Online Account Issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by shipwreck276, Feb 24, 2017.

  1. shipwreck276

    shipwreck276 Private E-2

    Hi,

    This morning I woke up and my amazon account information had been changed without my knowledge. I am worried that someone might have gotten into my email with malware of some type. I have changed all of my passwords, but I want to make sure my computer isn't compromised. Thank you for your help with this.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hopefully you did not change your passwords using this PC because it is infected. You should have used a different known clean PC.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of the code box
    • Make sure that you scroll all the way to the bottom of the code box to get the whole fix!
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Program Files (x86)\SearchProtect
    C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj
    C:\WINDOWS\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
    C:\WINDOWS\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
    C:\Program Files (x86)\Common Files\Gerediha\Ropohi.dat
    C:\Program Files (x86)\Common Files\Gerediha\ProductUpdt.exe
    C:\Program Files (x86)\Common Files\Gerediha
    C:\WINDOWS\system32\Tasks\{020D8A8B-6C1E-080C-F0B3-771A42E00217}
    C:\Users\test\AppData\Local\Temp\*.*
    
    :Reg
    [-HKEY_USERS\S-1-5-21-2943526111-3921562254-1684937411-1001\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-2943526111-3921562254-1684937411-1001\Software\csastats]
    [-HKEY_CURRENT_USER\Software\Conduit]
    [-HKEY_CURRENT_USER\Software\csastats]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\SOFTWARE\Conduit]
    [-HKEY_CURRENT_USER\Software\Conduit]
    [-HKEY_CURRENT_USER\Software\csastats]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\RunOnce]
    "Cekuhenu"=-
    
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\RunOnce]
    "Cekuhenu"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, Win7, 8 or 10, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7, Win8 or Win10, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. shipwreck276

    shipwreck276 Private E-2

    Thank you for your quick response. Here are those files.

    I changed my passwords at work this morning. I know that isn't ideal, but I figured it was better than using mine at the time. Once this computer is cleaned, I will change them all again.

    The computer seems to be working fine. Unfortunately, it seemed to be working fine before all of this too though. I hadn't noticed any slowdown at all.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay that looks better but let's run another scan as a double check.

    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.

    • See the download links under this icon [​IMG]
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. shipwreck276

    shipwreck276 Private E-2

    I'm glad it is looking better. I am at work right now, but I will run this and post the log as soon as I get home to my laptop (around 8PM CST). Thank you again for all of your help.
     
  6. shipwreck276

    shipwreck276 Private E-2

    Here are those two logs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay we have a little more to do.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Please attach the above log first before you continue with the below.

    Also at this point, I want to double check your status one more time by having you run another scan with FRST like in my last message and attach the new FRST.txt log.
     

    Attached Files:

  8. shipwreck276

    shipwreck276 Private E-2

    Here is the fixlog. I will attach the next scan in my next post.
     

    Attached Files:

  9. shipwreck276

    shipwreck276 Private E-2

    Here is the new scan. Did you want the new addition log also or just the FRST.txt file? Thanks!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can attach the new Addition.txt file too just to be complete but it is looking good based on the log from the fix.
     
  11. shipwreck276

    shipwreck276 Private E-2

    Here is that file too.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Please complete all of the below final instructions before running any other scans to avoid false detections of things we have already quarantined or left overs from system restore.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  13. shipwreck276

    shipwreck276 Private E-2

    Thank you so much for all of your help. Along the way, ublock origin was deleted from my browser. Is it safe to reinstall that extension for chrome?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes you can reinstall that addon.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds