Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 22, 2013, 06:37:40 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663621
Posts
70564
Topics
145222
Members
Latest Member:
TimmEDK
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
MBR Trojan need some help please !
« previous
next »
Pages:
1
[
2
]
Author
Topic: MBR Trojan need some help please ! (Read 17122 times)
_The_Nothing_
Newbie
Offline
Posts: 12
Re: MBR Trojan need some help please !
«
Reply #15 on:
December 30, 2011, 02:59:13 AM »
yes this is true ,but the reg shot shows it in red and when I use regedit to look for the reg files they are not there therefore I take that as they are super hidden files am I not correct, yes some micro$oft files are that way on purpose, so people don't mess their systems up and security I understand this much
Logged
wasgij6
Global Moderator
Comodo's Hero
Offline
Posts: 3061
Re: MBR Trojan need some help please !
«
Reply #16 on:
December 30, 2011, 03:03:19 AM »
if you do think you have a rootkit your best bet would be to create a bootable disk with kaspersky rescue disk. it makes things a lot easier to remove a rootkit when using a bootable environment.
Logged
| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
_The_Nothing_
Newbie
Offline
Posts: 12
Re: MBR Trojan need some help please !
«
Reply #17 on:
April 13, 2012, 09:54:11 PM »
sorry it's took awhile to get rid of and fix stuff just to get back on apparently I've been my WiFi has been hacked by someone in china I can't fix this one on my own so far
hacker 2012-02-29_030208.jpg
(168.82 KB, 1366x746 - viewed 14 times.)
hacker 2012-03-12_130858.jpg
(63.21 KB, 531x415 - viewed 12 times.)
Logged
MichelB
Comodo Staff
Comodo Loves me
Offline
Posts: 175
Re: MBR Trojan need some help please !
«
Reply #18 on:
April 27, 2012, 10:27:43 AM »
_The_Nothing_
First...
Change the username and password on your router.
Second...
Speak to your ISP and ask them to reallocate your public IP address
Third...
On a clean PC download UnHackMe from
http://www.greatis.com/unhackme/
save it to USB or burn it to CD
Fourth...
Install UnHackMe on the infected machine.Go through the "Check Me Now" and multi-engine virus scans. Reboot the system and let the RegRun do its thing. When UnHackMe get to the results page Do Not click "Fix Problems" - click Advanced View to show a list of hidden items, autoruns, BHOs etc. From that screen you should be able to see any suspicious items and action them accordingly.
Fifth...
Be aware that in a lot of cases involving MBR infections it is safer (and usually a lot quicker) to buy a new harddrive, install everything from scratch on to it and then copy data, and only data, from the old harddrive to the new one.
Logged
_The_Nothing_
Newbie
Offline
Posts: 12
Re: MBR Trojan need some help please !
«
Reply #19 on:
April 29, 2012, 10:04:57 PM »
well I took your suggestion and got a new copy of unhack me mine was from 2008 which the rookit finder still works where they've disabled it on the new one . anyways lol I had to run combofix again to get back on I will post my results for you. I've narrowed it down to they've put some code in my wlan .exe or swapped it out for an fake one that's where the funny connection keeps coming from.
lol this is like the best chess game I've ever played lol it's kinda fun well at first it was really annoying but I gathered enough get off my computer programs to remove stuff with and now it's kinda fun they hit me with a bunch of malware and spyware and in a half an hour to and hour I'm right back on.
thanks for any help you can provide me with helping remove them
Wlan2012-01-30_025319.jpg
(125.15 KB, 1366x738 - viewed 12 times.)
hacker post2012-04-29_200705.jpg
(124 KB, 669x740 - viewed 9 times.)
hacker passworded 2012-04-18_142153.jpg
(50.78 KB, 420x472 - viewed 8 times.)
Logged
MichelB
Comodo Staff
Comodo Loves me
Offline
Posts: 175
Re: MBR Trojan need some help please !
«
Reply #20 on:
April 30, 2012, 04:07:49 AM »
You may have a revised version of this
http://www.securelist.com/en/descriptions/old21782865
.
I assume that you removed or disabled any rogue startup entries UnHackMe found?
Be wary of PC Tools AV stuff, it flags a lot of false positives.
If your wlan.exe file is suspect, rename it to wlan.exe.old and copy a fresh version off the OS installation CD.
Check your startup registry keys, listings under msconfig and services.
Without any browser windows open, do a netstat -ano from the command line and look for any outgoing connections to foreign servers and note the Process ID (it will probably be 0 which indicates that scvhost is corrupt). If the PID is not 0 trace the executable calling the process, rename the .exe file and replace it with a known good copy.
As I said, if this is an MBR rootkit/bootkit you will be better of scrubbing the drive and re-installing from scratch. You could be hunting this thing down until kingdom come and still never be able to remove it.
Logged
EricJH
Global Moderator
Comodo's Hero
Online
Posts: 16703
Re: MBR Trojan need some help please !
«
Reply #21 on:
April 30, 2012, 08:38:21 AM »
Quote from: _The_Nothing_ on April 13, 2012, 09:54:11 PM
sorry it's took awhile to get rid of and fix stuff just to get back on apparently I've been my WiFi has been hacked by someone in china I can't fix this one on my own so far
What in the screenshots you provided makes you think your WiFi has been hacked?
Assuming the HPWAMain.exe is digitally signed I advice to see if the digital signature is OK. If it is OK then it is the original program from HP and not an infected version.
«
Last Edit: April 30, 2012, 08:43:49 AM by EricJH
»
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
_The_Nothing_
Newbie
Offline
Posts: 12
Re: MBR Trojan need some help please !
«
Reply #22 on:
May 01, 2012, 02:03:36 AM »
sorry for the spydoctor pic. I didn't mean to post that one and couldn't edit it.
um well I've been fighting this for about three years. and when I bought this dumb thing it didn't come with a disc. I made a windows recovery disc awhile back when they released an ISO of it so I got it thats about all I've got to work with
hacker hp 8 2012-04-21_225534.jpg
(247.07 KB, 1366x746 - viewed 12 times.)
hacker hp 2012-04-15_081656.jpg
(175.99 KB, 1366x746 - viewed 10 times.)
hacker passworded 2012-04-18_142153.jpg
(50.78 KB, 420x472 - viewed 9 times.)
Logged
MichelB
Comodo Staff
Comodo Loves me
Offline
Posts: 175
Re: MBR Trojan need some help please !
«
Reply #23 on:
May 01, 2012, 03:19:53 AM »
"I've been fighting this for about three years"... why?
Solve your problem -
http://emea.microsoftstore.com/uk/en-GB
- get on with life.
BTW: 169.254.x.y is an APIPA address which Windows allocates itself when it not being given an address by a server or a router. This is not an indication of an infection and is fixed by giving yourself a static IP address.
Logged
EricJH
Global Moderator
Comodo's Hero
Online
Posts: 16703
Re: MBR Trojan need some help please !
«
Reply #24 on:
May 01, 2012, 10:45:04 AM »
The IP address in the 169 range means that your computer does not see a network. When Windows does not see a network it will give the network card an IP address in the 169 range so it will have an IP address in case you want to make an ad hoc connection to another computer.
Getting an IP address in the 169 usually indicates a problem while connecting to a router; think a faulty wire or a lot of radio signals of neighbours interfering with your WiFi.
Did you check the digital signature of the HP program?
What version of Windows are you using?
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 5575
Re: MBR Trojan need some help please !
«
Reply #25 on:
May 01, 2012, 06:19:42 PM »
How to Clean An Infected Computer
Please let me know if following the advice given here is not enough to remove the malware. The instructions for how to make sure all malware has been removed can be found in my article about
How to Know If Your Computer Is Infected
. Please let me know if the methods suggested are not able to fully remove the infection, as I am trying to design the instructions such that they can remove almost any infection.
Once the infection has been removed please see
this topic
.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
_The_Nothing_
Newbie
Offline
Posts: 12
Re: MBR Trojan need some help please !
«
Reply #26 on:
May 12, 2012, 03:30:41 AM »
sorry it takes so long to get back to everyone
THANKS a million for all your patience's and time
well here it goes logs and pics
will look into that kaspersky link and check out more of this mess lol
unsigned 2012-05-02_031524.jpg
(58.26 KB, 387x449 - viewed 12 times.)
MiniToolBox by Farbar.txt
(22.66 KB - downloaded 2 times.)
regrunlog.txt
(385.33 KB - downloaded 2 times.)
Stack Data.txt
(0.59 KB - downloaded 1 times.)
unsigned files2012-05-02_031418.jpg
(58.53 KB, 600x600 - viewed 13 times.)
ComboFix.txt
(11.01 KB - downloaded 1 times.)
Logged
Tags:
Pages:
1
[
2
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.048 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com