Email and UAC PW stolen

Discussion in 'Malware Help (A Specialist Will Reply)' started by Pella333, May 28, 2014.

  1. Pella333

    Pella333 Private E-2

    Thanks in advance for your help.

    I haven't run any of the Read and Run Me First Yet steps yet as ,
    I am not able to shut off my UAC account as my passwords on my user account and my emails have been changed. I did make a second PW for my sign in on my laptop so whomever did it hasn't been able to disengage me from using the web.
    So , not being able to shut off the UAC , would that make any of the steps a mute point?

    If it will work , I will proceed. I did download all the programs suggested and am ready to go when you say so...

    Pella333
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to clarify, you are not able to turn off UAC? But you are able to log into the affected account to run the tools>?
     
  3. Pella333

    Pella333 Private E-2

    That is correct
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Kes needs you to run and attach the requested logs.
     
  5. Pella333

    Pella333 Private E-2

    You wish me to do the run and read me first steps and logs minus turning off UAC account?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try to run them and see how far you get.
     
  7. Pella333

    Pella333 Private E-2

    Sorry, not sure if you received the file logs. Sending them again to you...thanks a bunch!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware. Did you create a new user profile? Does that log in work?
     
  9. Pella333

    Pella333 Private E-2

    I didn't. I just looked in internet options and noticed remote access was on. I NEVER enable that. I unchecked it and now I can't get online.
     
  10. Pella333

    Pella333 Private E-2

    My Admin password was changed, I have a guest account it was off. I attempted sfc/scannow in cmd it says I have to be admin. I am admin and signed in to admin . Confused, if this isn't malware then what? I am the only person to use my laptop, absolutely no one else uses it, it is with me 100% of the time.

    I did system restore, got back online , still unable to get my Microsoft password, will attempt to contact Microsoft to resolve that problem
     
  11. Pella333

    Pella333 Private E-2

    Changed my admin pw with microsoft, it handles my laptop admin sign in. I then created a new micro account and user on my laptop. When I tried to change my original user admin account on my laptop uac account I received the following error message " service is unavable for this task try again later" stumped as to next step (s) I also downloaded Trend Micro ran scans on both accounts no threats found. Strange that all passwords on my laptop and email accounts were changed and no malware is found. Damn suspicious
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am going to suggest you post in the software forum for additional assistance.

    Have you cleaned out your email account? Can you turn on and off UAC?

    Can you delete your old account?
     
  13. Pella333

    Pella333 Private E-2

    Not yet, I have got control of one of the compromised email accounts and my Microsoft account. There is still one email account dangling out there am waiting for google team to phone me , they only do one account at a time.
    It might be a few days before I get it all sorted.

    I did find my compromised email, once I gained access today flooded with spam from Loan Companies, I had done an app on the web to refinance and that must have been at the bottom of the mess.
    I used recovery manager to refresh my win app and that has helped a bit...

    Odd that Trend, Norton and Defender ( I disabled each one then used and enabled them one at a time independently) they found nothing, but MBAM found some PUM issues.

    I need a break, thanks for trying, I am beat for today will post to software forum, not sure how to do that...maybe by wed I will have minute to try.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how you get on.
     
  15. Pella333

    Pella333 Private E-2

    I dug into the computer last night and today, here is what I found.
    Servicesmsc. I found a ton of remote desktop enabled and running. I shut them off.
    I just went into COmputer management and found this: A little worried since I found Admin remote user in two areas.
    Here is what is listed
    Shares folder when I expanded that I had :
    ADMIN$ C:/Windows client connections 0 Remote Admin
    C$ C:/ Windows 0
    D$ C:/WIndows 0
    IPC$ 0 Remote Admin

    Also I found alert errors for the date 6/3/2014
    desc 51
    error 900
    Have no clue what any of this is or whether it is benign or malevolent. Just that remote admin has me worried...although it says it has 0 connection it might even be normal as I have never looked around the computer management pane before.
    I reran Norton, after disabling all the remote systems running , it found a few cookies and that is all.

    I think I am at the end of the road of what I can do, should I post in another forum at this point or is this nothing to concern myself with?
    Thanks TIm, have no idea how you do this as often as you do, I would need meds and a lot of Vodka...
    Alexandra
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, I suggest you post in the software forum for additiona assistance.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds