i think my computer was/is being hacked into...

Discussion in 'Malware Help (A Specialist Will Reply)' started by bucketofstars, Mar 24, 2005.

  1. bucketofstars

    bucketofstars Private E-2

    hi i'm new here, i'm sure you get a lot of people like me who have pc problems....
    anyway, i was running spybot the other day b/c i've been having adware problems. in the middle of it running my computer just shuts down. so i started it back up and when it goes to the windows(i have xp) welcome screen a box displays this:
    "windows cannot load the locally stored profile. possible causes of this error include insufficient security rights or a corrupt local profile. if this problem persists, contact your network admin."

    and then after a countdown of 30 seconds, that box closes and another box appears that says this:
    "windows cannot find the local profile and is logging you on with a temporary profile. changes you make to this profile will be lost when you log off."

    this happened monday night. i found this website tuesday morning when looking through programs i had to fix my computer and i found hijack this and was going to run it, but i felt i better not since i have no idea how to use it or what i'm looking to remove. i had computer problems a few months ago and took it to a repair place to get it fixed and it cost me 130 bucks. and since my computer actually turns on and is still functioning i figured i'd try and fix it myself. so right now i am on a temp profile and none of my things like music files, picture files, word files, etc are on this profile. but all of my programs on my regular profile like photoshop, AIM, etc is on this profile. it's really strange. i was going to fix it on tuesday, or try to, but then my bathroom caught on fire while i left the house with a candle burning for a couple of hours (what a week). so now while the workers are in my apartment fixing everything, i decided there's finally time to try and fix this computer problem.

    i read the thing on here that says to scan your computer with all those programs before asking for help and i did do that. the only thing i haven't run is hijack this, but i have a feeling it won't work. maybe (hopefully) i'm wrong, but nothing else worked and i downloaded and ran everything that was listed in the order they were listed.

    if anyone could help me, it would be GREATLY appreciated.
    thanks!
    -kori
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).

    And one last step - please keep your candles away from the PC! :D
     
  3. bucketofstars

    bucketofstars Private E-2

    yeah luckily the computers in the apartment were not affected by all the smoke.

    okay i did the scan, and hopefully this attachment works.
     

    Attached Files:

    • log.txt
      File size:
      6.3 KB
      Views:
      3
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the previous step does not find and fix the ISTsvc problem, the below should. If it did fix it, you will most like not find the lines am referring to below so just continue with the other steps.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    istsvc.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://10517.splash.sexsearch.com/bucket1.html
    O4 - HKLM\..\Run: [JjcX7qJe] C:\WINNT\cxrca.exe
    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\ISTsvc
    C:\WINNT\cxrca.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings (you can use http://www.gateway.net if desired for your start page instead of www.majoreeks.com)
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. bucketofstars

    bucketofstars Private E-2

    i'll run that right now. i tried running the online scanners but they didn't work, i'm sorry i forgot to mention that before.
     
  7. bucketofstars

    bucketofstars Private E-2

    okay so i did everything you said to... i fixed everything on the hijacker thing you told me to except:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://10517.splash.sexsearch.com/bucket1.html

    because it wasn't there when i looked for it.
    everything went smoothly and then i booted it back up into normal mode and i still got those two messages and am again back onto the temporary profile and can't get into my files i have on my normal profile.
    here's another log for hijack this that i ran when i rebooted.

    oh and also, when i ran this:
    http://securityresponse.symantec.com/avcenter/FxIstbar.exe
    it didn't find anything.

    oh and another thing i forgot to mention:
    "make sure you have system restore disabled"
    i don't know how to disable the system restore if it is enabled, so that might have made the difference as to why my computer is still acting up.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    It's in the first Step in the READ ME FIRST! Please check it again.

    Your log is clean now.


    Also please check the below out for your other problem:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;812339
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds