Cell Service Account Hacked / Key Logger /Spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by harvastmoon, Jun 29, 2015.

  1. harvastmoon

    harvastmoon Private E-2

    Just found out my cell phone account was hacked, my home/billing address was changed to an address in Mays Landing, NJ. Never been there or know anyone there :confused !!
    I suspect it may be info taken off my computer. I have run all the programs as required but I could not run TDSSKiller. I even changed the name to iexplorer.exe and still couldnt run it.

    Would really appreciate any help. I have attached logs.

    thank you in advance...:)
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  3. harvastmoon

    harvastmoon Private E-2

    No I''ve never delibertly, set up a proxy. But FYI I do have 2 routers setup.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-2215768705-443594929-4078419579-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:21320 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-2215768705-443594929-4078419579-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:21320 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    ...and the same for this entry on the web browser tab please...

    • [PUM.Proxy][FIREFX:Config] 3gv0dhgb.default : user_pref("network.proxy.type", 4); -> Found

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Delete this:
    • C:\Program Files (x86)\GUM3935.tmp


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Please rerun RogueKiller (just a scan) and attach log.
    Also you didn't ever attach a log from Hitman Pro, I'd like you to do so please.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  5. harvastmoon

    harvastmoon Private E-2

    I've performed all the steps and attached the logs.

    The first step you had me do was go to MSconfig to change to "Normal startup". I also looked at the boot tab and noticed that safe mode was checked and so I unchecked it and restarted the computer.

    Now I've finished all of your instructions and took a look at the msconfig again and found that it is exactly the same as when I began... the General tab has "Selective startup" ticked and the Boot tab has boot options ""Safe mode - minimal" ticked. (see attached pic titled msconfig).
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not do what Kestrel13! requested. She just asked you to put your PC in Normal Startup mode. See the top of your first image. You should not touch anything on the Boot tab.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run RogueKiller again please (just a scan) I am not sure whether the proxy was removed or not, looking like it wasn't.
     
  8. harvastmoon

    harvastmoon Private E-2

    I apologise for making changes I shouldn't have.

    1. I have gone into msconfig and changed it to Normal startup and then rebooted. When the computer came back I noticed that I no longer had internet connection and could not establish one. Is this normal?
    I then ran roguekiller and saved the log but had no way to upload it to the forum because I have no connection, so I went back to msconfig and kept the normal startup mode but enabled the network just so that I could connect to MG website.

    2. I am now trying to rerun HitmanPro because as I stated in earlier post it would not let me run it even when I held the Left Cntrl key. However, now this program is missing from my desktop as well as anywhere on my computer. I did find a file called Remnants.bin created 6/29/2015 @ 12:03 AM 150 KB.
    I will leave the msconfig in Normal startup mode with netowrk so that I can check for your response.
    Also, please let me know how the msconfig should be before I download HitmanPro again and run it.
     

    Attached Files:

  9. harvastmoon

    harvastmoon Private E-2

    I went back and reread your instructions from Yesterday (6/29), 16:57 and see where I made my error. Honestly, I usually don't have problems following directions but somehow this time I did! :banghead ... I am so Sorry... You guys are the first place I turn to for anything tech related, I Love You!!

    Anyway, I went back and redid all of the steps in that post and am attaching the logs. I hope that was ok to do. Also I did find the HitmanPro on my desktop, I had renamed it to avoid detection by any malware. Once again I tried to run it and it stopped midway, then I tried it again holding down the left Cntrl and it it also stopped midway. I took a screen shot of the error details and will attach it.

    Again please accept my apologies for all of my confusion, I am just overwhelmed with the thought that all of my info might be in the wrong hands :cry
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is because of the change you made to select Safe Boot mode on the Boot tab! You are still not fully in Normal Startup mode due to this and I can see it in your logs. So unselect Safe Boot and make sure you are still in Normal Startup mode and then reboot.

    After reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    This way we have a proper MGLogs.zip from Normal Boot mode not safe boot mode. ;) Then Kestrel13! will be able to finish helping you.
     
  11. harvastmoon

    harvastmoon Private E-2

    OK. I've attached the MGlogs.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And how are things running? :)
     
  13. harvastmoon

    harvastmoon Private E-2

    Connecting to internet is very slow.
    Also there are some files that are now on the desktop that weren't there before, these are a few: ~WRL1170.tmp, desktop.ini, ~$anks and Beans2.docx, ~$ear Ms.dotm.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can post about that in the software forum. ;)

    All those files you see will disappear when you follow final steps.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  15. harvastmoon

    harvastmoon Private E-2

    I followed your last directions and then ran Malwarebytes. It picked up 12 PUP items. I've attached the log.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nirsoft is a utility that you downloaded on June 23

    Code:
    d-----w                 0 2015-06-23 16:58:57  C:\Users\Lynda\Desktop\Nirsoft Package 1.19.2
    I assume that you should know that you downloaded it for some reason.
     
  17. harvastmoon

    harvastmoon Private E-2

    rolleyes Hmmmm let me see.... yes, I am fully aware that I downloaded it, but

    1. I'm wondering why it didn't show up on any of the programs we ran during my cleanup procedure?

    2. What should I do at this point?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because it is not a problem. PUP means Potentially Unwanted Program. Thus if you "want" it then it is not a problem in most cases. There are some programs that fall under the title of PUP that are definitely not wanted. Many of these are so called "junkware" or "adware" programs that do cause issues. But even with these, you can find people that still want to use the program. Thus they want it and it is therefore not a PUP to them. ;)

    When you first came here your MBAM database was: Database version: v2015.06.28.04

    Now your database at last scan was: Database version: v2015.07.04.03
    Malwarebytes probably just added the PUP warning in this recent database.

    Nothing unless you want to delete it. You could just delete it manually. One other thing you could do is move it to better more secure location. This could prevent it from being detected. It should not be on your Desktop.
     
  19. harvastmoon

    harvastmoon Private E-2

    Thank you for the info. I incorrectly thought that PUPs were a bad thing. I will take a good look at my desktop and clean it up, I know have neglected this task for a while now.
    Also a good time to look through my harddrive as well, I know there are a lot of old files and programs I can remove to free up space.

    Thanks again
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds