Virus, Spyware attack???? Or something else

Discussion in 'Malware Help (A Specialist Will Reply)' started by richkard, Mar 2, 2012.

  1. richkard

    richkard Private E-2

    My computer laptop been action weird lately. It's an HP computer. Can you guys check out if it malware related or something else that causing me all those problems? Thanks you in advance
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you having?
     
  3. richkard

    richkard Private E-2

    The computer is hanging a lot. Sometimes at startup when I done putting my password I get like a messed up screen, like the pixels are distorted (it happened like 5 times already). Opening folders take more time than usual. When browsing the web I click a link a the computer just hangs and I have to manually turn it off.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds like a haredware issue. I suggest you post in the hardware section to get additional assistance.

    Your logs are not showing any malware that would be responsible for your issues.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  5. richkard

    richkard Private E-2

    OK thank you but can you check my logs one more time? I will do all the scans again. I didn't even do a rootkit scan. Thanks
     
  6. richkard

    richkard Private E-2

    Yo man TimW, I know you have a lot of thing to do but please do me this personal favor. I can swear to you that my roommate was hacking my computer and my wireless was disconnecting constantly when he was online. I don't know what he put in there. I heard him talking to one of his friends and from what I heard (I really hope I did hear falsely as I was listening through my door) it is something that no one can trace. Please believe me man. I am not lying. It happened last night and I switch place but I am not sure I can trust this pc. He could be spying on me now for what I know. Please man give me other tools to check every area of this computer. If you don't want to no problem. Thanks
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, if you think your roomate put something on it that is undetectable, then you have a problem.

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  8. richkard

    richkard Private E-2

    Thanks man seriously. Here are the scans. But I think he already took what he was looking for. I moved away, changed my yahoo messenger and hotmail password but a friend told me that I was online when I was not even on my computer, so he still can crack the password. I think (and I hope not) he was looking for my bank account number. The scans have shown nothing so maybe he was spying on me through the wireless connection cause it was constantly disconnecting but I really don't know how it's possible.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to use a different computer to change your passwords!!!
    I suggest you post in the networking forum to get advice on how to lock down your internet connections. Secure your modem/router.

    Your logs are clean.
     
  10. richkard

    richkard Private E-2

    Ok thanks man I really appreciate that. I will follow your recommendations. But there is no need to post in the networking forum cause the router wasn't mine wasn't his either but the landlord's. I just need a way to make myself invisible or block my ports but I guess that's impossible cause even with Comodo firewall he could still access my computer. Thanks again
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  12. richkard

    richkard Private E-2

    Yo man TimW I am a little worried there. I really think this guy got a hang on my computer. I was doing a skype call and even after closing skype my webcam was still on. I opened skype again remake the call the cam was still on and I could still see myself. How come he can still do this things while I am not using the same network as him?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Probably because you are piggybacking on someone elses router/modem.
     
  14. richkard

    richkard Private E-2

    No man. Everything happened on my university internet. I have a wireless account there as every students do.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then he must have your passwords. I am assuming that you are password protected. If you would, downloadMGtoolsand save it to your root folder. Overwrite your previous MGtools.exe file with this one, if you already uninstalled it and get me a new C:\MGLogs.zip.
     
  16. richkard

    richkard Private E-2

    Here's the log you requested. Thanks
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All I am finding is garbage in your temp folders. As I stated before, someone would have to know your passwords or have physical access to your computer. I am not seeing anything of that nature. You have Privacy Keyboard installed which should alert you to any keylogging software.

    Now download The Avenger by Swandog46 to your Desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    Extract avenger.exe from the Zip file and save it to your desktop.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):


    1. Run avenger.exe by double-clicking on it.
    2. Click OK at the warning to continue to use The Avenger
    3. Do not change any of the check box options!
    4. Shut down your protection software now to avoid possible conflicts.
    5. Copy everything in the Quote box below, and paste it into the Input script here: part of The Avenger
    6. Now click the http://img33.imageshack.us/img33/9159/executeavenger.jpg button
    7. Click Yes to the prompt to confirm you want to execute.
    8. Click Yes to the Reboot now? question that will appear when The Avenger finishes running.
    9. Your PC should reboot, if not, reboot it yourself.
    10. A log file from The Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
    11. Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    If you still feel that your system is compromised, the best course of action would be to back up your important data and files and re-install your OS>

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  18. richkard

    richkard Private E-2

    Hi, here are the logs. I really hope privacykeyboard is as good as it is advertised, I am testing and and thinking of buying it if it's good. Unfortunately I can't reinstall my OS I don't have any installation CD.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again, I am not seeing anything to indicate and intrusion. However, do you know what this is:
    Code:
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
    32CD~1        Mar  8 2012              "????"
    What issues are you still having?
     
  20. richkard

    richkard Private E-2

    I don't really know what that is. But when I follow the path it show a folder in chinese. I did not recall installing anything like that. Is privacy keyboard really good? Can it detect rootkit also?? Thanks man for helping me, I really appreciate it.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not familiar with Privacy Keyboard. It's something you should ask about in the software forum. We have run Avenger and it reports no rootkits. Did you delete that folder?
     
  22. richkard

    richkard Private E-2

    I just deleted it.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how things are going.
     
  24. richkard

    richkard Private E-2

    Everything seems good. No problem at all.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     
  26. richkard

    richkard Private E-2

    Thank you very much man!!:)
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds