Is someone sharing Windows 7 with me?

nottaclue9

New member
Member
VIP
Local time
9:35 AM
Messages
456
Location
San Antonio, TX
So, this all came about when I found the FBI ransom Trojan horse greeting me a couple of mornings ago. With the help of a techie friend, we got the thing removed (I hope). It took two days.

To find out which site I'd visited that may have given me the virus, I checked my history once everything was up and running again. I found a list of sites I have never, ever visited on any computer at any time in my life. International singles? HAHAHA! Myanmar newspapers? Downloaded videos? Nope. Not my stuff. What does this mean? Is it dire?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
nottaclue9

Let's see something . Run this tool called DDS


Download



Double click the dds icon to run the tool.
Place a check next to attact.txt and click Start . When done, DDS will open two logs
DDS.txt
Attach.txt
Save two logs onto your desktop and upload them with your reply
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
I did as you advised, but I cannot paste the first document, and I don't know how to zip. My apologies. I call myself nottacule for obvious reasons! :o Are there other ways to let you know what the documents say?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
nottaclue9,

You do have a clue...that the ransomware was up to no good!! :)

Have you deleted your browsing history?
How to delete your browsing history in Internet Explorer 9

Also, to make sure the ransomware files were removed, please do the following (this is a short report):

Download RogueKiller:
Tlcharger RogueKiller (Site Officiel)

When you get to the website, go to where it says:
(Download link) Lien de téléchargement:
rendu2.png

Select the version without the x64.
Click the dark-blue button to download.
Save to the Desktop.

Close all windows and browsers.

Right-click and select: Run as Administrator

At the program console, wait for the prescan to finish. (Under Status, it says: Prescan finished.)
Press: SCAN

When done, a report opens on the Desktop: RKreport.txt

Please provide the RKreport.txt (Mode: Scan) in your reply.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
You don't necessarily have to visit the actual site. The malware can come in on third-party ads from a site that you did visit. Or you may have clicked on an innocent looking "Info Box" on a site. Many sites sell ad space and don't monitor the ads or the links. Even the server that handles the ads could have been hacked for a short time.
 

My Computer My Computer

At a glance

Windows 7 Pro-x64i7-2600 3.4GHz - 3.8GHz Turbo8Gb - 2x4GB, Muskin 991770 PC3-1333Integrated Intel HD 2000
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
My computer became hopelessly locked up, so I sent it away with the computer guy who found all sorts of infections. He explained these to me, but I cannot explain them to you as my eyes glazed over and my brain shut down. Apparently, there is something called a black hole back door virus? There were three primary infections, and yes. Someone else was using my computer. He "changed my identity" at sign-in, so as far as the person in Thailand is concerned, my computer no longer exists.

He ran a free spyware detection program before he had to leave, and I am now faced with deciding whether or not this is serious. Of course, I am asked to pay money to get rid of a "snap do" threat. What do y'all think?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
...so I sent it away with the computer guy who found all sorts of infections...

He ran a free spyware detection program before he had to leave, and I am now faced with deciding whether or not this is serious. Of course, I am asked to pay money...

Sent it away, he had to leave...you lost me. In any event, you do not need to spend any money to resolve the issue.

You can use some very basic detailed instructions to run a program that will remove the problem from your computer.

If you wish to go this route, do you have a clean computer available, and a USB pen drive?

Also, at this point, can you run RogueKiller as posted above? It will provide a stsrting point.

If you cannot run RogueKiller, also let us know.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
My computer became hopelessly locked up, so I sent it away with the computer guy who found all sorts of infections. He explained these to me, but I cannot explain them to you as my eyes glazed over and my brain shut down. Apparently, there is something called a black hole back door virus? There were three primary infections, and yes. Someone else was using my computer. He "changed my identity" at sign-in, so as far as the person in Thailand is concerned, my computer no longer exists.

He ran a free spyware detection program before he had to leave, and I am now faced with deciding whether or not this is serious. Of course, I am asked to pay money to get rid of a "snap do" threat. What do y'all think?
This "FBI ransom Trojan" is an "Identity Thief"! Do NOT pay any money :mad:.... If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.

Passwords should be changed by using a different computer and not the infected one, if not an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified of the possible security breech.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Great information you guys. Thanks very much. Will proceed as directed.

RogueKiller has been run on this computer. It did not catch "snap do," or "snap do" has been quarantined by the free spyware scan to con me into paying for its removal. Can I ignore this, or is it something serious?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Snap.do hijacks browser settings for Chrome, Firefox, and Internet Explorer. It needs removed!
Q 1. Which one of the browsers above do you use?
Need to know to help you remove Snap.do

Please go to Start > Control Panel > Programs
On the list of progrms installed on your computer, is Snap.do on it?
If so, click: Uninstall

Q 2. Can you please post the report from RogueKiller?
Need to see it also.

Q 3. Also, do you have a USB pendrive you can use to load a program?

Please provide the answers to the 3 questions above.

Thanks!
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
I can give you two answers:
1) Snap do isn't listed in my programs. Seems suspicious, huh?
2) The computer guy who ran RogueKiller was a paid person from a company. I have no way of getting the report.
3) No. Don't even know what that is. Sorry.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Nottaclude9

Number 3's question . Is do you have one of these ( image below )

pic001.jpg
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
On Q 2.

To make sure the ransomware files were removed, please do the following (this is a short report):


If it is not already on the Desktop, download RogueKiller:
Tlcharger RogueKiller (Site Officiel)

When you get to the website, go to where it says:
(Download link) Lien de téléchargement:
rendu2.png

Select the version without the x64.
Click the dark-blue button to download.
Save to the Desktop.


Close all windows and browsers.

Right-click the downloaded file and select: Run as Administrator


At the program console, wait for the prescan to finish. (Under Status, it says: Prescan finished.)
Press: SCAN


When done, a report opens on the Desktop: RKreport.txt

If not,press the Report button to get it.


Please provide the RKreport.txt (Mode: Scan) in your reply.


If there are any RKreport files on your Desktop, please post them.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
nottaclue9

Click on Go Advanced next to Post Quick Reply. Then click on Manage Attachments . Click Choose file locate the RogueKiller log then click on Upload .
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
nottaclue9,


Need to see the entire RogueKiller log!


Please follow the instructions by VistaKing to attach the report.

Or, open the RKreport on the Desktop, then, do the following:


  • Press the key Ctrl and A to highlite all the text of the report
  • With the mouse, right-click the highlited text and select: Copy
  • Come back here, press: Post Reply
  • Right-click the upper left corner of the blank area, an select: Paste
That should get the report on here.


Press: Submit Reply ;)
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
RK report.PNG
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
See if you can do the following:

Please download the Farbar Recovery Scan Tool
Select the 64-bit version.




Save it to your Desktop.
  • Double-click the downloaded file to run it.
  • When the tool opens click Yes to disclaimer.
  • At the program console check: List BCD
  • Press the Scan button.
  • FRST64 makes a log (FRST.txt) in the same directory from which the tool is run (Desktop).
  • Please copy and paste the FRST.txt in your reply. <<---
  • The first time the tool is run, it also makes another log: Addition.txt
  • Please post the Addition.txt in your reply also. <<---
Please post both reports instead of uploading an image.
The image is difficult for this old dog to read!! :cry:
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Downloading Farbar Recovery Scan Tool
I cannot copy the "addition.txt." I clicked on it to see if I would get another page, but none appeared. I cannot get the "Fix" button to work, either.
I am sorry to be such a problem!
:o
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64-bit, service pack 1Intel box core i5 4460Kingston Hyper X Fury BLK 1866 8GB 4x2
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium 64-bit, service pack 1
CPU
Intel box core i5 4460
Motherboard
Asus B85MECSM 1150
Memory
Kingston Hyper X Fury BLK 1866 8GB 4x2
Monitor(s) Displays
Samsung 23" wide-screen
Screen Resolution
1920 X 1080
Hard Drives
WD Passport, 1 TB
Case
Win Z583 Mini Tower w/ USB3.0
Keyboard
Microsoft ergo wave
Mouse
Logitech wireless
Antivirus
Bitdefender; Malwarebytes Pro
Browser
IE11
Back
Top