Group Forum
Advanced Search
Filter     |   View Watchlist   |   Mark Forum as Read
[ Print Friendly ] [ Watch Thread ]
How to fix your computer from an attack? [ 1 ] [ 2 ]
mikilll115
#1   Posted 3 years ago
    [ Reply ]   [ Quote ]
Hey how do you fix from your computer from an attack? For example how to you get rid of a worm or spyware manually?
notthefbi
#2   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #1:

Are you suffering from an attack right now or are you just wondering how to prevent one?
mikilll115
#3   Posted 3 years ago
    [ Reply ]   [ Quote ]
I am wondering how to fix one in the event of one so basically I am wondering how to check the computer manually. If I ever get one that gets passed all the security on my computer.
notthefbi
#4   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #3:

Well, the best way is to Google the name of the item and find the removal instructions. Usually Google will bring up a website called bleepingcomputer.com somewhere near the top and they stay pretty up to date on the viruses that come out. But, if you don't feel like searching yourself, I do not mind doing it for you. Also, posting a HiJack This log in your first post of a thread will help us out so we can see some of what is going on with the computer. HiJack This can be found here. But, be careful with the program if you decide to use it without someone consulting you. It is very easy to screw up something important and then have to completely reinstall your operating system. By the way, what programs do you use?
mikilll115
#5   Posted 3 years ago
    [ Reply ]   [ Quote ]
Vista but my old xp computer has a big problem.
notthefbi
#6   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #5:

Sorry, I meant security programs lol.
mikilll115
#7   Posted 3 years ago
    [ Reply ]   [ Quote ]
AVG free. And a search bot of some kind.
notthefbi
#8   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #7:

Have you tried any of the programs that we recommend? Malwarebyte's is an amazing program and you should rarely have to remove malware manually with it.

Malwarebyte's Anti-malware
notthefbi
#9   Posted 3 years ago
    [ Reply ]   [ Quote ]
Also, you do not have to buy that program but there is an option for it if you want.
mikilll115
#10   Posted 3 years ago
    [ Reply ]   [ Quote ]
Yes, I am looking into that program.
notthefbi
#11   Posted 3 years ago
+ 1 Ditto     [ Reply ]   [ Quote ]
In reply to mikilll115, #10:

I can assure you that it is a great program. It's also really easy to use but if you need help with it, just ask. I have been using this program for almost a year now and it has done very well for me. I have had my laptop for over 2 years now. When I first got it, there was a program called spywarebot that Dell or my school had installed before giving me the laptop. They never gave me a license for it so I just removed it and removed all of it's files. Or so I thought. A year later, I found out about Malwarebyte's and decided to give it a shot. Luckily my computer was pretty clean of viruses and other stuff but there was one thing that it caught. Spywarebot. Ever since then I have wondered why Dell or a college would install malware on someones computer but nevertheless, I haven't had to worry about much since then. I had managed to get the Vundo virus about 6 months ago and after 1 full scan of the program, it was gone. Which was a lot easier than the first time I ran into that virus at work. Took me 3 days to remove it manually.
mikilll115
#12   Posted 3 years ago
    [ Reply ]   [ Quote ]
Yes but doesn't say it is for vista.
mikilll115
#13   Posted 3 years ago
    [ Reply ]   [ Quote ]
Ok, I downloaded it. I am going to try it now.
notthefbi
#14   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #13:

It works with Vista
mikilll115
#15   Posted 3 years ago
    [ Reply ]   [ Quote ]
It has already found 2 pieces of spyware!!!!!
notthefbi
#16   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #15:

That is a good thing. Congratulations, I think you have found the light lol.
mikilll115
#17   Posted 3 years ago
    [ Reply ]   [ Quote ]
Very funny but I am going to try on the computer that I have a problem on.
notthefbi
#18   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #17:

It should take care of the problem unless it's a brand new virus that nobody knows anything about. Let us know how it goes.
mikilll115
#19   Posted 3 years ago
    [ Reply ]   [ Quote ]
2 infected, located in the system32 section of my system! Something tells me when something says hijackyou in system that is very bad.
notthefbi
#20   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #19:

Can be, besides messing with your system. If you have personal data on your machine (bank accounts, etc...) you may want to change passwords and stuff like that.
mikilll115
#21   Posted 3 years ago
    [ Reply ]   [ Quote ]
What is system32?
notthefbi
#22   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #21:

That is where all of Windows critical files are. But do not feel targeted, most infections plant themselves in that directory. Usually not too bad of deal but it can be, just depends on the attack. Have you tried HiJack This yet?
mikilll115
#23   Posted 3 years ago
    [ Reply ]   [ Quote ]
yep, it finds alot but nothing is harmful, as of yet.
notthefbi
#24   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #23:

Can you go ahead and post a log of HiJack This here? I will be able to help you figure out what to remove if you do.
mikilll115
#25   Posted 3 years ago
    [ Reply ]   [ Quote ]
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:15:42 PM, on 11/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Windows\SysWow64\Macromed\FlashFlashUtil10b.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files (x86)\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files (x86)\WinTV\Ir.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: dlbt_device - Unknown owner - C:\Windows\system32\dlbtcoms.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C
notthefbi
#26   Posted 3 years ago
    [ Reply ]   [ Quote ]
Remove these for sure:

O1 - Hosts: ::1 localhost

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O13 - Gopher Prefix:


You might also consider doing a repair install because some of your Windows Services appear to be corrupt. If you feel confident enough to do a repair install (or in-place upgrade as Vista likes to call it) you can find the instructions here. If you feel that this is beyond your abilities, please do not proceed. You may end up with a huge paperweight or have to do a complete reinstall if you mess something up. If you have a friend that knows how to do this better than you, please have them do it. If you decide to proceed, we hold no accountability for your actions. You may even be able to fix your Services problems without doing this.
mikilll115
#27   Posted 3 years ago
    [ Reply ]   [ Quote ]
What do I remove to stop microsoft from watching me on, (basically reporting me to them) because i heard it slows your computer down. You sound like a vigara commerical about holding no accountability.
notthefbi
#28   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #27:

Sorry, I kind of have to. There are always people that will be displeased with computer/web/programming work, the trick is to try and do everything to keep them happy while still being able to do your job. Gets pretty rough sometimes. As far as Microsoft watching you, as long as you didn't sign up for the customer experience program you should be fine. Here are a couple of articles about how to help speed up your computer. Hopefully you can get some use out of them:

http://www.microsoft.com/atwork/maintenance/speed.aspx (Using ReadyBoost on Vista is pretty effective. Used to have a 1 GB stick in my girlfriend's computer because she made the mistake of getting a Vista PC with only 1 Gig of RAM)
http://www.mydigitallife.info/2008/02/26/tweak-windows-vista-virtual-memory-change-or-disable-paging-file-size/ (This is effective for a while. If you have the Hard Drive space to spare, I would crank it up to 3072 for the initial size and 4095 for the maximum size[Vista will not do 4096-or 4GB- for some strange reason].
http://www.switched.com/2009/03/03/how-to-shut-off-startup-programs-windows/ (This may also help but gets pretty tedious to do)
mikilll115
#29   Posted 3 years ago
    [ Reply ]   [ Quote ]
I hope to take a look at my xp as well. I have 1 big question for you, if i am to scrap an old computer and rebuild it with new hardware can I take the hard drive and use it's operating system?
notthefbi
#30   Posted 3 years ago
    [ Reply ]   [ Quote ]
In reply to mikilll115, #29:

Yes and no. I just had to do this with a computer at work. At first it didn't want to work but if you just pop your XP disc into the computer (If a straight swap doesn't work) and do a repair install on it, in theory it will work. Luckily it worked for me and hopefully it works for you. You will have to reactivate Windows after you do it but that isn't a problem, especially if you get lucky enough to do it over the internet. The one I did today I had to activate over the phone before I could install the drivers for the ethernet card but it is not too big of a deal. More than likely the first time you try it, it will fail but if you hit the 'Change product key' button at the bottom of the window and put in the product key from your old computer and then call the activation number it will work. The telephone activation is really easy and the automated service is great but a little slow. It will guide you through the whole process.

How is your Vista machine going?
[ 1 ] [ 2 ] [ Next ]
You must be a member of the group to post in this thread.