool. Thank you! But the grey screen that use to cover my desktop is still here, but now it is behind the desktop. Someone has set up a network and is still accessing my machine. When I go to Bit Comet my router is blocked and the IP address is incorrect. I have tried a number of online scans to try and determine which port they are using but all the scans are indicating that I have an unusually secure system with no open ports. I must have some open ports or I wouldn't be able to access the internet (right?). My bandwidth also drops to zero but the router lights are flashing like crazy. Also the icon in the bottom left corner of the computer has disapeared. The IP address that is appearing on my bit comet is 68.232.76.51 this is definitely not mine but is accessing and routing everything through this address.
     
  9. JamesDean

    JamesDean Private E-2

    My bandwidth keeps dropping to zero and I lose internet, yet the lights on the modem are still flashing. I have to unplug the modem and router and restart them again. Then it is ok for awhile, then it happens again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure what you mean, but my question was about using programs to control which startups are allow to run. Not a program using startups. It looks like you are using a few like Windows Defender, Spybot and perhaps others. Are you sure that you are not doing this? Your logs show that you have disabled quite a few startup entries.

    Well it is not gone completely since at some point in time, you disabled it with MSconfig and then uninstalled it while it was still in MSconfig. One of many reasons not to use MSconfig for a startup manager.


    Not according to the logs you attached; however, it does not look like you properly ran C:\MGtools\GetLogs.bat to get a new log file. The dates of the files in MGlogs.zip are from Dec 2 and Dec 5 which predates my fix on Dec 6th. Please do the below. Make sure you allow GetLogs.bat to finish running!!!!! DO NOT close the command prompt window until it tells you it is finished.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. JamesDean

    JamesDean Private E-2

    Hi Chaslang, Thanks again for your attention to this. I once again ran the MGtools log you asked me to. I forgot to tell you the last time I ran it the same thing happened this time...After the program says "zipping HiJack this log" I get an error message saying "ProcessDll.exe-Application Error The application failed to initialize properly (0xc0000135) click ok to terminate application....Last time I clicked it right away, this time I waited until the machine stopped chattering (about 25 minutes later) the whole time the pointer would flash every now and then with the little hour glass symbol.

    When I start my machine up it appears to be starting correctly, the desktop background appears (blank) then after about 20 seconds the screen goes grey (with the Desktop icons on it) then it flashes white a couple of times then the Desktop picture returns but all the icons are outlined in grey and the writing under the icons are in a grey box. I am still losing access to my internet once in awhile and cannot reconnect until I have unplugged the modem and router and plugged it back in. I have also added the router security log ( wasn't sure if you could tell anything from that but figured it wouldn't hurt to have you take a look at it.) Thank you again for the help and everything you are doing!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See the instructions for MGtools given in the READ & RUN ME ( Using MGtools ) This error message and fix was explained at the end.


    Your PC does not have enough memory to properly run Windows XP SP3 along with everything else you are loading/running. Your logs shows
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 90.67 MB
    You need to have at a minumum, 1 GB which is twice what you have and 2 GB would be much better.

    You already have AVG9 installed? Did you uninstall the Windows Live Safe Scanner. Also uninstall Windows Defender too since AVG already has antispyware protection built-in and Windows Defender in WinXP is not really that good. You don't have the system resources to run all of this.

    Sounds more like network problems with your hardware or from your ISP. I suggest that you also uninstall BitComet at least for now until you correct any problems you are having. Uninstall any other torrent/p2p downloaders too. This includes Torrents-Search-Engine Toolbar

    Port scans are always seen by routers with firewalls and software firewalls. It is one of the reasons for having a firewall. There are millions of PCs/networks in the world and some are used back hackers and scanning for open PCs. Also some ISP also frequently run port scans. As long as your firewall is active and blocking them, you have nothing to worry about.




    Now we need to use ComboFix again
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 18, 2009
  13. JamesDean

    JamesDean Private E-2

    Hi Chaslang, When I ran the combofix with the added files, it still said that mcafee was running, and after the restart spybot teatimer restarted as well. (I did go to the tools section and uncheck the resident tea timer box) I believe it ran ok so I have attached the logs. ***I installed then uninstalled mcafee (hope that works to remove it). Then I was going to redo your instructions in case it was interfering with anything. When I started the combo fix a warning came up and said that a critical update needed to be installed...The update said "failed". I figured that it may have been because the Tea Timer started itself up again, so when it said "do you agree to the terms?" I clicked "no" because I was going to turn off the Tea Timer and restart combofix again. Combofix was then gone from my desktop and I had to copy it over from the My Documents file where I had mistakenly downloaded it to the first time. I hope that the log was not removed from there as well...At this point in time combofix cannot be downloaded due to an error or something. Anyways I hope the logs that I got are sufficient. Thank you again for all your help! When I tried to upload the MGtools zip it says I already included this file, and wouldn't let me. I defragged the hard drive a few days ago and it said that there was over 500mb of temp files, after the scan it said that 14mb were compressed or cleaned. How do I safely get rid of the other 500mb? Thank you, James
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the original version is offline right now while a beta is being used to address a problem.

    That is because you did not follow the instructions given to get a new log. We don't need the same log. We need a new one and you have to run the C:\MGtools\GetLogs.bat program as stated to get a new log. You still need to do this.

    Sorry but this is not a topic for the malware forum. Any temp file you had were already cleaned if you ran CCleaner in the READ & RUN ME.

    You said you did not know what those folders were earlier. They are from you installing Sophos.
     
  15. JamesDean

    JamesDean Private E-2

    Here is the mglog you need. I am not sure if this is relevant to my problem but in the task manager there is 10 svchost.exe running, all with different size files. I only recall seeing 1 or 2 before all this started. On my internet connection icon in the bottom left corner when I click on it it has "Internet Gateway" and "my Computer". Under "Internet Gateway" it says packets sent 3,730 "packets recieved 4,142"....under the "My Computer" Packets sent 61,186 (going up in 5's every second, even when the internet is not on and there are no programs running) Packets recieved 39,670 (also increasing by 5 every second. I only turned my computer on this afternoon around 3 pm,(9pm now) This is the first time today even going on the internet.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. This is quite normal and you only had 6 running according to the MGlogs.zip file you just attached; however the number can vary based on what you have running. 6 to 8 is quite typical, and 4 to 10 would be normal.

    If your computer is on, there are programs running. If you have a broadband type connection (like DSL, Cable ...etc) you are always connected whether you have a brower or email program....etc running or not.

    Your logs are clean but let's just add a few tweaks.

    Disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer You don't have enough memory to keep this running and you already have AVG which has antispyware protection.


    I still see BitComet 1.16 in Add/Remove Programs. Did you forget to uninstall it?


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)


    After clicking Fix, exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. JamesDean

    JamesDean Private E-2

    Hi Chaslang, Thank you again. Is spybot suppose to automatically put the checkmark back in to the teatimer on a restart? I followed the instructions but every restart the checkmark re-appears, so I unchecked it again and followed the instructions for the batch file and the HiJack This. Yesterday I was on the computer and it seemed to freeze up, I checked the task manager and the system idle process was running at 98%. I did a restart and it seems to be ok for now. I still find it strange that on the startup my screen will go grey with all the icons on it, then it flashes white, then back to grey, then the desktop picture appears with all the icons outlined in grey. It wasn't like this before all this started happening. Also when I check the settings for the internet connection (right click on the little monitor icons in bottom left-clicked status)there is a check mark beside "svchost (in these brackets are an IP address and port number, i wasn't sure if I should post the numbers here) then another port# UDP". I dont recall seeing these things before. This also makes me think that some one is compromising my machine. For the amount of packets being sent by my computer to no one, it just doesn't make sense to me. (over 2million the other day before I unplugged the phone line, all of this was while my machine was "idle" for about 2 days.)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to answer my questions before we can continue:
    It is still there?

    I also asked the below which you did not directly answer
    However you indirectly have implied that you are using a dial-up network connection. Is that true?

    Uninstall Spybot too since its permissions have been messed up by the previous infection you had. It also stop the HijackThis fix I gave you from working which is a reason why we don't want Teatimer running. After uninstalling run the previous fix again.

    System Idle Process is not a process. It is measure of the time your CPU is idle (i.e., doing nothing).
     
  19. JamesDean

    JamesDean Private E-2

    Hi Chaslang, the last logs sent should have shown Bitcomet removed, I removed it before my previous post. I have uninstalled SpyBot and reran the HiJack This prgram but those 2 items were not listed. Here is the latest log file. I have hi-speed but when I am not on the computer I have been unplugging the modem because it is constantly flashing (never did this before). It use to only flash when I would click a link or if I was running Bitcomet. I understand about the system idle, but when I was infected with the virus the computer would be unresponsive the task manager showed "system idle process" 98% and nothing else was working. The other day it was doing the same thing. So something was masking itself as this. Could this even be possible? Someone freezing my machine with this process so they can upload my stuff without me being able to use any of my bandwidth. Thank you again for all your attention...
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was still there before. Now it is gone.

    At which connection? The one that goes to towards the internet or the one that goes to your PC.

    Not likely. If your PC was hung, it just could mean certain necessary process crashed and System Idle would still be showing the normal 98% free time.

    Based on your logs which are clean, this is also not likely. Does your modem ( Is it DSL or Cable?) contain a firewall and is it turned on? You need to also install a software firewall on your PC but your lack of adequate memory is going to slow your PC down even more and this may still be the reason for your PC freezing. You could just be running out of memory at various points.

    Let's cleanup a few more things but I you most likely do not have any remaining malware.


    Now download Junction,zip to your Windows folder
    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!
    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. JamesDean

    JamesDean Private E-2

    Hi Chaslang, Thank you again for all your help, you have really gone out of your way to help people like myself, Christmas day! Thank you!
    I have attached the requested logs.

    "Quote" At which connection? The one that goes to towards the internet or the one that goes to your PC.....The one that goes to the computer from the router. I have DSL modem...I think there is a wirewall on the modem but I am not sure, is there a way to check? I have the windows firewall enabled...A couple of times the ps3 shut down by itself, and when we turned it back on it said it was shutdown incorrectly and had to reformat. (i think someone was trying to hack into it as well) through the wireless router (is that possible?)(I know this isnt the forum for something like this but I wanted to know if something was using the wireless if someone could access it)
    Thank you again!
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have to research you DSL modem specs to find out. However check your router since you say you have one. Most new routers have a hardware firewall too and typically have a web browser interface as should your DSL modem.

    Better than nothing but totally inadequate.

    PS3 ????

    Possibly but not likely. Do you have encryption turned on so that your wireless connection is protected from general access.

    If you don't have you wireless signal setup properly and protected, yes anyone in range can use it.

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  23. JamesDean

    JamesDean Private E-2

    Thank you for everything!!!!!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds