Think I've been hacked

XXDracoX

Honorable
Sep 3, 2013
82
0
10,640
I have windows vista ultimate 64 bit OS with antimalware (comodo) and all that crap that is supposed to help. I previously had avira today, but i uninstalled it because of the resource use on my low end system. I noticed today on my desktop, a file called setuplog. I open it up and here's what it says: 21:52:40 (5148-02776)========== 11/05/2014 ==========
21:52:40 (5148-02776)DUMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY LATEST KILLER
now i didn't make that and it wasn't there before. I'm guessing someone did remote access, and this doesn't bother me except that i have school docs that have my full name on em. Any advice would be appreciated.
 

Remixex

Reputable
Mar 18, 2014
808
0
5,360
reinstall antivirus, run an anti-malware /spyware program (malwarebytes), any strange stuff you see happening LIVE on your computer i would unplug it immediately from the internet, back up your most important files...best of luck
 
restart your computer, hit f8 load into safe mode with networking. Download malwarebytes, run a full scan. download an antivirus program, like AVAST! or AVG 2014-Free... run that with a full scan too.

Comodo is a well known FIREWALL not a well known antivirus... there is a difference between the two . you need an antivirus in addition to the firewall.
 

USAFRet

Titan
Moderator
Assuming you have another copy of critical docs elsewhere.....wipe and reinstall.
You could go through multiple levels of anytivurus and malware eradication.....but that's what I would do seeing someone type on my system in real time.
Wipe and reinstall.
 

XXDracoX

Honorable
Sep 3, 2013
82
0
10,640
Already did malwarebytes. Found nothing. I had avira until i switched to comodo. Comodo does have an antivirus. Will get rid of tunngle. I'm going to get teatimer up again i think. Took it down previously. I don't have these files backed up, but recently, U drive started denying me access and i couldn't change it. Could that be where the virus is?
 

XXDracoX

Honorable
Sep 3, 2013
82
0
10,640
I turned comodo HIPS on paranoid mode. Got teatimer going also.... Not sure if that's good or not.... I booted the pc up in safemode and noticed to csrss.exe processes running. Could that possibly be it coming on in safemode trying to disguise itself?
 

Icon1911

Reputable
May 19, 2014
3
0
4,510
Hi. The same file with the exact message appeared on my desktop on the 16th (2014/05/16). Something fishy is happening. Any ideas?


 

Icon1911

Reputable
May 19, 2014
3
0
4,510
Sorry, my details:
Windows 7 Professional 64 bit (latest patches)
McAfee Anti-virus (updated)
Inside corporate network


 

Thood196612

Reputable
Jun 1, 2014
1
0
4,510
Can you discuss what you downloaded/installed because I got the same problem installing unlocker.exe
I found a further link https://forums.malwarebytes.org/index.php?showtopic=149290 I think it happens when you have unlocker install there extra program called delta toolbar. If it was a different program you can verify by checking the creation date/time of both the program and the setuplog by right clicking to the property. Heard its a logger but I have nothing running in the background yet.