New
#1
someone harvesting bitcoin on my laptop
Hello Everyone,
I was just informed on Malwarebytes forum that I was hacked and that someone is using my laptop to harvest bitcoin. My laptop hardware info is in profile. Experience terrible start time, lagging throughout everything, Mozilla experiences freezes and terrible lag. Working on becoming a Whitehat but still new to the whole ordeal so I am in need of serious help. Neither Avast nor M.S.E. were able to find anything. Spybot on the other hand found:
SweetIM: [SBI $A2B8532B] Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\priam_bho.DLL
SweetIM: [SBI $A2B8532B] Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\priam_bho.DLL
SweetIM: [SBI $9C9B9F12] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
I ran cmd.exe and here is my current tasklist:
Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 24 K
System 4 Services 0 2,916 K
smss.exe 400 Services 0 1,228 K
csrss.exe 556 Services 0 7,272 K
wininit.exe 600 Services 0 4,672 K
csrss.exe 624 Console 1 43,064 K
services.exe 660 Services 0 10,648 K
lsass.exe 680 Services 0 12,968 K
lsm.exe 692 Services 0 4,524 K
svchost.exe 800 Services 0 10,484 K
svchost.exe 892 Services 0 9,808 K
MsMpEng.exe 952 Services 0 78,460 K
winlogon.exe 1004 Console 1 7,216 K
svchost.exe 560 Services 0 27,512 K
svchost.exe 736 Services 0 157,236 K
svchost.exe 1036 Services 0 53,024 K
svchost.exe 1128 Services 0 5,468 K
svchost.exe 1160 Services 0 20,012 K
svchost.exe 1232 Services 0 33,016 K
AvastSvc.exe 1332 Services 0 3,996 K
spoolsv.exe 1448 Services 0 13,792 K
svchost.exe 1484 Services 0 17,248 K
armsvc.exe 1556 Services 0 3,828 K
svchost.exe 1588 Services 0 8,944 K
AppleMobileDeviceService. 1612 Services 0 9,088 K
ASO3DefragSrv64.exe 1700 Services 0 4,892 K
mDNSResponder.exe 1744 Services 0 5,968 K
svchost.exe 1776 Services 0 25,392 K
svchost.exe 1816 Services 0 3,904 K
LMIGuardianSvc.exe 1844 Services 0 6,888 K
ramaint.exe 1900 Services 0 5,696 K
LMS.exe 1924 Services 0 5,272 K
LogMeIn.exe 1948 Services 0 26,028 K
lxdqcoms.exe 1188 Services 0 6,068 K
taskhost.exe 2760 Console 1 11,608 K
taskeng.exe 2792 Console 1 7,460 K
dwm.exe 2884 Console 1 68,768 K
explorer.exe 2944 Console 1 148,704 K
msseces.exe 2512 Console 1 19,460 K
igfxtray.exe 2552 Console 1 7,576 K
hkcmd.exe 2812 Console 1 17,048 K
igfxsrvc.exe 2012 Console 1 7,496 K
igfxpers.exe 536 Console 1 10,060 K
IAStorIcon.exe 2556 Console 1 20,904 K
AvastUI.exe 3152 Console 1 16,796 K
sua.exe 3324 Services 0 3,948 K
TCPSVCS.EXE 3384 Services 0 5,224 K
svchost.exe 3472 Services 0 9,244 K
TODDSrv.exe 3584 Services 0 5,796 K
svchost.exe 3616 Services 0 10,024 K
SearchIndexer.exe 3640 Services 0 47,824 K
IAStorDataMgrSvc.exe 3732 Services 0 17,356 K
SMSvcHost.exe 3968 Services 0 22,552 K
NDSTray.exe 2856 Console 1 1,248 K
alg.exe 4220 Services 0 5,744 K
NisSrv.exe 4264 Services 0 13,744 K
CFSwMgr.exe 4608 Console 1 528 K
KeNotify.exe 4776 Console 1 10,032 K
svchost.exe 4796 Services 0 17,844 K
ToshibaServiceStation.exe 5036 Console 1 64,860 K
wmpnetwk.exe 5052 Services 0 15,144 K
TMachInfo.exe 3208 Services 0 30,944 K
CFIWmxSvcs64.exe 4892 Services 0 4,520 K
CFSvcs.exe 3488 Services 0 2,996 K
UNS.exe 4352 Services 0 8,944 K
svchost.exe 2504 Services 0 5,216 K
ielowutil.exe 4068 Console 1 528 K
taskhost.exe 4216 Console 1 17,088 K
SpybotSD.exe 1880 Console 1 124,084 K
firefox.exe 3456 Console 1 326,896 K
notepad.exe 3008 Console 1 8,528 K
WUDFHost.exe 4256 Services 0 7,608 K
Speccy64.exe 3204 Console 1 50,716 K
WmiPrvSE.exe 1604 Services 0 16,512 K
WmiPrvSE.exe 5720 Services 0 28,592 K
WmiPrvSE.exe 6052 Services 0 10,888 K
Speccy64.exe 3576 Console 1 51,948 K
cmd.exe 5376 Console 1 3,820 K
conhost.exe 5288 Console 1 6,748 K
tasklist.exe 1888 Console 1 6,816
Not sure what to do from here or what to post. Please just point the way and I'll do whatever.
Thank you in advance