HELP, Keylogger??? Money was withdrawn from my bank account.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by glasshalffull5, Nov 23, 2009.

  1. glasshalffull5

    glasshalffull5 Private E-2

    I just had money withdrawn via western union from my bank account and they confirmed it was fraud.

    I'm not sure how they got my debit card info, but they did. They also got several answers to security questions to allow them access to my account.

    How do i fix this? Not sure if this is an online keylogger or theft offline.

    What should i do to fix this? What should i not do on my computer right now as far as logging in to sites?

    PLEASE help
     
  2. glasshalffull5

    glasshalffull5 Private E-2

    i just noticed that when i went to sign up for a brand new youtube account that there was an, account member signup section (where you create a username, pass, and basic details) that hung up and stayed partially on the page after i had entered and submitted the info. the boxes where you put the info to signup at "stuck" to the page and didn't disappear completely leaving a few of the boxes there and you could still type into them.

    When I had clicked submit and the rest of the page changed, some of those form input boxes stayed and were on top of the next page's info.

    Could this be the keylogger?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first thing you need to do is the below and don't use the potentially infected PC to do this and don't use a public PC either (like a library PC etc).
    After you do the above you need to consider whether you want to attempt cleaning the PC or you wish to be safe and perform a totall clean reinstall.
     
  4. glasshalffull5

    glasshalffull5 Private E-2

    I have already reported this to western union and have closed the account with the bank.

    what is a total clean install? will i still have access to all of my programs and records.

    I bought this computer new about 3 years ago and have alot of data on it.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If one account has been accessed, it is possible that all accounts, credit cards, and passwords for anything you use have been compromised. That is what that link was talking about.

    It means you erase everything on your hard disk and start over. The Software Forum can help you with this if you wish to take this route. The other choice would be to attempt cleaning per the stickies ( READ & RUN ME FIRST. Malware Removal Guide ) but this does not guarantee that you will be clean.

    Not unless you back them up first and put them back later and you have to be careful that you are not putting back anything that has been infected.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have to go out for awhile. If you wish to attempt cleaning, start running the READ & RUN ME FIRST process. In the mean time, do not use this PC for logging into anything that requires security and use another clean PC to change passwords for ALL accounts that you use anything.
     
  7. glasshalffull5

    glasshalffull5 Private E-2

    i have 2 computers hooked up to this network.

    1 of them, i could completely wipe clean, but the newer onw with all of the data i need i would like to try and clean.

    If i were to completely wipe the older one first, could i then use it while i clean the newer one? I ask that because I'm not sure if it matters that they share the same wireless router and could that affect things.

    I that is a problem, i can disconnect the newer one from the net while i clean it to allow the fresh installed to work with no issues.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some infections can spread across network interfaces especially if you have File and Print Sharing enabled. Since we really don't know at this point what infections you may have nor do we know if both or only one are infected, it would be best to remove the one from the network and start reinstalling the other if that is what you wish to do. However, I must re-emphasize that you need to immediately address the issues of passwords and possibly user account names and you need to do it from different PCs that are known to be clean. You also need to check with all other financial accounts to make sure that have not been compromised already.
     
  9. glasshalffull5

    glasshalffull5 Private E-2

    I've been trying to locate another computer with no luck yet. I'm locating one as fast as i can as i do understand the severity.

    bank won't let me change the pass over the phone only online.

    can i do this from a mobile device that has web access?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How about in person and also explain to them why you cannot do it online since online access has been compromised.

    How much do you trust that it is secure?
     
  11. glasshalffull5

    glasshalffull5 Private E-2

    they issued me a temprary pass and user for a few hours.

    Now I'm trying to fresh install xp from the xp disc onto the old computer which is not connected to the net.

    unfortunately for some reason, when i restart computer and boot thru the disk and i get to the XP Licensing Agreement, it ask:

    to agree to agreement: press F8

    to disagree: press Esc.

    when i hit F8 to agree nothing happens.

    i can hit esc and it will take me back thru the boot from cd process.

    what do you think is wrong?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need to work thru installation/reinstall issues in the Software Forum: Software
     
  13. glasshalffull5

    glasshalffull5 Private E-2

    ok, i'll be back when i get that handled


    ...hopefully shortly
     
  14. glasshalffull5

    glasshalffull5 Private E-2

    after the holiday i will be back to get this straightened out and follow the procedure you provided.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you mean the READ & RUN ME FIRST will be run on the PC you first posted about?
     
  16. glasshalffull5

    glasshalffull5 Private E-2

    yes that is correct
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Hopefully you are not using this PC for anything else before running the cleaning process so we can check for problem malware.
     
  18. glasshalffull5

    glasshalffull5 Private E-2

    going thru the steps to remove malware and I'm at the combofix step and when i try to install combofix a warning box pops up saying this:

    --warning--

    This is a BETA version Combofix meant for compatibility testing

    under no circumstances should this be run on a live machine

    click "NO" to exit



    then it gives me the option to click yes or no

    what should i do?
     
  19. glasshalffull5

    glasshalffull5 Private E-2

    Here are the logs for my scans.

    I cannot run the RootRepeal Scan.

    I get an error:

    DeviceIOControl Error

    error code = 0x0
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to put ComboFix.exe directly onto your Desktop to be able to follow our later instructions. You put it in the below folder which you should delete:
    c:\users\Jason\Desktop\major geeks\ComboFix.exe

    And while speaking of the Desktop, yours is a mess. I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Uninstall the below software:
    RegNow.com Marketplace Explorer 1.0

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Jason\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll (file missing)
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
    O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\temp
    C:\Users\Jason\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. glasshalffull5

    glasshalffull5 Private E-2

    I followed your instructions in your previous post and cleared the desktop as well.

    the 2 logs you asked for are attached?

    As far as how the computer is running.....it's running less sluggish....especially after running ccleaner....which i hadn't done in awhile.

    My brother had set this computer up for me when i bought it and he installed alot of programs on here for me and he told me that i should run ccleaner often.


    Please let me know the next steps after looking at the logs.

    thank you
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  23. glasshalffull5

    glasshalffull5 Private E-2

    that's great that the logs are clear. I hope that removed any potential keyloggers that might have caused the online banking breach. that was a mess getting that straightened out with the bank and closing that account.

    in step 8, does this apply for windows 7 as well?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No keyloggers showed in you logs. If you require a guarantee that you are clean, you will have to delete partitions, format, and reinstall from original uninfected media. That is the only way to be sure.

    Yes!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds