PDA

View Full Version : Man in the middle attack, various sources infected.



Stephan1983
2013-11-17, 20:10
Hi,

I got some problems, but before I start a never ending story, please let me know what your experts need to see from me.

Looks like there is some hidden partition containing some image file, anyway, this guy is serving me in "Echtzeit".

Also it looks to me that he placed some Backdoor via Hardware (Bios)...
I got many log files, too much to handle so we better start together a new....

The SBSD Log file created via "Autostart" is to big to upload.... :(

Even splitted... OS (Win7 64bit) is several times new installed, actuall the SBSD updating process stop at emalware146....

Stephan1983
2013-11-17, 20:13
Thanks a lot for your Help!

Stephan

tashi
2013-11-17, 20:39
Hello Stephan1983, :greeting:

Please don't post HJT logs in the Spybot forums, thanks :-) (http://forums.spybot.info/showthread.php?1266-Please-don-t-post-Malware-logs-in-the-Spybot-forums-thanks-))

Is this a personal computer? :)

Best regards,

Stephan1983
2013-11-18, 04:52
Okay, never ever again. :)

Personal Computer, hmmm ... i think so, but Homeoffice will met also.

No Server, No Administration Specials needed or used by my side, I`m using Win7 64 bits Home Premium. ;)

Got some nice fresh Screenshots :D but upload don`t work actually from my Computer... :(

http://www.fotos-hochladen.net/view/k640tuneup11duoz7vxlk.jpg
http://www.fotos-hochladen.net/view/tuneup2wu8ljhfv6r.png
http://www.fotos-hochladen.net/view/k1024top100ifhspynqjv.jpg

Thanks a lot,

Stephan

tashi
2013-11-18, 06:18
Hi Stephan1983,

Someone can take a look at the system if you start a topic in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise when available. :)

If you'd like to do that see the forum FAQ which also includes instructions in post #2 on how to provide DDS and aswMBR logs, which are used in the preliminary analysis.

http://forums.spybot.info/showthread.php?t=288

Best regards.

Stephan1983
2013-11-19, 09:01
Hello again.

One more question....

At this point there are no files to keep on my pc. Should I start the topic with "new installed" Windows7?

May be it is to much work for less, I think some qualified tool to erase all hidden files on my SSD could be fine also... :( :D



Greetings

tashi
2013-11-19, 17:41
Hello Stephan1983,



At this point there are no files to keep on my pc. Should I start the topic with "new installed" Windows7?

May be it is to much work for less, I think some qualified tool to erase all hidden files on my SSD could be fine also... :( :D


Volunteer analysts help with infected computers so it's up to you. :)

Kind regards.

Stephan1983
2013-11-21, 23:53
Okay, thanks a lot!

I start a thread at: http://forums.spybot.info/showthread.php?69759-Spyware-Malware-%28MITM%29&p=447264#post447264


bye