also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

Help with a HijackThis log

Discussion in 'Virus and Malware Removal' started by onacomputer1, Jun 3, 2007.

Thread Status:
Not open for further replies.
  1. onacomputer1 Newcomer, in training

    But when I was looking through the screenshot previews for all the photos it found on my memory card, it could have been taking secret screenshots of all of that? I really, really need to know if the spyware was able to take any screenshots. If I had someone look at my computer in person that was trained in computer security, could they be able to tell if the spyware worked? I sound like a broken record, but I really need to know..

    Thanks.
  2. momok Newcomer, in training

    Hi,

    To my best of knowledge, the screenshots are taken during configurable intervals, but unknown to us. So the possibility exists that your pictures were "seen" and taken by the spyware, or it might not have taken a screenshot at all during the time your were viewing your pictures.

    Please see HERE.

    I would suggest that since the images were highly sensitive, you take every precaution that you had in mind in case the screenshots did capture the pictures when you were viewing them.

    I wouldn't know if the spyware did work; Unless of course you had removed the infection before viewing your pictures.


    Regards,
    Your friendly momok =)

    This thread is for the use of onacomputer1 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. onacomputer1 Newcomer, in training

    So if the spyware did capture my pictures, who has access to those screenshots? Just some random person?

    Even after I executed the ComboFix txt thing, I'm still having problems.

    Today when I booted this computer, an error titled "internal window: svchost.exe" came up and said "The instruction at "0x00000103" references memory at "0x000000103". The memory could not be "written"." Click on OK to terminate the program. Click on CANCEL to debug the program.

    Then I tried to open firefox, and it froze my computer, and Windows Task Manager wouldn't come up either. So then I restarted the computer, and I got that message that I received when I first knew something was wrong that says "To help protect your computer, windows has closed this program." It was worded exactly like how I received it the first time.

    What should I do?
  4. momok Newcomer, in training

    Hi,

    You could have a windows problem.

    I would suggest that you do a repair via this thread HERE.


    Regards,
    Your friendly momok =)

    This thread is for the use of onacomputer1 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  5. onacomputer1 Newcomer, in training

    Hello,

    If I'm still getting the same error now as I was originally a couple days ago even after I removed those files with ComboFix, then can we be sure that the "Spectre" spyware was actually running/causing the problem?

    Also, does spyware need to go through a computer reboot to be "activated", because I hadn't rebooted my computer for the first time after the spyware being installed until AFTER I had used all the programs to look at my pictures, so that would mean I would be in the clear if that's true.
  6. momok Newcomer, in training

    Hi,

    Since your error refers to svchost.exe, a system process, I had reason to believe that your file might have been corrupted or damaged. Thus I suggested the repair.

    With regards to the reboot for spyware, no worries about that as your system logs show all startup entries and I've cleared them of the infection.

    PS. Have you followed my last set of instructions involving system restore?

    Regards,
    Your friendly momok =)

    This thread is for the use of onacomputer1 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Thread Status:
Not open for further replies.