Symptoms of being hijacked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lavender, Jul 18, 2011.

  1. Lavender

    Lavender Master Sergeant

    I am 99% sure my emails are being hacked. The person is 'eye-listening' to everything I write.

    What symptoms or evidence should I look for? Using Vista, gmail, and modem supplier email. I also use Bullguard. Should I contact them?

    Not being paranoid. Something mentioned just on email is known to a certain individual. It'a also happening to another person, by the same individual.

    Is there a way I can prove it to the police?
     
  2. Lavender

    Lavender Master Sergeant

    Sorry, that should read "Hacked" not 'Hijacked'.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sounds like you suspect you have a keylogger or something?

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  4. Lavender

    Lavender Master Sergeant

    Thanks. Tried to follow the instructions but got stuck at:

    Windows Vista
    Right Click Start
    Select Explore
    Select Organize
    Select Folder and Search Options

    I don't seem to have Organize.

    If it helps, I run Advance System Care 4 daily, Crap Cleaner seeral times a day. I use Avast.

    Windows Firewall with Advanced Security. Windows Firewall. Should I uninstall one of them?

    I have a 32 bit system.

    MSconfig is on my computer but not in Startup. Startup is empty.

    I don't have Add/Remove in my Control Panel. I looked through the rogue list but I don't think I have any of those programs.

    Defogger didn't find anything.

    Sorry, not very technical but this is terrifying:

    For Vista users - to turn off UAC ( UAC = User Account Control )
    Click Start, and then click Control Panel.
    In Control Panel, click User Accounts.
    In the User Accounts window, click User Accounts.
    In the User Accounts tasks window, click Turn User Account Control on or off.

    I did it and I'm at the point where I reboot my computer.
     
  5. Lavender

    Lavender Master Sergeant

    MG Tools wouldn't open on my computer.

    The other two scans revealed nothing. I scan my computer regularly so this was a wasted effort.

    So, what do I do now?
     
  6. Lavender

    Lavender Master Sergeant

    Well, thank you. Now I cannot download Spy Bot because "I have no Internet connection".

    Cheers.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It should not be in start up, so I do not know what you are talking about.

    But you should have Programs > uninstall a program ;)

    Open up a command prompt and copy and paste in the following and hit ENTER. This should take you to the uninstall programs list. Does it or not?


    It isn't meant to FIND anything.
    What's terrifying, turning off UAC? :confused Why? What's the problem?

    Not a waste at all, I requested to see those logs and I would like for you to attach them and follow instructions.

    Why are you thanking me? Do I detect sarcasm here? Like it was my fault or something? I did not ask you to download spybot.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The instructions are there so we can gather logs to look into your system to detect any malicious programs. Without the logs, there really isn;t much we can do. Since you are running Vista, please do the following:

    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.

    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.

    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Attach those logs if they run.
     
  9. Lavender

    Lavender Master Sergeant

    Thank you, Tim. I'll be back when I've done that.
     
  10. Lavender

    Lavender Master Sergeant

    Unfortunately, I managed to remove MGTools this morning. I just tried to download and, once again, something on my computer prevented me. Registry continued to flash in my sys tray and I couldn't even close or delete the program. The only thing I could was Restart mycomputer.

    I am the Administrator and the only legal user on this computer.

    Trying again.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you able to download combofix.exe? Will it run?

    You stated that someone from Bullguard logged into your computer and deemed it clean. How long ago was this?

    Did you use a different computer to change all your email passwords?

    ( I have edited this thread due to unnecessary remarks. )
     
  12. Lavender

    Lavender Master Sergeant

    Didn't work because my PC won't allow me to download MGtools.

    I'm tempted to let the hacker or keylogger just get on with hit. I've lost two days of work because of this. Even if I get another computer, he'll just do the same thing.

    I even changed gmail to a two-system verification which was a waste of time. Somehow he has bugged three telephones. We're not paranoid, we can hear him coughing when we're talking to other women. He is in court every few weeks on stalking charges, so this is a very bad person. The police are involved and investigating him.

    In the meantime, I really don't know how to protect my computer and my work. I have certain files lociked under Easy File Locker but I don't know how safe they are. I could lose years of work and research.

    Is there another way I can download MGtools?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have another computer available to you> if so, try downloading to it and transfer via CD or thumb drive. Here is a link:
    MGtools

    Again, what about Combo? Same issue?
     
  14. Lavender

    Lavender Master Sergeant

    Many thanks, Tim, for everything.

    I'll try that download.

    Bullguard was in about a week ago because their Inspector came up with a High Risk item I couldn't find. It turned out to be on a Recovery file of old programs that were on my XP before it crashed. The newer versions are on my Vista PC. I asked if I should delete it and he said it would be more trouble than the worth of it and to leave it alone and ignore it when it popped up on Inspector again. At that time my computer was perfectly secure.

    The last try of Inspector failed to complete the scan. It told me to retry, which I did, and still it couldn't finish. I contacted Bullguard support and got a very rude person who was no help at all. That's when I came to MG.

    I've changed email passwords recently, but not the ones I use to log into sites.
     
  15. Lavender

    Lavender Master Sergeant

    Neither Avast nor Bullguard will allow me to have combofix. They both say it is potentially unsafe. I can't even open in Sandbox.
     
  16. Lavender

    Lavender Master Sergeant

    I don't have another computer I can use.

    I had to delete Combofix otherwise Avast wouldn't let me see anything else on screen.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We both know ComboFix is a safe program. So you may need to uninstall temporarily both Avast and Bullguard. You shouldn't be running two AV programs anyway.
     
  18. Lavender

    Lavender Master Sergeant

    Bullguard is an AV program? It's out of here. I had the free trial program, but not after today.

    I'll take your word about temporarily removing Avast, but that scares me silly. I'll give it a shot and try Combofix again.
     
  19. Lavender

    Lavender Master Sergeant

    I can't uninstall othe Bullguard program, nor shred or Send to Recycle.

    I've had the same problems with other programs I've tried to uninstall. I'll see if I can deactivate it somehow.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So to summarize, you can't download or uninstall? You don't have another computer to use to do the downloads on. What other issues are you having, because aside from the suspected intrusion into your emails, this is sounding like a software issue at present. Do you have your Vista install disc?
     
  21. Lavender

    Lavender Master Sergeant

    No, the computer came with Vista installed. Hacking emails was confirmed by emailing something deliberately untrue after arranging it with other person. It sent the man into a panic. There may well be something to do with softwear, but I've been running scans daily. I just found a different path so I could get rid of Bullguard. I wish Vista was as straightforward as XP was.

    Will try to disable or temporarily remove Avas and try Combofix again.
     
  22. Lavender

    Lavender Master Sergeant

    Okay, here 'tis:
     

    Attached Files:

    Last edited by a moderator: Jul 19, 2011
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was not the full log. Please attach items to your posts. Can you now download and run MGTools?
     
  24. Lavender

    Lavender Master Sergeant

    Trying again:
     

    Attached Files:

    Last edited by a moderator: Jul 19, 2011
  25. Lavender

    Lavender Master Sergeant

    I can't run MGtools. the only way I can get out of trying after access is denied, is by logging off.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please ATTACH items to your posts!!

    Have you tried running MGTools in safe mode?

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!
     
  27. Lavender

    Lavender Master Sergeant

    Are you able to see the log file?

    I am trying to reply to you but what I write is being deleted. I'll try again, although my computer might end up with a black screen yet again and I won't be able to access anything until I reboot. This doesn't help with a gmail two-system verification. I am on the point of closing all gmail accounts and getting rid of the Internet. I'm also considering throwing my phone away to avoid nuisance calls that don't even show where the call came from. Yes, the a**hole is that capable that he can send a signal to my phone to stop it showing numbers.

    Spybot and teatimer were not on my computer until last night. I checked when I followed the lengthy instructions, and it was not on my computer. I checked allthe items you said to check. Should I delete Spybot? It's shown as one of the few programs that will detect keyloggers.

    I can't even find Safe Mode, although it ws there two days ago.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What log file? Did you try to attach a log? Which log?

    What do you mean? Deleted by what?

    Yes, you may wish to close your gmail account and establish a new one. Although it is possible to make a call on a cell phone and block the callers number, there is no way for him to make your phone block all numbers.
    No you do not need to delete Spybot. In fact, you should run it and ATTACH the log for me to look at. I thought you said you were unable to download it.
    What do you mean by this? When you power down and restart your computer, you just need to continuously hit F8 while the computer is first booting up. You should then have options and should choose Safe Mode with Networking. Then try to download MGTools and run it.
     
  29. Lavender

    Lavender Master Sergeant

    What else can I say? There are times when what I type is deleted as soon as I complete a word.

    There are times when I don't have control of this computer. No one else lives here so it's being done by the same neighbor who hacked my Gmail. Records will show that I've had to approach you twice to get my password set up after it was changed.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Would you be so kind as to address Tim's questions?
    Attach the log perhaps.


    What about this?
     
  31. Lavender

    Lavender Master Sergeant

    MG Tools is downloaded but I don't know how to run it. It lists everything on my computer and I don't think that's the log you want.

    I have a Hijackthis log but I don't know how to access Notebook files.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you look at post number 3 in this thread, you will see a link to the Read and Run Me First procedures. Choose the guide for your operating system, and somewhere along the way there you will find clear and concise instructions on how to run MGTools.

    What does? MGtools? So did you actually get it to run or not? You need to be clear. You said you could not run it but now you talk about what it lists in it's logs as if you know because you HAVE ran it. Do you have a C:\MGlogs.zip or not? If not go back to my instructions in post # 3 where you will see how to run it.

    We don't need to see that at the moment.
     
  33. Lavender

    Lavender Master Sergeant

    Just as well.
     
  34. Lavender

    Lavender Master Sergeant

    Search doesn't bring MGlogs.zip.
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, but you have since ran it and TimW said he was not finding any malware in that log. So that's that out of the way.
    Agree to the Trend Micro license agreement. May need to click "YES" to confirm twice not just once. This is really HijackThis. When MGTools is completely finished it will tell you to hit any key to continue. You know you are done then. You can then attach the C:\MGlogs.zip
     
  36. Lavender

    Lavender Master Sergeant

    Avast and Bullguard are long gone.

    Okay, running TrendMicro.
     
  37. Lavender

    Lavender Master Sergeant

    Log attached, I think.
     

    Attached Files:

  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, but remember what I said? I would like to see the whole C:\MGlogs.zip, NOT individual logs from within it. If you are running MGTools then you should not have a browser open, best to shut it down, let it run, and THEN come back online.
     
  39. Lavender

    Lavender Master Sergeant

    Ow, Gowd! Okay, I'll do that and come back.

    Thanks.
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome.
     
  41. Lavender

    Lavender Master Sergeant

    Okay, here we go. New log.

    If it isn't all there, I don't know what I'm doing wrong.
     

    Attached Files:

  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Remember how we discussed finding the conduit folder earlier on in the software forum? So to locate the zipped log I would like to see, click start > computer > double click C drive and now look carefully for a C:\MGlogs.zip. Is one there?
     
  43. Lavender

    Lavender Master Sergeant

    Nope, nothing there. Also ran Search. Nothing showing up.

    I can't be running MG Tools properly.
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      MGlogs.zip
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  45. Lavender

    Lavender Master Sergeant

    If I highlight Select All what do I do then?

    Okay, just saw your post.
     
  46. Lavender

    Lavender Master Sergeant

    So where do I find it? I Googled it and all Ic an see is reports of errors but nowhere to download.

    The mirror links won't work without the rest of it downloaded first.
     
  47. Lavender

    Lavender Master Sergeant

    This does not look good. (removed link to potentially dangerous website)
     
    Last edited by a moderator: Sep 6, 2011
  48. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You just gave a link to a bad website! Good job Firefox stopped me from going there. I am going to remove the link, edit it out.
     
  49. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me ask you something outright, are you questioning whether the tools I ask you to download are safe or not? If we do not have trust here, we do not have anything I'm afraid.
     
  50. Lavender

    Lavender Master Sergeant

    Thanks for deleting the dangerous site.

    I am not questioning you but I can't download the mirrors without the other program so I Googled it. You gave me live links to the mirrors but not to the program itself. I downloaded one mirror and it said it couldn't run with out the text file. (I think it said text file.) It wouldn't work anyway.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds