PDA

View Full Version : computer is hacked



G.
08-06-09, 10:40 PM
no, not this one...


HELP!

g. must have hit a bad website, then clicked "ok".

Spybot went nuts, AVG went nuts, and a few "fake" spyware sweeper sites popped up (in IE, which I don't use).

I tried to clean them up with AVG, but things got wickedly locked up, and I eventually had to hit the power button. Now I can't boot up. Not with F8, <esc>, F10 (restore point), anything. I can get my background screen to come up and that's it. (the function keys may not be working bc I have a wl keyboard. I think the kb driver starts after the point where I need to have hit F8. I don't own a wired keyboard. :( )

A bit of research, ask a few people, I need a "live CD". I go to http://www.knopper.net/knoppix-mirrors/index-en.html to get knoppix (don't know crap about Linux). I need a bootable OS.

Seems like I'm on the right path. I download knoppix with Adriane, then I try to open it with utorrent (http://utorrent.com/downloads/complete?os=win).

OK, I'm in deep now.

utorrent takes Knoppix and pretends to open it. It's been 25 mins with no progress (0% downloaded). It should be clear by now that I'm just following directions, and am without a clue.

If I can DL Knoppix, what do I use to DO something with it? I need to burn it on a CD or flash, but it's on my computer as a .torrent. My computer doesn't know what to do with it.

Can I give up and just boot with a Windose CD (if I can find it)?

I really want to try to clean this thing out, if for no other reason than to learn, but I'm stuck. No huge loss if I have to wipe the HD, but I can't even do that with no workoing OS.

I bow to the wisdom of the offcamber.

Thanks!

grungex
08-06-09, 10:44 PM
You can boot with a Windoze CD, if you can find it.

If your BIOS isn't set to boot from CD before HD you might still be screwed, if the keyboard can't get you into the BIOS, or allow you to press whatever key you need to say you want to boot from CD (F1?).

Robstar
08-07-09, 12:12 AM
You can boot with a Windoze CD, if you can find it.

If your BIOS isn't set to boot from CD before HD you might still be screwed, if the keyboard can't get you into the BIOS, or allow you to press whatever key you need to say you want to boot from CD (F1?).

Pretty sure it's F2 to change the boot order thingamijiggie

redmist
08-07-09, 12:28 AM
if you can't fid your windows disk and can boot to cd drive you might try this http://www.ultimatebootcd.com/. i think there are some antivirus spyware tools on it. might give it a shot.

trish
08-07-09, 05:44 AM
I think if it detects a cd in the drive while you're booting, it asks if you want to boot from cd. Just put it in, turn it on and keep hitting the y key. Well, after you go and buy or borrow a proper keyboard.

dando
08-07-09, 10:00 AM
My contribution:

bZRh6sZZyz0

:gomer:

Srsly, after my laptop troubles, you need to get an OS CD. Either find your Windoze CD or find a way to get Ubuntu on CD to boot this sucker, and with a proper KB as well.

-Kevin

dando
08-07-09, 10:01 AM
I think if it detects a cd in the drive while you're booting, it asks if you want to boot from cd. Just put it in, turn it on and keep hitting the y key. Well, after you go and buy or borrow a proper keyboard.

That depends on the make and model. On a Dell (@ least my laptop), you need to hit F12 for the boot menu.

-Kevin

CQ
08-07-09, 10:14 AM
Once you've booted it with a disk, go to the MS website & download "Process Manager" & run it. This is more powerful than Task Manager & will allow you to shut down the spyware pseudo-A/V programs.

Then go to the Malwarebytes site (www.malwarebytes.org) & download their freeware version. It does not do real time monitoring, you'll have to buy the premium version for that, but you can manually run it & it will pull every known virus & spyware out of your OS & delete them. Very good stuff.

Good luck.

Kiwifan
08-07-09, 04:38 PM
Just started using Malwarebytes after reading an article in NZ PCWorld where a long standing columnist got bitten in a similar fashion to G. He suggested downloading the program as CQ suggested and then if something does happen it's already on your PC.

Good luck sport.

Insomniac
08-10-09, 02:50 PM
I'll second (I guess third) Malware Bytes. It found something nasty on a friend's PC that nothing else could find. (It disabled the Windows notification if the firewall/av are disabled and then quietly disabled the AV. She noticed something was off when sometimes the search result she clicked didn't go where she expected it to go.)

On uTorrent, is the torrent started? By default torrents aren't started.

TedN
08-11-09, 07:10 AM
Another thumbs-up here for MalwareBytes. Each time you're ready to run a scan, a couple of suggestions:

1.) click on the "updates" tab to download the latest updates
2.) then disconnect your computer from the Internet before running the scan

Ted

TrueBrit
08-11-09, 03:12 PM
I recently had a very nasty virus which mimicked the offical Windooze security centre..first thing it did was disable and then gut Malwarebytes....up 'til that point MWB had been brilliant...

Robstar
08-12-09, 12:51 AM
Either find your Windoze CD or find a way to get Ubuntu on CD to boot this sucker, and with a proper KB as well.

-Kevin

Or make a Ubuntu bootable USB drive (http://www.lifehacker.com.au/2009/07/usbuntu-live-creator-makes-bootable-linux-usb-drives/)...

G.
08-12-09, 11:53 PM
quick update: Got it to boot in safe mode, ran AVG & spybot to get rid of a lot of stuff. I can get the 'net, but I can't surf to such places as, say, malwarebytes.org or spybot update site, etc. They are blocked.

Installed malwarebytes from a CD I burned. It got rid of a lot more (26) but I am still unable to get updates (ran the scan with the definitions the install file came with).

Running rootrepeal right now, we'll see if it finds a bogus rootkit.

FYI, I did eventually get the Knoppix torrent to un-torrent itself, I just needed about 16 hours of patience. I THINK it needed to share my file before it let me USE my file, but I am stupid, so who knows. I DL'ed a free ISO recorder (cleverly named "ISOrecorderV2"), but never got that to run.

Still Linux-free, but bootin', at least.

I still want to play with Linux (I'll try the thumbdrive version, but I wanted Knoppix dammit!)

Yes, I found my corded keyboard. Forgot I even HAD one. And I found a copy of Windows, so I can nuke the thing if I have to.

Can someone explain to me why computers don't give you CDs anymore, but they have you back up your OS on the same fricken HD that is going to crash?? I even got smart :gomer: and backed my OS onto an add-on HD that I shoved in there. I'll try that one if it comes down to re-formatting, but WTF!

Thanks, all. I'll let you know how bad I screw this up. I mean, rootkit, rootcanal, roto-rooter, all stuff that you can do yourself, right?

Insomniac
08-15-09, 11:48 AM
Can someone explain to me why computers don't give you CDs anymore, but they have you back up your OS on the same fricken HD that is going to crash?? I even got smart :gomer: and backed my OS onto an add-on HD that I shoved in there. I'll try that one if it comes down to re-formatting, but WTF!

My best guess is to save a bit of money and to then offer you CDs for $20 after they take some of you HD space for the original image. I think most now let you create a backup from the image on your own blanks.

G.
09-13-09, 01:43 AM
Spent too much time learning about Linux and stuff. Don't have much spare time, so I went for the nuke route (nothing irreplaceable on the HD).

Blasted in XP, wiped the friggin slate clean. Yay! I'll have this running in NO TIME!

Loaded a few more free sweeper things (one was Avast, just so my boot up takes extra long :gomer:).

Things looking good, sweeps were clean, started loading up FF, all the virii stuff, etc.

Found the source of the nasty. It's called Virut or Vitro (I got Vitro, but it's from the same ****ing Ukraine ***holes).

Basically, you have to clean it with fire. :flame: Reformat, repartition, regurgitate, reanimate, whatever. It can be cleaned off, as long as you don't run any .exe programs (including installing Windows) or surf the net.:\

A little more searching, but it might be new HD time.

(note: I was mainly "clean" after the install, at least for a little while, then I got "smart" and cleaned my 2nd HD, used for backup and game installs. See, a funny thing happens when you run any .exe on an infected computer - it wakes up and goes back to work.)

oddlycalm
09-13-09, 03:49 PM
Sorry to hear about the pain G. I hope there's a special ring of hell for the pukes that spread this stuff.

oc

cameraman
09-13-09, 09:53 PM
A little more searching, but it might be new HD time.

If you do a low level format that zeros the entire disk having booted from a cd you should be okay. You won't need to buy a new drive. thing is every single .exe file on that computer is infected and nothing can be reused. Every application has to come from the original cds or re-downloaded.

Hard Driver
09-14-09, 10:00 AM
quick update: Got it to boot in safe mode, ran AVG & spybot to get rid of a lot of stuff. I can get the 'net, but I can't surf to such places as, say, malwarebytes.org or spybot update site, etc. They are blocked.

Installed malwarebytes from a CD I burned. It got rid of a lot more (26) but I am still unable to get updates (ran the scan with the definitions the install file came with).

Running rootrepeal right now, we'll see if it finds a bogus rootkit.

FYI, I did eventually get the Knoppix torrent to un-torrent itself, I just needed about 16 hours of patience. I THINK it needed to share my file before it let me USE my file, but I am stupid, so who knows. I DL'ed a free ISO recorder (cleverly named "ISOrecorderV2"), but never got that to run.

Still Linux-free, but bootin', at least.

I still want to play with Linux (I'll try the thumbdrive version, but I wanted Knoppix dammit!)

Yes, I found my corded keyboard. Forgot I even HAD one. And I found a copy of Windows, so I can nuke the thing if I have to.

Can someone explain to me why computers don't give you CDs anymore, but they have you back up your OS on the same fricken HD that is going to crash?? I even got smart :gomer: and backed my OS onto an add-on HD that I shoved in there. I'll try that one if it comes down to re-formatting, but WTF!

Thanks, all. I'll let you know how bad I screw this up. I mean, rootkit, rootcanal, roto-rooter, all stuff that you can do yourself, right?

Sounds like you got a nasty rootkit.

Download the Sophos rootkit remover:
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

Run this in safe mode. If it finds a bunch of files that begin with UAC... delete them all, no matter what it says if they are safe or not.

Then run MalwareBytes twice.
Then run Spybot Search and Destroy.
Then run Superantispyware.

Methanolandbrats
09-14-09, 10:09 AM
[QUOTE=G.;261100]

Can someone explain to me why computers don't give you CDs anymore, but they have you back up your OS on the same fricken HD that is going to crash?? I even got smart :gomer: and backed my OS onto an add-on HD that I shoved in there. I'll try that one if it comes down to re-formatting, but WTF!

QUOTE]

Best way around your scenario or the typical drive failure is to only keep the OS and programs on the boot drive. Put your data on another drive or two. Then have an exteral drive (s) to back up the drives in the computer. Buy Acronis and clone your boot drive to an external on a regular basis. If the boot drive gets infected or fails, just format or replace it and clone it back.
Copying your internal data drives is a simple copy, so it's easy to keep up with that.