Chewie help!!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Derree
    Digital Video Expert
    Digital Video Expert
    • Jul 2005
    • 546

    Chewie help!!

    Hey Chewie...I have done a Hijack this post and got a reply on http://www.bleepingcomputer.com/ and got a reply I did not expect..I am going to post the log and reply can you tell me if I am getting good advice here?
    hijackthis.log
    and here is the response I got:

    I am sorry to tell you that there is a <!--coloro:red--><!--/coloro-->bot worm<!--colorc--><!--/colorc--> on your computer.

    A bot worm is a program that is installed without your knowledge and enables a hacker, sitting at another computer perhaps thousands of miles away, to control your computer so that it does what he wants -- it becomes his "bot."

    Bots can be used to launch <!--coloro:blue--><!--/coloro-->denial-of-service attacks<!--colorc--><!--/colorc--> (This is where hundreds of bots simultaneously bombard a website with requests for information, overwhelming its capacity to respond and, thereby, shutting it down) and for other sorts of mischief. The bot can also do mass spam mailing, download files to the computer, or upload files and data, <!--coloro:red--><!--/coloro-->including passwords and other private information<!--colorc--><!--/colorc-->.

    For these reasons it is very important that, starting immediately, <!--coloro:red--><!--/coloro-->this machine be kept off the internet and physically disconnected from any network it may be part of<!--colorc--><!--/colorc-->.

    If you use or have used this computer for online banking or shopping or for accessing or storing personal information such as school records, then you need to take steps to protect your information that may have been compromised. I recommend these steps for action:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

    This is something i don't like to recommend normally, but with a computer this badly infected, the best solution for your safety would be to reformat the hard drive and reinstall Windows.

    Please read the following link very carefully:

    When Should I Format, How Should I Reinstall

    Here are some more links to help you decide:


    Security Management - May 2004
    Help: I Got Hacked. Now What Do I Do?
    http://www.microsoft.com/technet/community...gmt/sm0504.mspx

    Security Management - July 2004
    Help: I Got Hacked. Now What Do I Do? Part II
    http://www.microsoft.com/technet/community...gmt/sm0704.mspx


    Only you can make this decision, you know the uses this computer has been put to. But please consider carefully before deciding against a reformat. If you do make that decision I will do my best to help you disinfect it, but you must understand that once a machine has been taken over by this type of malware, it can never be declared clean.

    If you choose to format and reinstall see this link for instructions:
    http://www.cyberwalker.net/faqs/how-tos/reinstall-faq.html

    Please let me know whatever decision you make.

    Dave<!-- google_ad_section_end -->

    So Should I follow his advice??<!--IBF.ATTACHMENT_399369--><!-- THE POST -->
    sigpic



    Turn down the suck...Turn up the
    good
    -------------------------------------------
  • Chewy
    Super Moderator
    • Nov 2003
    • 18971

    #2
    there are a couple of possible nasties there, but I would look for confirmation
    with a safe mode scan from 1 or 2 other programs(anti-trojans)

    a clean install is the best way to get rid of a trojan if you confirm you have one

    Comment

    • Derree
      Digital Video Expert
      Digital Video Expert
      • Jul 2005
      • 546

      #3
      Ok I will try that as well chewy...For some reason my pc-cillian will not work in safe mode but I use ewido and it does work...thanks for the advice
      sigpic



      Turn down the suck...Turn up the
      good
      -------------------------------------------

      Comment

      • Chewy
        Super Moderator
        • Nov 2003
        • 18971

        #4
        have you used your free trial of trojanhunter?

        Comment

        • Derree
          Digital Video Expert
          Digital Video Expert
          • Jul 2005
          • 546

          #5
          I looks like I have used it already...now I gotta find another one..I will look on major geeks and on file hippo see what I can find
          sigpic



          Turn down the suck...Turn up the
          good
          -------------------------------------------

          Comment

          • Chewy
            Super Moderator
            • Nov 2003
            • 18971

            #6
            Have you ever done a clean install? Every year or so is not a bad idea.
            Even the best computer geeks can't keep windows healthy forever, that is if they ever use the computer much?

            Comment

            • Derree
              Digital Video Expert
              Digital Video Expert
              • Jul 2005
              • 546

              #7
              By doing a clean install is that like reformatting..will I lose everything that is on th pc right now? I have not done one since I got the pc almost 2 years ago...
              sigpic



              Turn down the suck...Turn up the
              good
              -------------------------------------------

              Comment

              • Chewy
                Super Moderator
                • Nov 2003
                • 18971

                #8
                that's why everyone needs a data partition or second hard drive and still back up

                Comment

                • LT. Columbo
                  Demigod of Digital Video
                  • Nov 2004
                  • 10671

                  #9
                  if you can't do what chewy said, which would be ideal

                  burn some data rw's before you format derree
                  "One day men will look back and say I gave birth to the 20th Century". Jack The Ripper - 1888
                  Columbo moments...
                  "Double Shock" "The Greenhouse Jungle" "Swan Song" FORUM RULES
                  "You try to contrive a perfect alibi, and it's your perfect alibi that's gonna hang ya."
                  (An Exercise In Fatality, 1974)


                  Comment

                  • Derree
                    Digital Video Expert
                    Digital Video Expert
                    • Jul 2005
                    • 546

                    #10
                    ok...so I will have to start over from scratch progarm wise.. by that I mean rip it, shrink dvdd etc as well as all the non-dvd releated programs...but (and sorry for the dumb question) what is the quickest way to back up all the files I have on the pc, and keep in mind I don't have a second hard drive...wish I did....and now I just gotta remember where I put the discs I made when I first got the pc..that is my windows..didn't come with instal discs
                    sigpic



                    Turn down the suck...Turn up the
                    good
                    -------------------------------------------

                    Comment

                    • LT. Columbo
                      Demigod of Digital Video
                      • Nov 2004
                      • 10671

                      #11
                      burn data discs with nero or similar, what else can you do without an external HD?

                      if it was me though and i had no security concerns (passwords, card numbers) and the pc has no problems i would just try to remove it or just ignore it.
                      "One day men will look back and say I gave birth to the 20th Century". Jack The Ripper - 1888
                      Columbo moments...
                      "Double Shock" "The Greenhouse Jungle" "Swan Song" FORUM RULES
                      "You try to contrive a perfect alibi, and it's your perfect alibi that's gonna hang ya."
                      (An Exercise In Fatality, 1974)


                      Comment

                      • Derree
                        Digital Video Expert
                        Digital Video Expert
                        • Jul 2005
                        • 546

                        #12
                        yeah that is what I am doing Looie..the guy at bleeping gave me some insturctions but the path I have to follow isn't co-operating...C:\Windows\system32\winlog.exe... When I go into safe mode and try to navigate to that I can't find the system32 folder...sigh...
                        sigpic



                        Turn down the suck...Turn up the
                        good
                        -------------------------------------------

                        Comment

                        • Chewy
                          Super Moderator
                          • Nov 2003
                          • 18971

                          #13
                          Description:
                          winlog.exe is a process belonging to the Salfeld Personal Security tool which is used to set parental controls to your computer. This program is a non-essential process, but should not be terminated unless suspected to be causing problems.

                          Note: winlog.exe is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.
                          looks pretty bad if you didn't install the first option

                          call your manufacturer if you can't find recovery disks that you made, they have to supply you with them upon request(for a small fee)

                          Comment

                          • Derree
                            Digital Video Expert
                            Digital Video Expert
                            • Jul 2005
                            • 546

                            #14
                            Well the guy from bleeping that was helping me gave me some instuctions to follow..as I posted above...what is strange is I couldn't find the system32 folder to get in there to delete the file...I did search for the winlog.exe and it is nowhere on the pc..when I posted to him my new hijackthis and ewido logs he said it is coming up clean now...I wonder tho..we had tried out a 'internet spying' program awhile ago and I wonder if part of it was left behind when we got rid of it...either way we changed passwords for our banking and should be ok...thanks for the help Chooie and Looie..if I could you would both get greens!
                            sigpic



                            Turn down the suck...Turn up the
                            good
                            -------------------------------------------

                            Comment

                            • Chewy
                              Super Moderator
                              • Nov 2003
                              • 18971

                              #15
                              these trojans are often multifaceted(many components), there may be a small well hidden downloader left, keep a close eye out for any reinfection.

                              Comment

                              Working...