I was on earlier today. This is a much more serious issue, hence, a new question. I have been attacked by a hacker - he has control of my Norton Internet Security via the password. He set himself up as supervisor and I can't delete the program from any way. I have been freaking out all afternoon and finally got a friend to "let" me use her PC so I could talk to you and get programs I need. Everyone is extremely paranoid.
I can't begin to say how much I appreciate what you guys are doing! I did get the info about the 7 issues to deal with. Is it safe and will it work if I download those things on my friend's PC and then put on mine? After you read below, I hope you can tell me that I caught this in time. I need something to delete Norton on my PC so I can re-install it.
This hacker has placed all kinds of crap on my PC, but it still runs! I am determined to get this F......R! and hopefully not have to reinstall. I think he thinks I am really dumb, which basically I am, but learning fast! Pest Patrol found 16 pests, 2 slight risk and 1 medium risk -it was an exe file. He went in and removed Norton from start up - and, lucky me, I didn't notice for a couple hours. I am on DSL through a wireless connection that we just set up a week ago. Is the other PC at any risk if she goes online? I disconnected, just in case. We moved the computers into two separate rooms, before was through the networking modem in one room.
He set up another password for entering the PC and didn't do it as supervisor (so I wouldn't notice? I think) I deleted it. Also looks like he was using my printer for something - not sure, found a huge very weird file. I can't put everything here for you to see because most of it is on my PC. Probably doesn't matter. EXCEPT that after this is all over - I have quite a bit of data and would love to do whatever to go after this person. I feel so violated. He has been looking at all my files, I have a couple websites with tons of pictures on them that I did as a memorial to my son who died tragically. And I don't know yet about any financial concerns.
How did this guy get in? I had Norton virus and firewall updated and MacAfee SPAM killer for email. Everyone thinks I had something to do with it. Is that possible?
In my fear, I managed to leave some important stuff at home, rather than on disk. But I do have written down 2 files Pest Patrol found, and what it said:
SAVE NOW. This file can be executed. Quiksoft Corp. Located in C:\ windows/system32/emsmtp.dl
l It was placed there 10/13/2003. File desc: Easy Mail SMTP Object. Internal Name: Easy Mail. Original File name: emsmtp.dll
and---
Trogan Java Open Connection.
plus a bunch of spyware that it said was not dangerous.
I removed all Java programs from my PC, but one of them wouldn't fully delete. I used Add/Remove.
Thanks to all of you, I downloaded Hijackthis JUST IN TIME. Literally!
This is the last scan result:
Logfile of HijackThis v1.97.7
Scan saved at 4:31:57 PM, on 7/12/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Softex\OmniPass\OPXP
App.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\McAfee\SPAMKI~
1\MSKSrvr.
exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\snmp.e
xe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\PESTPA~1\Cooki
ePatrol.ex
e
C:\Program Files\Java\j2re1.4.2_04\bi
n\jusched.
exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ScanSoft\OmniPageSE\
opware32.e
xe
C:\PROGRA~1\McAfee\SPAMKI~
1\MskAgent
.exe
C:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv
.exe
C:\WINDOWS\System32\hphmon
04.exe
C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb07.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\Unload\hpqcmon.exe
C:\PROGRA~1\PESTPA~1\PPMem
Check.exe
C:\PROGRA~1\PESTPA~1\PPCon
trol.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\rundll
32.exe
C:\Program Files\Webshots\WebshotsTra
y.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Common Files\Real\Update_OB\rnath
chk.exe
C:\HIJACKTHIS\HijackThis.e
xe
C:\Program Files\PestPatrol\PestPatro
l.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.google.com/ieR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.google.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://us8.hpwis.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://srch-us8.hpwis.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://us8.hpwis.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://srch-us8.hpwis.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhomeR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://www.google.com/keyword/%sR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = 127.0.0.1;localhost
N3 - Netscape 7: user_pref("browser.search.
defaulteng
ine", "engine://C%3A%5CProgram%2
0Files%5CN
etscape%5C
Netscape%5
Csearchplu
gins%5CSBW
eb_01.src"
); (C:\Documents and Settings\Owner\Application
Data\Mozilla\Profiles\defa
ult\o95qf7
qa.slt\pre
fs.js)
O1 - Hosts: 64.12.152.18 search.netscape.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {82315A18-6CFB-44a7-BDFD-9
0E36537C25
2} - C:\Program Files\QuickSearch\QuickSea
rchBar3_28
.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-0
5D28BCF79F
5} - C:\HP\EXPLOREBAR\HPTOOLKT.
DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-9
0E36537C25
2} - C:\Program Files\QuickSearch\QuickSea
rchBar3_28
.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
3.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
nt\mcupdat
e.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\Cooki
ePatrol.ex
e
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bi
n\jusched.
exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD
.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
e
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\
opware32.e
xe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~
1\MSKDetct
.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~
1\MskAgent
.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hph
upd04.exe"
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon
04.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb07.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digi
tal Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMem
Check.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPCon
trol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\age
nt\mcregwi
z.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMo
n.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTra
y.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-
137903.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
3.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar
3.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar
3.dll/cmca
che.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar
3.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
3.dll/cmtr
ans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: ChatSpace Full Java Client 4.0.0.301 -
http://63.102.226.240:8000/Java/cfs40301.cabO16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cabO16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabO16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {08BEF711-06DA-48B2-9534-8
02ECAA2E4F
9} (PlxInstall Class) -
http://down.plaxo.com/down/release/PlaxoInstall.cabO16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2
407B42F57C
9} (MSSecurityAdvisor Class) -
http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1088957259375O16 - DPF: {231B1C6E-F934-42A2-92B6-C
2FEFEC2427
6} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yuccon
fig.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {2FC9A21E-2069-4E47-8235-3
6318989DB1
3} (PPSDKActiveXScanner.MainS
creen) -
http://www.pestscan.com/scanner/axscanner.cabO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsth
elper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cabO16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6
A52B394EC3
B} (WSDownloader Control) -
http://www.webshots.com/samplers/WSDownloader.ocxO16 - DPF: {9CF28A69-7659-4C51-BFD5-9
ADE19E19EC
3} (RegConfig Class) -
http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cabO16 - DPF: {A8658086-E6AC-4957-BC8E-7
D54A7E8A78
E} (SassCln Object) -
http://www.microsoft.com/security/controls/Sasser/20/SassCln.CABO16 - DPF: {BCC0FF27-31D9-4614-A68E-C
18E1ADA438
9} (DwnldGroupMgr Class) -
http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cabO16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-F
B9E207A39E
6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4349/mcfscan.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
87CAF3EE8C
6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabOMG, THANK YOU!