I may have been hit with one of those remote spy programs in an email

Discussion in 'Malware Help (A Specialist Will Reply)' started by screamingcheeto, Jul 16, 2007.

  1. screamingcheeto

    screamingcheeto Private E-2

    Someone I know has told me that they have used one of the programs that spy on people's actions remotely and is installed by sending them an email. I opened an attachment-free email from them that contained a link that i did not click, but they have said that this program installs itslef just by opening an email. Is it possible that it can be hidden in an email, and simply opening the email can install the program? The email seemed strange and I don't know if I'm infected. Also, if I am, can i just do a system restore to the day before to get rid of it? Please help me.

    Thanks,
    John
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is possible. It is less likely if your system is properly protected.

    While doing a System Restore to the day be for could remove symptoms of an infection (yet to be determined that you even have one), it does not necessarily remove all traces or files of the infection from your PC. It could make the infection dormant, but it could still be there.

    You should consider running the below to see if anything is found on your PC.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. screamingcheeto

    screamingcheeto Private E-2

    Alright, Vista's giving me hell. The only log I obtained was HijackThis. I couldn't run GetRunKey or ShowNew. Getrunkey would give an "access denied" error over and over and i tried multiple things but couldn't fix it. ShowNew gave some error about a file not existing that wasn't listed on here. BitDefender worked, and it found absolutely nothing so there's no log for that. I also did Counterspy, which also found nothing. PandaScan wouldn't work. I have another concern, when I made all the hidden files viewable, desktop.ini showed up in a lot of places and I haven't opened it. I've never heard of it, so is it malware or normal?

    Oh, just as I was attaching this some warning came up with allow or disallow for some "microsoft host process run dll32" or something like that. Please help me out and give this all a lookover.
     
  4. screamingcheeto

    screamingcheeto Private E-2

    I'm not sure if the HJT log attached so I did it again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah Vista is an issue since it is so different. You should have told us in your first message that you have Vista. I tend to doubt that you picked up an infection if you have Vista's UAC enable and have other protection software in place.

    You must temporarily disable UAC to run GetRunKey and ShowNew. Re-enable UAC after running.


    Normal! It was just hidden before like many, many other files and folders.


    You HJT is clean but HJT logs are really not an adequate representation of a PC's malware status. However as stated above, I tend to doubt you picked up anything.
     
  6. screamingcheeto

    screamingcheeto Private E-2

    Just to be safe, how do i disable the UAC thing?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See this: http://technet2.microsoft.com/WindowsVista/en/library/0d75f774-8514-4c9e-ac08-4c21f5c6c2d91033.mspx?mfr=true

    Or this may be more straight forward for what you need to do:

    http://www.petri.co.il/disable_uac_in_windows_vista.htm


    However note that I really doubt I will see anything in the GetRunKey and ShowNew logs. They are not truly malware scanners. They just dump a variety of registry keys and files and folders lists into logs for us to manually read. However, be my guest and run them. We will look at the logs.
     
  8. screamingcheeto

    screamingcheeto Private E-2

    So, would you just honestly say I'm probably not infected and I should just compute as normal?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. screamingcheeto

    screamingcheeto Private E-2

    Here's the log, looks like it didn't find anything..
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that's good and it just agrees with what I was saying. You are not infected!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds