Computer hacked. Very serious

Status
Not open for further replies.

luunnn

Commendable
May 6, 2016
4
0
1,510
Hello,

so basically, I was playing runescape recently and got into an online argument(nothing serious, the dude was trying to scam me and I told him to <<edited>> off) and about 10 minutes later I cant use my keyboard anymore. The virus starts typing my username and password ingame, so everyone can see, so I quickly shut down my computer.

I turn it back on, to download kaspersky antivirus, since I had a code laying around. When I want to type in my login information, the virus(?) starts typing thing that I said to the guy when I was in the argument, it was pretty creepy so I type in the box 'what is this? Why?' and I just get a response '<<edited>> off'. So now I disconnected from the internet, downloaded kaspersky and ran a full scan. It said that I had 2 trojans and that they were removed, but the virus is still on there. Even though I'm disconnected from the internet, everytime I go to safari it starts typing things I said ingame into my url, aswell as my password. It is scaring me a lot and I really want to solve this. Any help would be very appreciated.

Also, I am on an iMac.

Best regards,
Lun
 
Solution
1. Go back to an earlier Restore Point
(edit: I did not notice that you were on a Mac)

2. Go back to the drive image you made 2 days ago

3. Embrace the pain and reinstall

Ethanh100

Estimable
Jun 10, 2014
50
0
4,610
If your data is backed up, or you dont mind loosing everything on that installation, I would suggest going with a fresh install, do so by booting into the recovery partition. You can try to use antivirus programs, malwarebytes as suggested above, but it may not get you far. Just dont connect to the internet for now as personal security can be severely harmed at this point. If you need to install programs, just download it on another computer and put it on a flash drive to then install it on the infected machine.
 

luunnn

Commendable
May 6, 2016
4
0
1,510
Also, reinstalling the software is not an option here, sadly. I have files that are worth a lot of money and if I lose them I might be in big trouble. I also think that it might be a RAT infection.
 

turkey3_scratch

Estimable
Herald
Jul 15, 2014
571
0
5,210


And you didn't backup your files?
 


Unfortunately if you have files worth a lot of money and no backup of them, this is likely to be an expensive lesson for you to learn. Important/valuable files = files that should be backed up.

Did you have any anti-virus/anti-malware programs installed & running at the time? It seems odd you had to download Kaspersky to deal with this, you weren't protected all along? That's likely lesson #2 - you really should be running some form of antivirus/malware at all times (at least while connected to the internet)
 

luunnn

Commendable
May 6, 2016
4
0
1,510

Thanks for the reply.
My question is, can I still put all the files on a separate disk?
Also, do I have to hurry up with the OS reinstall, is my hardware at risk? Can my computer just die?

 

ccampy

Honorable
Jan 4, 2014
61
0
10,610
Probably believes like apple marketing suggests Macs don't get virus

And you could backup the files but they may be infected so you would just reinfect your PC after the reinstall
 

mjslakeridge

Distinguished
Back up your files to a completely new source (DVD's, HDD, flash drive, etc). They may be infected so you want to keep them isolated. Reinstall your OS, let it do the updates, and make an image (clone) of your OS drive. Reintroduce the files from wherever you backed them up to and hope for the best. If the virus re-introduces itself, restore the OS image you made earlier and re-introduce your backed up files in small batches to see which one(s) may have the virus in them.

If it is a RAT, then that may be an entirely different matter, as I understand they can corrupt your BIOS also. I am not an expert in this area, read a thread on Tom's about it a while back and it sounded nasty.
 


mjslakerigde has covered off what you need to do. To have a chance of recovering your files, back them up now (not a whole system image, just the files you can't do without). Then format your drive & reinstall the OS and, as has been covered off, make an image at that point - before you reintroduce the potentially infected files.

I don't claim to be an expert here, so I can't confirm 100% your hardware is not at risk, but it's usually a software level problem - depending on the scope of the virus/hacker. A format and reinstall should solve the main problem, the files may or may not be infected, only time will tell.
 

Jugeum

Commendable
Apr 26, 2016
36
0
1,610
I would also suggest going on a different computer and changing all your passwords, I noticed no one has mentioned this, and when panicked, you don't always remember this step.
 

Paul Wagenseil

Senior Editor
Apr 11, 2014
692
1
4,940
Let me ask a couple of questions:

-- Is everything you're seeing things that you typed into the Mac during or around the time of the Runescape argument?

-- Do you use Apple's Time Machine software?

It sounds to me that your Runescape adversary somehow got a keyboard script onto your Mac that's set up to repeat things you've already typed in. It may not actually be that serious. I don't know how to remove it, but more Mac-savvy users might.

Regarding Time Machine, if you do have that running, you could dial back to just before you started interacting with this guy on Runescape.

Good luck....
 
Status
Not open for further replies.