Computer hacked?

Discussion in 'Malware Help (A Specialist Will Reply)' started by seelisilus, Dec 14, 2010.

  1. seelisilus

    seelisilus Private E-2

    I was surfing the net a few days ago when it slowed down considerably. I immediately logged off my user account and tried to go to ADMIN to do a scan. After i clicked enter, a message appeared and said i cannot access said account because it is being used by someone. There was a 30-second timer on the right side of the message window, i let it finish, then it started up again at 30sec so i just clicked ok. When the account opened, there was Windows Tour, like i just opened a new acount. What could possibly be the reason why it happened? I then did a system restore, and after that, i downloaded Malwarebytes. I did a scan and it found 100+ adwares plus 3 trojans and some hijackers. They are now quarantined, do i remove them all? What steps do i do after i totally remove them, should i also delete and reinstall other programs? Help please, i don't know much about these things. I'll post below the mbam logs. Thanks.


    Malwarebytes' Anti-Malware 1.50
    www.malwarebytes.org

    Database version: 5297

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    12/12/2010 7:40:30 AM
    mbam-log-2010-12-12 (07-40-30).txt

    *Edited by dr.moriarty - Removed inline log and attached
     

    Attached Files:

    Last edited by a moderator: Dec 16, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. seelisilus

    seelisilus Private E-2

    do i download both Java(TM)6 Update 23 and Sun Java Runtime Environment 6 Update 23?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you needed to do was click the link given in the instructions where it said the below
    This sends you to the proper download
     
  5. seelisilus

    seelisilus Private E-2

    Thanks. I just asked coz i got both Java(TM) Update 21 and Java(TM) SE Runtime Environment 6 on my computer and i don't know their difference, if they do the same job or not.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you going to attach the rest of the requested logs? We still need these::
    SAS
    RootRepeal
    ComboFix
    C:\MGLogs.zip --> from running the C:\MGTools.exe.
     
  7. seelisilus

    seelisilus Private E-2

    sorry, been very busy. Christmas season is crazy here in my country. haven't even installed JRE yet. i'll get JavaRa later and have it uninstall the older versions. then i'll update.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just post back when you have all the logs. :)
     
  9. seelisilus

    seelisilus Private E-2

    just an update guys: i am now in windows cleaning procedure. i have already downloaded MBAM a few days ago and already did a scan and posted the log here. Do i remove it and download again? All the mywebsearch adwares and the trojans plus hijackers are already in quarantine.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No you do not need to redownload MBAM> but we do need the other requested logs.
     
  11. seelisilus

    seelisilus Private E-2

    do i still have to rename it mb.exe?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, since it presumably ran fine without renaming.
     
  13. seelisilus

    seelisilus Private E-2

    question about MGtools; do i download it in C drive? how? that's also where i open it?
     
  14. seelisilus

    seelisilus Private E-2

    sorry about that. i saved it already in C. do i skip step 2, disabling user account control? seems it's only for vista and windows 7.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can skip running MBAM, but you need to still run these:
    SAS ( SuperAntispyware )
    RootRepeal ( If it will run ).
    ComboFix
    C:\MGTools.exe --- which will produce the C:\MGLogs.zip.
     
  16. seelisilus

    seelisilus Private E-2

    i am now about to scan with combofix. how do i disable temporarily SAS,MBAM, and my windows firewall? or can i now remove SAS now that i saved it's log?
     
    Last edited: Dec 18, 2010
  17. seelisilus

    seelisilus Private E-2

    i also have spywareblaster. how do i disable all these?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No need to disable spyware Blaster. Just continue on.
     
  19. seelisilus

    seelisilus Private E-2

    what about my windows firewall, SAS and MBAM?
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry about them, just continue on!
     
  21. seelisilus

    seelisilus Private E-2

    i don''t get this windows recovery console. do i just ignore and continue?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just ignore it and continue on.
     
  23. seelisilus

    seelisilus Private E-2

    finished with the logs. how do i post MGTools log here? there are 14 logs for this. do i attach this as a folder?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this:
    How to attach items to your post.

    Attach the entire C:\MGLogs.zip
    and also attach the other requested logs:
    SAS
    ComboFix
    RootRepeal ( If it ran. )
     
  25. seelisilus

    seelisilus Private E-2

    here are the logs. hope they're all complete as you requested.
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did just fine. :)

    Your logs are clean. The scans took care of any malware that was on your system. ;)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  27. seelisilus

    seelisilus Private E-2

    how do i delete rootrepeal? just delete it from desktop?
     
  28. seelisilus

    seelisilus Private E-2

    thanks for your help TimW and Kestrel13!...one more question, do i keep the normal startup mode?
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can just delete RootRepeal. And to answer your other question, you must always remain in normal start up mode, any other mode is primarily used for troubleshooting and diagnostics purposes.
     
  30. seelisilus

    seelisilus Private E-2

  31. seelisilus

    seelisilus Private E-2

    DISABLING AUTORUNS: do i need to download "Guided Help"? Or do i just follow the manual steps in backing up registry? Also, how do i copy the bold text to notepad?
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't understand what you are referring to. If you want to disable autoruns you can use this utility:
    AutoEater.

    Why are you trying to backup your registry and what text are you trying to save to notepad?
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe that seelisilus is referring to Step 9 of the How to protect yourself from malware thread. ;)
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah, the cloud parts.

    Just highlight the bold text in the quotation box and then paste it into notepad. Be sure to save it as AutoRunDisable.reg and then save the type file as "all files". Then double click it to let it merge with the registry. You can delete it once you are done.
     
  35. seelisilus

    seelisilus Private E-2

    yes, that's it. it said i back up first before disabling autorun.
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks for clearing that up for me. :)
     
  37. seelisilus

    seelisilus Private E-2

    i'll just download autoeater instead of disabling autorun. will it not harm my computer if i keep both MBAM and SAS?
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We recommend that you keep both SAS and MBAM for running backup scans when you suspect a malware issue.
     
  39. seelisilus

    seelisilus Private E-2

    Hey guys. I have this old slow PC that i still keep, just in case of emergency, if ever laptop doesn't work. I earlier did all the steps in Read & Run Me First, then scanned with MBAM and SAS. Both found nothing. Should i continue and run Combofix, Rootrepeal and MGtools and post the logs here? I just want to be sure that it's all clean.
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can start a new thread for this other machine and post all the logs so we can check them. ;)
     
  41. seelisilus

    seelisilus Private E-2

    ok, thanks. i'll post all 5 logs there when i'm done.
     
  42. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds