Hacked and money taken 1 of 2

Discussion in 'Malware Help (A Specialist Will Reply)' started by HiFi4TeePee, Feb 12, 2011.

  1. HiFi4TeePee

    HiFi4TeePee Private E-2

    Hi, my iTunes account has been compromised so I am taking steps to see if whether my PC has been compromised. By hacked I mean that about $200 credit was used for in-app purchases for an app I didn't buy.

    I have followed the READ ME procedures and am attaching log files. RootRepeal didn't run, see the .jpg for exact error message.

    SuperAnti... found a couple of files which I suspect were NOT malicious. I have follwed the instructions though and cleaned.

    I'd be grateful if you can tell me whether my system is clean or not.

    Cheers

    Tim
     

    Attached Files:

  2. HiFi4TeePee

    HiFi4TeePee Private E-2

    Hacked and money taken 2 of 2

    Last log file attached.

    Thanks and regards

    Tim
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Other than a left over sign from a fake anti-spyware program which SUPERAntiSpyware removed, your logs are clean. So it does not appear that malware on this PC is the cause of your problems.


    It could be that your problems came from any of the below.
    • Poor security on the website itself
    • Accessing your account from a different PC. Even on not belonging to you.
    • Using an unsecure wireless connection somewhere from any PC or even any wireless device.
    To be safe, you should change all passwords for all online type accounts that you use and you should check with financial institutions to make sure no other accounts have been accessed.

    However, I do have to asked why you have the below IP address from Peer 1 Dedicated Hosting entered in your Trusted Zone

    O15 - Trusted IP range: http://66.155.114.204


    Also is the below folder something you just created?

    C:\Program Files\NoVirusThanks
     
    Last edited: Feb 12, 2011
  4. HiFi4TeePee

    HiFi4TeePee Private E-2

    This was created by a virus scan from novirusthanks.org
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. HiFi4TeePee

    HiFi4TeePee Private E-2

    Thanks. Happy to run with that. But how do I get rid of the port you identified as open?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not say anything about a port being open. What are you referring to?

    Do you mean the below which is an IP Address not a port?


    O15 - Trusted IP range: http://66.155.114.204
     
  8. HiFi4TeePee

    HiFi4TeePee Private E-2

    Yes, the IP address. Sorry about that :-o
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can just remove it from your Trusted Zone, via Tools, Internet Options. Click the Security tab. Then select the Trusted Zone icon. The click the Sites button. Then under the Websites: listing, select the IP and then click Remove
     
  10. HiFi4TeePee

    HiFi4TeePee Private E-2

    Thanks VERY much. I'm good with this response.

    I really appreciate your help. Thank you!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds