1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Possible Hack and User Account

Discussion in 'Security and Privacy' started by flynempire, 2010/05/17.

  1. 2010/05/17
    flynempire

    flynempire Well-Known Member Thread Starter

    Joined:
    2009/10/21
    Messages:
    90
    Likes Received:
    1
    Hello, I don't know if this is the correct section to post this but I will anyways.

    A customer of mine seems to have been hacked from what I could tell but scans with Avira AntiVir latest Version, Malware Bytes Latest and Threat Fire latest come up clean.

    The reason I say hack is that his user account was locked out. An account called Support was the only thing showing up on the welcome screen. I tried to get in with the Administrator account and that had a password added and that never did have one.

    What fixed everything was a Linux boot CD which loads a text based option menu and I was able to restore his account again with Admin Privileges and I disabled Support. So, does this sound like a hack?

    He would never do this to himself and he says no one uses the machine but him. No virus, spyware or Rootkits found.

    I must mention one last thing. I took the Support account and renamed it to test. I also gave it a password. It is still disabled. I try to delete it though and get an error message that the account name is not a member of the local group.

    I really want to delete this. Does anyone have a method of doing this? The machine is still working well for now.


    Mike
     
  2. 2010/05/18
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    Mike, you don't say what operating system this is but I found this on the MS website. I hope it's helpful

    Mitch
     

  3. to hide this advert.

  4. 2010/05/18
    flynempire

    flynempire Well-Known Member Thread Starter

    Joined:
    2009/10/21
    Messages:
    90
    Likes Received:
    1
    Sorry should have mentioned that. He is on XP Pro SP-3
     
  5. 2010/05/18
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    No, it does not.
     
    Arie,
    #4
  6. 2010/05/19
    flynempire

    flynempire Well-Known Member Thread Starter

    Joined:
    2009/10/21
    Messages:
    90
    Likes Received:
    1
    The same thing occurred today. His user account is disabled and on the welcome screen it shows an account called support and you need a password to long on. I feel he has a rootkit . Right now I have the disc out of the machine and I am scanning with 3 different Anti-Rootkit programs.

    This is not normal, that is for sure. I have to use a special Linux cd which allows me to enable his account and set him to admin again outside of Windows. Once I am in, I cannot delete this Support account. It says error not part of local group.
     
  7. 2010/05/19
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    This is far beyond my allowable expertise. Since the system has SP3 the link I provided above probably doesn't apply. Hopefully someone with the necessary qualifications will jump in here or you can try posting in the Malware and Virus Removal forum
     
  8. 2010/05/19
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
  9. 2010/05/21
    flynempire

    flynempire Well-Known Member Thread Starter

    Joined:
    2009/10/21
    Messages:
    90
    Likes Received:
    1
    The problem is still going but it is not the login screen anymore. I have shutdown and started up the machine 10 times today and I always get to the login screen with his user account.

    The problem now is the antivirus programs I put in are having their guards disabled and then the update module is corrupt. This happened with Avira and MSE. Something hidden is breaking these programs unfortunately.

    So let me ask you this. I want to wipe out the partitions, format the disk and install everything again. I will backup everything first.

    Anyhow if a Virus or Rootkit embedded itself deep in the system or file system and if I wipe the partitions and format will the virus be gone for good?

    That is all I want to know. This is the first time I have come across this problem before. I have dealt with all manners of Virus, etc. This is new and has stummped me. A Google search did not produce any results for 'User Account Named Support'


    Mike
     
  10. 2010/05/21
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    I think you should do as Arie suggests. My concern is if whatever is causing your problem is hidden in a file you backup you would be in a pickle. I am sure a Nuke and Pave would take care of the problem. But why not let the Malware Experts give it a whirl.

    Mitch
     
  11. 2010/05/21
    flynempire

    flynempire Well-Known Member Thread Starter

    Joined:
    2009/10/21
    Messages:
    90
    Likes Received:
    1
    The problem is I have done scans with 2 different anti-virus, 4 anti-spyware and several anti-rootkits and they all show clean.

    So posting the logs would do no good. What is Nuke and Pave?
     
  12. 2010/05/21
    flynempire

    flynempire Well-Known Member Thread Starter

    Joined:
    2009/10/21
    Messages:
    90
    Likes Received:
    1
    OK I know what it means now. Did not understand the Lingo :)
     
  13. 2010/05/22
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    My fault, I should have been clearer. Dispite what the "logs" show, the Analysts may see something in the logs requested at the top of the malware forum.
     
  14. 2010/07/17
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi flynempire
    Everyday Rootkits are getting harder and harder to detect, Everyday they find ways to hide from RootKit scanners.
    Scanners are always one step behind the RootKit inventors.
    Only a "trained malware specialist" will be able to find and remove the RootKit.

    Geri
     
  15. 2010/07/17
    DugE

    DugE Well-Known Member

    Joined:
    2002/09/10
    Messages:
    726
    Likes Received:
    3
    Flynempire, if you haven't already go to the malware section. Those guys know what they are doing and exactly what to look for.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.