am i being watched ?

hi, it’s been a while. yesterday i was at my station at 6.00pm when avast alarm sounded. checked i the chest to see what i had captured and was surprised to find a few captures of the past week or so. i must’ve been out when they came in. anyway, i am still not wholly satisfied avast5 has prevented whoever is responsible for these hacks getting into my computer. i also downloaded hijack this (i’ve no idea if it’s set up proper but i managed to get a log of sorts. couldn’t see anything suspicious though. is it okay to post the logs on here (they have been cropped. ) gordon.

http://i36.photobucket.com/albums/e1/ghola_warrior/Screenshot-13_07_201019_11_55-1.jpg

Give us your log as an attached txt file,

pol

I suggest:

  1. Clean your temporary files.
  2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
  3. Use MBAM (or SUPERantispyware or even Spyware Terminator) to scan for spywares and trojans. If any infection is detected, it is better and safer to send the infected file(s) to quarantine (Chest), rather than simply deleting them.
  4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
  5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
  6. Clean your Hosts file (replacing it) with HostsMan tool.
  7. Disable System Restore and then reenable it again.
  8. Immunize your system with SpywareBlaster.
  9. Check if you have insecure applications with Secunia Software Inspector.

hi pol, best i could do was send attached screenshots via email to virus@avast.com

i’m using windows 7 64bit, and have spybot, mbam already in use. started using hijackthis just yesterday and it needs some configuring. will try the other suggestions you made. thanks,gordon

superantispyware clean up completed.

i just remembered i bought a load of games from steam on the 2nd of july and started playing them on or around the 6th of july. could that be the cause ?

ran avast anti root kit yesterday, wasn’t much to worry about.
ran ad aware today and received this

http://i36.photobucket.com/albums/e1/ghola_warrior/Screenshot-14_07_201022_37_06.jpg

i notice it says BT. I CHANGED MY internet provider from BT to SKY 2 months ago.

my guess is avast is blocking these attempts to hack into my computer, every day at 6 or 7 pm (therefore they must be automated and slightly less to worry about. computer seems to be running fine, but i still suspect i am being spied upon.

Are you using avast firewall?

Did you follow steps on reply #2?

sorry mate, i’m computer illiterate. could not get the log file pasted in. i’m a motor mechanic ;D

i did send screenshots of hijackthis to virus@avast.com.

just hoping ad aware sorted it. will update tonite at 1900 hrs…

I really doubt that the email is correct for getting support.
I’m not an expert on HijackThis.
There are automated analysis here: http://hjt.networktechs.com/

You can find more info in the links of the last column of this table.
That info could guide you on the cleaning process.
Anyway, if you have doubts, just post here.
Also, take a careful look at the first column of the table:

  1. If you don’t recognize a legit program in one of the items marked as FIX IF UNKNOWN, please post it back here and maybe we can help you. Or, if you’re sure it’s a malware item, you can remove it as posted bellow.

  2. If you agree with the automatic classification of the infected items marked as FIX (CHECK NOTES!), you can turn back to HijackThis program, check the box of this item and then remove it using the button ‘Fix checked’.

Hope it helps.

If you want to do it by yourself, click here to download HJTsetup.exe

[*]Save HJTsetup.exe to your desktop.
[*]Doubleclick on the HJTsetup.exe icon on your desktop.
[*]By default it will install to C:\Program Files\Hijack This.
[*]Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
[*]Put a check by Create a desktop icon then click Next again.
[*]Continue to follow the rest of the prompts from there.
[*]At the final dialogue box click Finish and it will launch Hijack This.
[*]Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
[*]Click on “Edit > Select All” then click on “Edit > Copy” to copy the entire contents of the log.
[*]Come back here to this thread and Paste the log in your next reply.
[*]DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

:smiley: it has gone. ad aware found it, and avast blocked it from further attacks. amazingly the only 2 programs i am paying for.

http://i36.photobucket.com/albums/e1/ghola_warrior/Screenshot-14_07_201022_37_06.jpg