Potential problem/situation, hacked?

Jsizzle

Member
Hey there,

This may be a problem or I may just be paranoid. Hopefully, the latter.
About ~10 days ago, I downloaded a file from the file hosting service "FileSonic". Once the download was complete, I tried to download another file sometime after the first file had finished downloading. I received a download error " Download session in progress." I was not downloading anything at that time and this was the first time I recieved that error. I read that this is an error that can occur occasionally. But it usually occurs if you are living in the UK (which I am not).
I am concerned someone could have downloaded something to my computer without me knowing. My question is, is the possible? If so how could I find out?


I run the Norton Security Suite w/ firewall. When I ran the Norton scan, theis is what came up:

Code:
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Downloader
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Downloader
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Trojan Horse
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Downloader
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Downloader
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Downloader
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved
 
 
Trojan.Gen
Type: Compressed
Risk: High (High Stealth, High Removal, High Performance, High Privacy) 
Categories: Virus
Status: Fully Resolved



All of these were in my Appdata\locallow\sun\java\deployment\cache folder. I don't think any of these could have downloaded a specific file off of FileSonic, I am more concerned that a person could have physically done this. Future scans show everything as clean. I also scanned with Malwares Anti-Malware, which showed everything as clean.

Thoughts?
 

My Computer

Clean your Java cache with ATF Cleaner Welcome to the Frontpage - www.atribune.org
Click "Main" > check 'select all' (except prefetch) this first time using it, then click "Empty Selected". Do the same for FireFox or Opera if you use either of those browsers.
Next, go to Control Panel > Internet Options.
On the General tab under "Temporary Internet Files" Click "Delete Files".
Put a check by "Delete Offline Content" and click OK.
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
My opinion is that something may have been downloaded and that you should take Jacees advice. She is an MVP in this area. If it turns out that it is not a download, we can resolve any other problem at that point. What Jacee is suggesting requires immediate attention, everything else can wait.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
I cleaned everything with the ATF Cleaner but I can't go to the normal Internet Options screen (its been this way for quite awhile). I can do the normal "Delete HIstory" but when I go to Internet Options, it acts as if I don't have a connection. But when I try to setup a connection I says I already have one.

I have included screen shots.
 

Attachments

  • 1.jpg
    1.jpg
    32.2 KB · Views: 38
  • 2.jpg
    2.jpg
    17.5 KB · Views: 35

My Computer

Was this what you were after? Earn $300 in 7days with Filesonic
Payouts
We pay weekly, every Friday, for the same week
We make payments to Paypal, Webmoney and ePassporte. Payments via bank wire transfer are available on request
Minimum payout is $15

Did you download a 'crack'?
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Let's clean up your DNS cache and restore MS's Hosts file

Copy and paste these lines in Note pad.
@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
Save as flush.bat to your desktop. Right click and run as Administrator.
Your computer will reboot itself.

Now, download Malwarebytes' Anti-Malware to your desktop
|MG| Malwarebytes Anti-Malware 1.46 Download
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location (desktop is fine). Copy and Paste that log into your next reply.
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Was this what you were after? Earn $300 in 7days with Filesonic
Payouts
We pay weekly, every Friday, for the same week
We make payments to Paypal, Webmoney and ePassporte. Payments via bank wire transfer are available on request
Minimum payout is $15

Did you download a 'crack'?


No, I don't know anything about that.
I was downloading a normal video file as a free user.

I'm running anti-malware right now, will post log when complete.
 

My Computer

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4595
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943
9/11/2010 7:49:27 PM
mbam-log-2010-09-11 (19-49-27).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 337593
Time elapsed: 1 hour(s), 30 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
 

My Computer

Please forgive me! I visit so many forums and I totally missed you :( :o

MBam doesn't show any malware. Tell me how your computer is acting.
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Please forgive me! I visit so many forums and I totally missed you :( :o

MBam doesn't show any malware. Tell me how your computer is acting.

Don't worry about it, no problem.

It seems to be ok.

I noticed a few things but I don't know if I'm getting overly suspicious.
Like a few days ago there was an extra tab opened in my IE and I was trying to remember if I opened it.
Another day I was looking at word documents on my computer, I opened mutiples ones at the same time and one was opened that I couldn't recall if I opened.
 
Last edited:

My Computer

Jsizzle, I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Right click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop, and run as Administrator.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
My computer tech told me that when you download anything, you will usually get a window that needs your approval to continue. If you click the accept button, you just downloaded your virus. Your antivirus software will not catch it because you just gave it permission to download. If this is the case...

Before downloading, save the file to your desktop and scan the file, remove viruses, then install. If it won't install, its because the virus was needed to install. If this is the case. Delete the file.

In your case, you will have to do what I did, take your hard drive into the geek squad (best buy) and get them to clean your computer. $200.00, but worth every dime, and neither of us will make this mistake again.
 

My Computer

Hi Debbie935, welcome to the Vista Forums
adios.gif


I'm trying to help Jsizzle. I work for free to clean up malware, so that no one has to pay the price you did by using Best Buy's "Geek Squad". ;)

Thanks for your reply to this matter, tho'.
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
My computer tech told me that when you download anything, you will usually get a window that needs your approval to continue. If you click the accept button, you just downloaded your virus. Your antivirus software will not catch it because you just gave it permission to download. If this is the case...

Before downloading, save the file to your desktop and scan the file, remove viruses, then install. If it won't install, its because the virus was needed to install. If this is the case. Delete the file.

In your case, you will have to do what I did, take your hard drive into the geek squad (best buy) and get them to clean your computer. $200.00, but worth every dime, and neither of us will make this mistake again.

The problem for me was that I was not downloading anything yet still got a message "Download in the progress." So I never got that confirmation window. You make a good point though.
Thanks for the reply.


Hi Debbie935, welcome to the Vista Forums
adios.gif


I'm trying to help Jsizzle. I work for free to clean up malware, so that no one has to pay the price you did by using Best Buy's "Geek Squad". ;)

Thanks for your reply to this matter, tho'.

I'm running the ESET scan right now...
 

My Computer

a041.gif
Yay!
How is IE acting? Do you have all the MS critical updates?
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
It seems ok, freezes every now and then, but Ive always had that.....

My only concern is that someone could be hacked into my computer and have access to it, to do whatever they please.....But with every spyware and malware program showing everything clean, running the Norton Security Suite w/firewall, and being on a secure network do I really have any reason to be concerned?
 

My Computer

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Back
Top