Bank Informed Might Have Trojan Panic Ran Run Me First.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by huntin, Jun 5, 2019.

  1. huntin

    huntin Private E-2

    Hi yeah running windows 7 networked with a lot of windows 10 machines, bank has informed me they've detected a trojan, and another of my bank transactions has been edited/changed to be something else. triple checking system, might be a steelwerks infestation, not sure what that is but the warning has been scaring me since I found you guys years ago. I am worried, let me know how worried I should be.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLogs is a month old. Please run the scan again so that I can see what is current. How were you contacted? Did your bank call you and did you confirm it was your bank?
     
  3. huntin

    huntin Private E-2

    It is almost definitely not a month old. I haven't run it on this computer for quite a while since yesterday.
     
  4. huntin

    huntin Private E-2

    It's using my default for dates dd/mm/yy.
     
  5. huntin

    huntin Private E-2

    I guess I will run it again and have my dates in a format that makes them more easy to understand. Sorry for confusing you.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...this would be confusing - Scan saved at 4:38:36 PM, on 5/06/2019
    I will relook in the morning.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Again, who told you that your system was infected?

    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  8. huntin

    huntin Private E-2

    I've had a single bank transaction of a rather large sum have the destination change dramatically, bank and destination. A different bank I deal with said they detected some kind of trojan and wanted me to add in third party checks before I could check my statements with them, and I had the "steelwerks" box pop up when running MGTOOLS when you specifically mention not to press "cancel" but instead to press "close window". I'm most worried about the transaction destination change, and I've contacted my bank about the transaction, and thats the only thing I'm sure isn't correct.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what that is....nor have you explained the transaction. How was it done? What did the "other" bank say about what they detected? So far, I am not seeing any malware.

    I also need you to delete all your temp files!!
     
    Last edited: Jun 6, 2019
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ANNIE...stay out of this thread. Last and only warning!
     
  11. huntin

    huntin Private E-2

    1/
    MGtools.exe runs a cmd prompt and runs about a million cleaning systems, finalizes all, writes about forty logs.

    during MGtools.exe running, there is a warning that comes up "

    ********************************WARNING****************************************
    If you see a popup saying that
    SteelWerX WhoAmI application has stopped working

    do not click the cancel button that first appears. Wait for the Close button to appear and click it to continue
    *******************************WARNING*****************************************

    I had this "popup" actually come up. I waited, i saw the "cancel" button, i waited, i saw the "close program" button. i clicked it.

    So, I think, i must have a SteelWerX WhoAmI infection which, maybe MGtools.exe has fixed, maybe not.

    2/
    I will delete all my temp files.


    3/ timeline
    Okay transaction. User logged into bank using username, password and dongle.
    user organised $10,000 transaction from particular account, bank 1, to another account, bank 2. saved bank details used. dongle used.

    bank 1's (Suncorp) web portal has the ability to edit destination details after destination selected.

    bank 2 (ANZ) details completely changed, (how is this possible??)

    bank 3 (CBA) details put in, bank 3 account. completely different bsb and account details (still same country).

    this incorrect transaction was only realized 7 days later, turns out.

    the text details on the transfer was "ANZ account".

    two weeks ago.


    1 week after this transaction, user tried to log into ANZ accounts using same PC. no idea about fraudulent transaction, no worries about anything.

    ANZ reports : possibly fraudulent connection, you need to install 3rd party software to log into our accounts now.

    User freaks out, installs ANZ propriety software re a phone conversation and an email


    I have tried to condense the email neatly and failed. I believe ANZ has this propriety software available, I don't think it's malware.
    ============================================================================
    Dear [Users name in full],

    Following on from our conversation, we recommend that you install IBM/Trusteer Rapport on your workstation. We are confident that this program will identify the malware that has infected your machine.

    Please note: Trusteer Rapport should not be used to replace your antivirus program.

    Install Trusteer Rapport
    IBM/Trusteer may be downloaded by pasting below link in the browser:
    www.anz.com/securitysoftware
    • Click Download Links (top right of screen)
    • Select ANZ Bank
    • Click download on the correct Operating System



    • For technical support to install Rapport paste below link in the browser:
    http://www.trusteer.com/support
    Confirm installation
    Go to: Start->All Programs->Trusteer EndPoint Protection-> Trusteer EndPoint Protection Console
    If you can see above shortcuts on your workstation and the Trusteer console opens up successfully, it means that Rapport has been installed on the workstation.
    Obtain Trusteer Rapport ID
    Open the Trusteer EndPoint Protection Console
    In the Product Settings then click on more settings
    Click on the Copy Trusteer EndPoint Protection ID button, then reply to this email by pasting the information on the email.
    https://forums.majorgeeks.com/file:///C:/Users/Workshop/AppData/Local/Temp/msohtmlclip1/01/clip_image001.jpg

    Call ANZ
    Once Rapport has been installed, please call our ANZ Internet Banking team on 133350 (24/7) or for ANZ Internet Banking for Business call 1800 269 242 (8AM-8PM AEST Monday-Friday) to have your Internet Banking access reinstated.
    Kind regards,
    James Munday | ANZ | Digital Fraud Case Officer | Digital Fraud | Customer Protection
    Level 5A, 833 Collins Street, Docklands 3008, Australia | P: +61 3 8655 3023 | www.anz.com

    ====================================================================================
    After conversation and installing software for accessing ANZ accounts, customer realized $10,000 transaction had gone awry, and called up bank manager at suncorp.

    Suncorp had no idea about this transaction or any problem. they are chasing it up now with CBA.
     
    Last edited: Jun 7, 2019
  12. huntin

    huntin Private E-2

    I understand the previous reply may be a bit confusing. I can condense any parts that do not make sense if required.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The notice when running MGTools is normal and safe. Do you still have the log from running Trusteer? I have not found any malware. What dongle? Is your WiFi dead on your computer and you are using a USB WiFi dongle? If so, where did that come from?
     
  14. huntin

    huntin Private E-2

    The dongle is a piece of hardware issued by suncorp that shows a new code every 30 seconds that is needed to log in and to do transactions.

    I will find the log from Trusteer. I'm not back there until next Wednesday.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ah...good to know. I am afraid that what ever happened, there may no longer be any evidence of it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds