Possibly hacked please help!

Associate
Joined
15 Feb 2010
Posts
474
I left my PC on last night for the first time; did Avast scan and it found three infected files; all "Win32:Cybot-KI [Trj]" in file names:

"C\windows\SysWOW64\Kernal32.dll [Emul]"
"C\windows\winsxs...[Emul]"
"C\windows\SysWOW64\Kernal32.dll [Emul]"

I accidentally clicked move to chest; two of them went in there the other did not; it said cannot find file.Avst said you should do a boot scan to complete the operation; or something tot hat effect. I restarted to do full scans but then windows did not load properly. I am very concerned that someone hacked into my PC and left this backdoor or whatever on my PC (i did lock my PC with a password over night).

The only icons in the system tray are sound and network; no Avast or firewall icons. My mouse short cuts did not work apart from to documents disk. I cannot open action center or network and sharing. After a while action center says do you want to turn on avast, firewall etc i click yes i trust publisher but nothing happens. The avast service is "stopped" in task manager; and when i try to manually start it says "the operation could not be completed... the service did not respond to the start or control request in a timely fashion". The only non-Microsoft service running is nvida.

I recently install comado dragon browser when i try to uninstall any program it says "an error occurred... it may have already been uninstalled. With perfect disk it started the uninstall then "error 1719 windows installer service could not be accessed". Note i do not have system restore turned on

MSCONFIG seems to go to "selective boot up" automatically sometimes; i booted into normal mode but still get the issue and "normal mode" is still selected. I also tried safe mode but cannot open avast

I tried a repair install; it was a few seconds but that did not work; the first time it said repair operating system on D drive when it should be C; the second time it said C drive but said no problems were found.

I found a TEMP folder in C drive with note pads in there named the following:bcdinfo, bootfailure, disklayout, SrtTrail, SrtTrail

I am running windows 7, service pack 1, with Avast and zone alarm all updated. I am going to boot into another OS and full scan all the disks

1) So firstly were these false positives? Are there any portable sans i can run on the SSD OS? since i cannot load any of them when i boot

2) Secondarily how can i restore the files i put into the virus chest to see if that resolve my boot issue or any thing else?

3) How could this happen; i heard leaving your PC on over night is fine; i have anti virus and a firewall; as well as a router/hardware firewall. IS this just a coincidence that yesterday i left the PC on over night for the first time?

4) Also when/if i reformat how can i ensure the virus does not stay on the SSD; since i cannot write zeros to the drive or is it okay to do that due to security issue?

Pleas help Thanks
 
Last edited:
Back up your data, and reformat.

Sounds like too much of a mess to sort out.

As for protection, turn on your routers firewall, set a decently strong password on it, install a software firewall (I use Comodo firewall) and use an antivirus. (I use AVG free)

Keep windows uptodate as well.

Thats it.

Havent had any issues for years and years.
 
Last edited:
1) Ok it looks like it was a false positive; after doing scan disk it seems resolved. Guess just a horrible coincidence that it occurred the first time i left my PC on over night. Any one else have this issue with avast or can 100% confirm it was a false positive?

2) What extra security measures should i take; I have hardware firewall enabled, Zone alarm firewall, Avast AV running actively. And do scans with IOBITS anti malware and malwerebtes?

3) Are there any other non-standard scans/precautions i can take which scans for port holes, network vulnerabilities outside of windows etc; for example the Symantec online scan?

Thanks
 
1) Ok it looks like it was a false positive; after doing scan disk it seems resolved. Guess just a horrible coincidence that it occurred the first time i left my PC on over night. Any one else have this issue with avast or can 100% confirm it was a false positive?

2) What extra security measures should i take; I have hardware firewall enabled, Zone alarm firewall, Avast AV running actively. And do scans with IOBITS anti malware and malwerebtes?

3) Are there any other non-standard scans/precautions i can take which scans for port holes, network vulnerabilities outside of windows etc; for example the Symantec online scan?

Thanks


Nah. You got plenty of protection there.

Windows updates and obviously application updates isthe only out standing thing.
 
These are all good things to do, aside from that the best thing to do is to use caution when opening any executable file.

Even legit programs can install adware which would raise a flag on your AV, and then in theory could lead to it adding something to the chest which affects the program.

If unsure about an .exe scan it using a multi scanner like http://virustotal.com and run it on http://anubis.iseclab.org/

Failing that if you are still paranoid lol, you can use Wireshark or Fiddler to monitor all incoming/outgoing requests.
 
Boot in Safe Mode ***. I get false warnings all the time from keygens, cracks and java apps

Are you sure they are false warnings? It's pretty common to package such things with malware.

Anyway in addition to firewall and AV (not to mention common sense) if you can live without them uninstall Flash, Adobe reader and java. I've been running IE9 like this for months now and I don't miss them personally.
 
Yeah they false, even my vnc software is classed as a virus because of the remote access capabilities lol
 
Back
Top Bottom