Announcement

Collapse
No announcement yet.

I got my game password stolen after downloading an infected file.

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • I got my game password stolen after downloading an infected file.

    I used Hijack this to do a scan and I spotted this process (highlighted in red) i dont remember it being there before, i deleted the file obviously and i closed the process, could it be part of the trojan or whatever the person used to steal my password? im worried it's still on my computer and i dont want to get another more important password stolen. AVG and Ad-aware have not come up with anything in full scans.


    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
    O4 - Startup: ord32.exe
    O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


  • #2
    Re: I got my game password stolen after downloading an infected file.

    Do you still have the file? You could have uploaded it for scanning at Virustotal.com and seen what it had to say about it.


    If you do not have it anymore, then you are out of luck for doing that though. I would have removed it as well as it does look suspect.

    Comment

    Working...
    X