Bank account was drained - please review my logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by a_hansen, Aug 14, 2008.

  1. a_hansen

    a_hansen Private E-2

    Hi chaslang and timw,
    I was shocked as I yesterday found out that I had been the victim of someone emptying my bank account. It seems my money was spent playing poker online. Somehow someone must have acquired my card number and I can't figure out how that happened. The situation is now resolved, but I am very concerned to figure out if something is lurking inside my pc, picking up my details while I have been making transactions online.

    Please be so kind and review my logs.
     

    Attached Files:

  2. a_hansen

    a_hansen Private E-2

    MGTools
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no signs of any problems in your logs. Are you sure that your account infor was stolen from this PC? Perhaps it occurred while using a different PC.

    If you really expect that this PC was the root of your problem then security wise the safest thing to do is a total reinstall.
     
  4. a_hansen

    a_hansen Private E-2

    chaslang,
    thanks for your reply. I'm going to give you the gmer scan also. Are there any other essential rootkit scanners that would be of any use?

    I am trying to rule out my pc as the possible source of the recent misuse of my bank account. Is there any way you could estimate the chance of some malware passing all these scans unnoticed? Given the clean result of these scans (if gmer doesn't find something), should i calm down or reformat?

    Suppose something was transferring my visa details - would that be a keylogger in general or some malware using more of a pinpoint/specific technique?

    Again, many thanks for your time
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is clean too.

    No! Since everything thus far is clean we are unlikely to find any real problems running any other scanners.

    We cannot guarantee that something is not being missed; however since everything is totally clean it is unlikely. If you are really worried, the best answer is to reinstall. Also ALL passwords to EVERYTHING ( not just financial related ) should be changed. However do not change them from your PC or any other PC that may have originally been the source of your bank info being stolen.

    Keyloggers and password stealing trojans are designed to steal your info but your PC shows no problems at all. The source of your problems could be elsewhere.
     
  6. a_hansen

    a_hansen Private E-2

    chaslang,
    thanks for your support and advice! I will choose to act in compliance with the scans and regard my PC as clean. Is there any point in keeping SAS as a regular scanner?

    Since I've seen the subject recently surfacing again as a topic in the mg malware forums: Regarding AVG8 my own observation is that Grisoft seems to have come to terms with the interaction with Spyware Blaster. Scanning my PC now won't result in AVG flagging 'warnings' regarding the registry entries made by Spyware Blaster.

    I've said it before - I'm very impressed by the work that you people put down at this forum and how much of a structure you seem to have established to make it all possible!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is quite useful but I would just disable the option that has it load when Windows starts up. Just run it as a scanner when you want. A better option would be to purchase it and run it for realtime antispyware protection and scanning.

    That's funny! Others are still seeing the problem. I will have to check it myself (if I can find the time). Run SpywareBlaster and check for updates and install any that are needed. Then make sure that you enable all protection in Spyware Blaster. See if AVG pops up while doing this and also run a scan with AVG afterwards to see if it mentions these active-x settings.

    Thanks! ;) We do work hard at this.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now if you don't want to keep it.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Aug 20, 2008
  8. a_hansen

    a_hansen Private E-2

    Hi chaslang,

    I have never received a reaction from AVG8 when updating the definitions of SpywareBlaster. Right now I tried scanning the computer with AVG8, and letting it pass through the stage where it scans the registry, it doesn't pick up on anything.

    Running this command will only result in the message (roughly translated): c:\Documents and Settings\Administrator\Desktop is referring to a location not available...
    Combofix is installed on the desktop (it was run directly from the executable, right?), so what's up with this?

    Thanks!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually according to your logs it is not located there at all and you may have illegal characters in the Administrator user account name making it a problem to read properly with all the tools. See your newfiles.txt log inside of the MGlogs.zip file and you will see the user account is actually showing as:

    USERNAME=Administratör

    The umlouts maybe causing a problem because further down you will see:

    Code:
    List contents of C:\Documents and Settings                           
    "C:\Documents and Settings\"
    ADMINI~1       2007-03-27              "Administrat”r"
    ADMINI~2       2007-04-10              "Administratr"
    Notice two accounts similarly named and one shows with a "r .

    There is no way ComboFix will find this. Also further down in the newfiles.txt log, the below appeared when trying to get to the Desktop:
    Because of the "r in the folder name, the tool could not find any files on the Desktop since this is not what the user acount name really is. The umlout is an illegal DOS type character.

    You will have to replace the "%userprofile%\Desktop\combofix" by what ever your real full path is and hopefully it will work. You need the quotes.
     
  10. a_hansen

    a_hansen Private E-2

    chaslang,
    I realize this is kind of a waste of your time using time just getting combofix to uninstall.

    I checked the newfiles and see what you're talking about, although: since I am not used to scan the logs - where do they say combofix is installed if not on the desktop? (I see the red lion logo right there)

    Under what account is cf installed? The illegal character of 'ö' is the way of spelling Administrator in Swedish.

    Further, when entering the dos command I suppose am I supposed to replace also the "%" characters with the actual user account name?

    Well, this is embarrassing, I consider myself being reasonably computer savvy and here I find myself asking questions about the final steps. :-D
     
  11. a_hansen

    a_hansen Private E-2

    Since time limit for editing existing messages expired: Searching for ComboFix.exe gives me C:\Documents and Settings\Administratör\Skrivbord ("Skrivbord" meaning "Desktop")
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so try the below ;)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "C:\Documents and Settings\Administratör\Skrivbord\combofix" /u
    • Note: The space between the combofix" and the /u, it must be there.
    Did that work?
     
  13. a_hansen

    a_hansen Private E-2

    Yes. of course it worked! And, annoyingly, that's what I tried myself, just that I must have missed the quotation marks. Thanks and thanks again my friend.

    Now, one more of these nagging questions. Ever since I completed the read and run me, it seems when starting up the computer Windows security center doesn't seem to recognize that ZoneAlarm is up and running. The red warning symbol from the security center appears in the activity menu after startup, clicking it brings up windows security center telling me I have no active firewall. According to the activity menu ZA has started up as usual and checking the running processes and processes launched at startup confirms this. Closing and restarting ZA will make the security center recognize my firewall it seems, as the red icon disappears.

    Ever seen this before after going through read and run me?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually no! It would seem unlikely to be from the READ & RUN ME because of the below info from your logs:
    It may be a good idea to unplug you cable to the internet and uninstall ZoneAlarm. Then reboot and reinstall it to make sure that everything is working correctly.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds