Hacked -

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anth0079, Dec 13, 2006.

  1. Anth0079

    Anth0079 Private E-2

    Hi I registered for some help. Ok here is my problem:

    I came home from work 3.5 hrs ago and all my desktop icons were deleted. There was an open notepad document on my desktop that was titled [Owned]
    and contained the text [ HAHAHAHAHAHA ]. Now I am no computer expert but I think I might have been hacked. I checked my Norton Internet Security reports and it stated there was an intrusion about 6 min before I walked in the door.

    I have never had this happen to me before so I came here for help. I was not going to post until I followed all the steps in your cleanup thread, but I am just too freaked out :eek: to wait until I finish. by the way, I am currently scanning my comp with BitDefender in safe mode.

    I ran Spybot and it found a registry entry, maybe a hack? I don't know. which it said was: WINDOWS.SECURITY.CENTER_DISABLED and I fixed it.

    I ran CounterSpy and it found 965 reg entries infected which all had something to do with WildTangent. I removed all of those along with WildTangent too. I would post my CS log but it has apparently disappeared! I guess I will have to run it again after scanning online.

    Anyway I think this whole mess has something to do with a process called SVCHOST.EXE which only shows up in my process list in normal mode. There might be another C in there at the beginning of the process name, I can't remember and I do not want to even boot up in normal mode to find out when there is someone writing freaking notepad memos on my desktop. When I try to end it a system alert saying I was denied access pops up.

    Any thoughts at this point would really ease my mind here.

    Thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You need to complete all steps in the READ & RUN ME and attach ALL the requested logs. You should not be connecting here or anywhere else while scanning. It will slow things down and can prevent the scanners from fixing certain problems. Closed ALL browser windows except the ones needed by the scanners.

    NOTES:
    1. Your Windows Security Center is disabled because you are running Norton as your security center. This is normal.
    2. svchost.exe is a normal valid process that will be see running multiple times. As long as it is running from the system32 folder it is okay.
     
  3. Anth0079

    Anth0079 Private E-2

    I did 1-7 on the list and here are my logs. Only thing is I was super tired last night so I accidentally saved the BitDefender scan results in html format :rolleyes: . I copy and pasted the results into notepad so I could upload them anyway. I hope you can still use them. I still have the html results saved on my comp though.

    Thanks
     

    Attached Files:

  4. Anth0079

    Anth0079 Private E-2

    The thing is I didn't even know that I had a problem so I have no idea what to look for.

    I am connecting to the internet via cable modem. No one has access to my computer except me. This is the only computer in my place. And I am using Norton Internet Security for protection.

    I have to get ready for work now. I will check back in 10 hrs when I get home from work. I think I will just shut my internet off while I go.

    Thanks!
     

    Attached Files:

  5. Anth0079

    Anth0079 Private E-2

    Sorry posted the wrong hijackthis log :mad: ...

    Here is the right one with the renamed exe used.

    Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is what the procedure in the READ ME asks for. We don't want the file converted to text. The HTML file is easier to read. If you followed the procedure, all you had to do was rename the file to have a .txt extension rather than .html

    It does not matter anyway since no problems were found by BitDefender. And in fact none of your logs are showing any malware.

    Are you still having problems?


    But you do need to do the below to get your Sun Java version updated.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Now install the current version of Sun Java from: Sun Java Runtime Environment
     
  7. Anth0079

    Anth0079 Private E-2

    Hi chaslang, and thank you for taking the time to reply to my posts.

    See the whole thing is I don't even know how to tell if I still have a problem. How can I even tell? I could wait for another taunting notepad document to pop up on my desktop I suppose:confused: .

    like I said in my first post:

    I guess what I am asking for is your advice here chaslang :) .

    Seriously, I am worried that I might be monitored right now. How can I be sure it is even safe to continue paying my bills online or accessing my bank account online?

    Any thoughts would be helpful chaslang.

    Thanks!
     
    Last edited: Dec 13, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I'll give you something else to run (it digs deeper) but I doubt we are going to find anything.

    Does your Norton software include a firewall?


    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.

    Before you came here for help, what antispyware realtime blocking tool were you using. I don't see any other than CounterSpy which I assume you installed while following the READ & RUN ME.

    Do you use a router to your cable modem? Are you wireless or wired (or both)?

    What did you have to do to get your icons back?
     
    Last edited: Dec 14, 2006
  9. Anth0079

    Anth0079 Private E-2

    You were right about the blbeta scan, it found nothing.

    I use Norton Internet Security (the newest Version), and it does have a firewall included.

    No I do not use a router for my cable modem. I am just connected to it through an ethernet cable.

    I had no previous antispyware (realtime) program installed and running before CS. But I have CS running now even though the sunThreatEngine.exe eats up a lot of memory usage.

    My Desktop icons are gone and to tell you the truth I cannot even remember all of them anyway. And, well, I just decided to leave my desktop bare for the moment until I can figure this out.

    By the way, now I know I have a problem because every time I turn off my cable modem or disconnect it from my computer something that does not show up on my running processes list in the Windows Task Manager instantly eats up 50% of my CPU until I reconnect (and turn on) my cable modem:eek: .

    So now I am worried. Please help :)

    Here is my blbeta log:
     

    Attached Files:

    Last edited: Dec 14, 2006
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's just first try the obvious! Right click anywhere on your Desktop and select Arrange Icons By and then in the next pane make sure Show Desktop Icons is selected.

    Let me know the results.

    Consider getting one as the added layer of protection is worth it.

    Protection does not come for free. Having no protection is a very bad idea! You can uninstall CounterSpy now since it is only a free trial which expires after 15 days and is of no use at that point. Try installing the below free tool which offer protection too and see if it is less resource hungry for you.

    Spyware Terminator 1.7.0.899



     
    Last edited: Dec 14, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds