[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

I think I got hacked yesterday and I need some help. Here's

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 57
Thread images: 9

File: 1481292128168.png (3MB, 2000x1351px) Image search: [Google]
1481292128168.png
3MB, 2000x1351px
I think I got hacked yesterday and I need some help. Here's how it went down

tldr I need 1) advice and 2) a new w7 iso from a reliable source. Please provide details of where you got your iso from and how you know it's trusted. This probably isn't the best place to ask but I'm looking everywhere I can)

>night before
>reinstalled a few games and updated nvidia drivers
>yesterday
>browsan yt, working in docs in other monitor
>kb+m stops working, capslock still noticably working
>comes back to me in 2 minutes
>suddenly, all the windows close out
>then the taskbar disappeared. Nothing but a wallpaper
>spooky-ass pop up message
>"stop what you're doing i'm in control"
>"hello."
>at that very moment i was spooked as fucking hell and immediately powered off my PC and disconnected my ethernet
>rebooted and ran malwarebytes. Killed 88 trojans
>i'm still suspicious as hell about whether I was actually hacked or not in the unironic sense
>reconnected with ethernet for the past 12 hours. Nothing suspicious so far but this is suspected hacking we're talking about

I need a new w7 iso i think. I don't have the slightest clue how this "guy" got to me. So far my friends say it's probably the w7 iso i got (source is on the installgentoo wiki's w7 page), and I'm probably going to run DBAN and reinstall. Where can I find w7 iso's? A google search is NOT helping at all, just like how it was when I initially installed, which is why I request for any advice and sources for w7 here. Thanks for reading this post
>>
https://www.microsoft.com/en-us/software-download/windows7
>>
http://windowsiso.net/windows-7-iso/windows-7-download/home-iso-7/

Try the torrent on this page. I haven't tried it yet so not sure if anyone is seeding.

When downloading it, google the file name and add "sha1" to it. The number should match multiple sources on the net to the real untouched iso.
>>
>>346127
>>346132
Ideally you should validate the SHA1 against the list on MSDN, and before installing delete your EFI system partition if you're on EFI or "bootrec /fixboot" and "bootrec /fixmbr" if you're on legacy.

Windows 7 doesn't have SecureBoot, so it's easy to persist a trojan in the MBR, VBR or EFI system partition.
>>
File: asdf.png (818KB, 933x342px) Image search: [Google]
asdf.png
818KB, 933x342px
>>346138
Translate for me, a not well-rounded one with ISO's, o wise anon

Also, pic related is what I installed recently if anyone wants to know. I have high suspicions on that PPAPI and NPAPI since I don't remember either of the two
>>
>>346140

Which version of Windows do you have? ultimate? home? home/premium?
>>
>>346144
Ultimate x64
>>
>>346145

Download that. WHen it finishes check if the md5 matches this http://hasibul.info/blog/2015/04/12/download-windows-7-iso-updated/
>>
>>346148
I can't find Ultimate on the link that >>346132
posted, but I'll be sure to check with the premium x64 version

Downloadan rn
>>
>>346150

>X17-59465.iso: Windows 7 SP1 Ultimate (x64)
http://msft.digitalrivercontent.net/win/X17-59465.iso
Mirror: https://googledrive.com/host/0ByXszuHgPs8ubkpHRFhqY3ZGZnc

It's there unless I'm seriously fucked up
>>
File: sdfsdfds.png (96KB, 1366x736px) Image search: [Google]
sdfsdfds.png
96KB, 1366x736px
Both sources are dead, the digitalriver one just loads to M$'s homepage
>>
>>346156

Damn, I forgot to give you the link like 4 posts ago. Use this https://drive.google.com/file/d/0B_FIX0Fzt36eSE1wdnZodGMzTDQ/edit and THEN when you download it match the MD5/sha1 to the ones on that blog page.
>>
File: roboky.png (6KB, 525x133px) Image search: [Google]
roboky.png
6KB, 525x133px
Oh, you gave me professional version. Fuck it, this will be fine

Going to try installing it. Seems legit so far
>>
>>346169
Use "ei.cfg remover", and it will ask you whether you want Home, Professional, Ultimate, Enterprise, etc.

Professional won't accept your Home product key, so you'll need to either install Home or pirate it.
>>
>>346169
Derp, you said Ultimate.

You can use "anytime upgrade" to go from Professional to Ultimate, so just install without a product key then put your key into anytime upgrade when it's done.

You can't anytime downgrade so this only works in an upwards direction.
>>
>>346140
NPAPI and PPAPI are just browser plugin standards. PPAPI is a vaguely-updated version of NPAPI; the other common one is ActiveX.
>>
>>346140
All the best trojans hijack your bootsector then trojan your windows installer (or your new windows the first time it boots) so that reinstalling windows doesn't shift them.

You need to either blank the disk, or delete the MBR (the bootsector for the drive) and the VBR (the bootsector for the partition); or if you're using UEFI instead of Legacy, you need to wipe the EFI system partition (which is a 100MB partition the BIOS uses to load drivers and OS loaders from).
>>
In the process of backing up data from my PC to a laptop, I had to turn off my PC and now the machine's fans won't turn on and thus the machine itself. I'll be bumping this thread from now on until I get this issue fixed

Thanks for the help so far, I'll come back soon
>>
Alright cool I fixed the issue eith booting. Apparantly

>>346187
Yeah I'm going to do a total wipe of the entire hard drive soon, that included. Although, explain to me how to delete the VBR. I recall wiping the MBR last I downgraded to w7 initially, but I'm not too sure about VBR
>>
>>346203
The VBR is just the first sectors of the partition. Anything that wants to boot the partition loads the VBR and runs it. Windows' MBR always scans the partition table for a partition with the "Active" flag then boots the first one it finds.

Shift-f10 at any point in the installer gets you a command prompt, and "bootrec /fixboot" will overwrite the boot sector and bootloaders in the partition that the Windows MBR will try to boot.
>>
Hacker anon could have got your password and banking info too. Would stay away from torrents, it's the only way I've encountered viruses and malware and I'm pretty careful.
>>
>>346230

I suggest you and OP using Sandboxie.

>inb4 shit can still slip out
>inb4 virtual machine is better

I use Sandoboxie when I live dangerously because it's a lot less of a hassle than running an entire VM and it's better than running sketchy shit out in the open just because
>>
>>346230
I already got that covered as soon as I shut off my pc after the popup message. Also I live off of prepaid cards. I'm not torrenting it, I'm using the one provided the anon with the google drive link
>>346231
I'll look into this after I get settled with everything. I might end up using this after what happened
>>
>>346248
Whether you torrent it or not is not relevant: if it has the same SHA1 it is the same file.

If it has the same SHA1 as is listed on MSDN, then it is the same file as the one on MSDN no matter where you get it from.

Conversely, if you got it from a source you trust yet it doesn't have the same SHA1 as MSDN, then it is not the same file and you should not trust it.
>>
>>346251
This is all definitely true, but I actually already lost my original iso I used months ago

Maybe the one I used months ago really is trustful after all, but this still an "unpredictable hacker" I'm dealing with, so it's a good idea to reinstall and wipe shit. If I end up wasting time, then that's fine. Better to be safe than sorry
>>
>>346253

Definitely do like this guy said >>346181

All versions of Windows 7 are on every single disc. They're all just configured to default to a specific one.

If you remove the ei.cfg thing or whatever from any Windows 7 iso you will get a screen at install asking you to pick the version you want to install so you can choose to insatll Ultimate right away.
>>
>>346255
Actually I used MSToolkit for my "key" but surely there wouldnt be much of an issue with just using pro version, would there?
>>
>>346248
Depends on how long those Trojans have been sitting there, he could have been intercepting and tampering with your data long before spooking you with that message. Not saying he did, but you never know. I'd nuke the system and start over, resetting only your most important passwords along the way. Also you might consider paying for Malwarebytes Pro so that you've got real-time protection.
>>
>>346260

>MSToolkit

I used to use DAZ %100 of the time but now think if I were to go back I'd just use KMSpico.

If you Have a legitimate serial DEFINITELY WITHOUT A DOUBT go that route. That's my advice. If I had a key I'd go through the trouble of making the "Ultimate" disc and then installing with your key.

Nobody knows for sure what's in these OS activators. I just use it because reputation wise some of them are sworn on and either way I'm not paying for a copy of Windows every couple years or every time I build a new pc.
>>
Finally finished transferring files. That took a while

>>346261
Installing DBAN as we speak. I'll consider buying malwarebytes but I'm not in the situation in life to do that as of now unfortunately
>>
>>346270
Windows 10 is apparently the last Windows Microsoft will make, it's really too bad OP didn't install it while it was offered free for a year
>>
>>346368
It's not that big a shame given you can run the media creation tool, do an install, and get a free upgrade.
>>
>>346381
you would need an activation key, it's like 50-60$ otherwise
>>
>>346406
No you don't, but carry on not googling it and looking stupid.
>>
File: iuyiuyiutiy.png (516KB, 763x386px) Image search: [Google]
iuyiuyiutiy.png
516KB, 763x386px
Just an update: woke up to work on shit again and found DBAN like this [pic related]
>>
File: 6-29.webm (2MB, 920x880px) Image search: [Google]
6-29.webm
2MB, 920x880px
get iso this way.
>>
File: win10act.webm (2MB, 1024x768px) Image search: [Google]
win10act.webm
2MB, 1024x768px
activate this way
>>
>>346435
like I'm gonna Google that
>>
test
>>
>>346580
Because if you don't find out you're wrong you get to not know you're wrong?
>>
Power outages suck man. I'm back and still can't run dban. Any ideas other than disable secure boot and since I already tried it? Z170-E mobo if anyone wants to know (asus)
>>
>>346593
I only know the official route, least amount of headache. OS hacks are taxing.
>>
>>346602

Why are you even using dban? Just delete all partitions when installing Windows and let it create new stuff.

No need to be super duper paranoid. Might as well throw away your motherboard. Your shit will install clean.
>>
>>346616
I need maximum assurance that everything is wiped. I'll take an alternative, so long as I don't have to have the thought of "he's still there" in the back of my head whenever I turn on my PC and look at porn or w/e
>>
>>346617

How are you running dban?. Can't you run Hiren't boot cd, they have a bunch of tools on there that are like fool proof. Just boot up with it and use what they got on there.
>>
>>346620
I've been using rufus and a USB. I'll check Hiren's soon. My power is being shitty again
>>
File: iuhdsfkhsdkfh.png (701KB, 789x478px) Image search: [Google]
iuhdsfkhsdkfh.png
701KB, 789x478px
My power is back yet again. Today's been wack, dude

>>346621
Hey I got DBAN to work with Hiren, Thanks for that, but the second I let it run I get this. I feel like something screwed up. Confirm?
>>
>>346665
Meant to respond to >>346620
>>
>>346665

Nah, looks good. I never used DBAN so not sure. Looks like it got wiped but maybe just letting you know some sectors couldn't be touched?.
>>
>>346606
There are no hacks.
It is the official route.
The fact you keep saying it doesn't work when it does is what's making you look like an idiot.
>>
>>346682
Well how could this possibly happen when DBAN is the OS and has exclusive access to the disk?
>>
>>346690

I think bad sectors is a physical error on the disk. I don't think any os can do anything do them.
>>
>>346688
you cannot use official Windows without an official key
>>
>>347138
The free upgrade deal still works, it's just the GWX campaign that's ended, and all you need to do is run setup.exe from Windows 10 media.

You could have tested this at any time in the past few days either by doing it yourself or by FUCKING GOOGLING IT.

You still haven't done this, and you keep saying it doesn't work when it does, and you are making yourself look like an idiot.
>>
>>347144
the upgrade only lasts for about a week or so then asks for a key
>>
File: mmmmmmmmmmmmmmmmmmmmmmmmm.png (440KB, 1280x1024px) Image search: [Google]
mmmmmmmmmmmmmmmmmmmmmmmmm.png
440KB, 1280x1024px
Alright I finally got shit to eork finally. Everything is back for the most part

Thanks everyone for your participation. Have a doodle. /thread
>>
>>347240
No, not only does it not expire, but it records a digital entitlement so you can clean install later and never have to enter a product key ever again.

Face it, you're wrong and you're clutching at straws. It's bizarre that you didn't just google it the first time you were shown wrong, and it's positively baffling the way you're doubling down on a position you can't possibly defend.
Thread posts: 57
Thread images: 9


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.