Am I Being Hacked? Are They Copying My Files Remotely?

Discussion in 'Malware Help (A Specialist Will Reply)' started by massillimo, Apr 17, 2015.

  1. massillimo

    massillimo Private E-2

    I Found the Following Logs in AppData in Windows 7.
    **********************************************************
    FILE NAME jusched.log

    CONTENTS

    [2015/04/11 23:37:37.719, jusched.exe (PID: 3108, TID: 3112), SysInfo.cpp:214 (SysInfo::getSystem32Dir)]
    ERROR: GetSystem32Dir failed with COM error 0x8007000D (The data is invalid)
    [2015/04/12 01:08:01.925, jusched.exe (PID: 3496, TID: 3500), SysInfo.cpp:214 (SysInfo::getSystem32Dir)]
    ERROR: GetSystem32Dir failed with COM error 0x8007000D (The data is invalid)
    ****************************************************
    FILE NAME LogFile.txt

    Backend construcor called.
    Backend Initiallized.
    Backend destructor called.
    Backend clear function called.

    ***********************************************
    FILE NAME Swtag.log

    CONTENTS

    2015-04-12 00:25:11 [3760] SWTAG: _info_: ==========================================
    2015-04-12 00:25:11 [3760] SWTAG: _info_: Start SWTAGGING productName=Acrobat Pro; productAdobeCode={AC76BA86-1033-F400-7760-000000000004}; driverName=Acrobat Pro; driverAdobeCode={AC76BA86-1033-F400-7760-000000000004}
    2015-04-12 00:25:11 [3760] SWTAG: _info_: GetNamedSecurityInfo for tag file "C:\ProgramData\Adobe\ISO-19770\Acrobat Pro-{AC76BA86-1033-F400-7760-000000000004}.swtag" returned 0
    2015-04-12 00:25:11 [3760] SWTAG: _info_: SetNamedSecurityInfo for tag file "C:\ProgramData\Adobe\ISO-19770\Acrobat Pro-{AC76BA86-1033-F400-7760-000000000004}.swtag" returned 0
    2015-04-12 00:25:11 [3760] SWTAG: _info_: Created new C:\ProgramData\Adobe\ISO-19770\Acrobat Pro-{AC76BA86-1033-F400-7760-000000000004}.swtag file
    2015-04-12 00:25:11 [3760] SWTAG: _info_: End SWTAGGING
    2015-04-12 00:25:11 [3760] SWTAG: _info_: ==========================================


    2015-04-12 00:26:21 [2952] SWTAG: _info_: ==========================================
    2015-04-12 00:26:21 [2952] SWTAG: _info_: Start SWTAGGING productName=Acrobat Pro; productAdobeCode={AC76BA86-1033-F400-7760-000000000004}; driverName=Acrobat Pro; driverAdobeCode={AC76BA86-1033-F400-7760-000000000004}
    2015-04-12 00:26:21 [2952] SWTAG: _info_: Reading existing C:\ProgramData\Adobe\ISO-19770\Acrobat Pro-{AC76BA86-1033-F400-7760-000000000004}.swtag file
    2015-04-12 00:26:21 [2952] SWTAG: _info_: End SWTAGGING
    2015-04-12 00:26:21 [2952] SWTAG: _info_: ==========================================


    2015-04-12 18:21:42 [1300] SWTAG: _info_: ==========================================
    2015-04-12 18:21:42 [1300] SWTAG: _info_: Start SWTAGGING productName=Acrobat Pro; productAdobeCode={AC76BA86-1033-F400-7760-000000000004}; driverName=Acrobat Pro; driverAdobeCode={AC76BA86-1033-F400-7760-000000000004}
    2015-04-12 18:21:42 [1300] SWTAG: _info_: Reading existing C:\ProgramData\Adobe\ISO-19770\Acrobat Pro-{AC76BA86-1033-F400-7760-000000000004}.swtag file
    2015-04-12 18:21:43 [1300] SWTAG: _info_: End SWTAGGING
    2015-04-12 18:21:43 [1300] SWTAG: _info_: ==========================================
    ********************************************
    FILE NAME Updater.log
    CONTENTS

    : Loading AUM Integration library at path C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AdobeUpdater.dll.
    : Successfully loaded AUM integration library
    : Successfully found all library entry points. Library is valid.
    : Entering GetAppID()
    : AUMDoPluginAction returns => 0
    *********************************************
    FILE NAME wmsetup.log

    CONTENTS

    [*WMC Logging begun at 2015/04/12 - 03:14:26. Logging at level: '4'. OS is NT. OSVer is 6.1.7601.0.17514. System Lang is 1033. Prev version system is 12.0.7601.17514. Setup version 12.0.7601.17514.]
    Setup commandlines are "C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1.
    Services information URL is : 'http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86'.
    Unable to establish connection: 0xc00d0bca.
    Service data gathering complete: 0 interesting service(s) found. Result 0xc00d0bca.
    =====Updating Install list for UI.
    Install list not generated or parsed for this install type.
    Finished updating install list.

    [*WMC Logging begun at 2015/04/12 - 05:45:42. Logging at level: '4'. OS is NT. OSVer is 6.1.7601.0.17514. System Lang is 1033. Prev version system is 12.0.7601.17514. Setup version 12.0.7601.17514.]
    Setup commandlines are "C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1.
    Services information URL is : 'http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86'.
    Unable to establish connection: 0xc00d0bca.
    Service data gathering complete: 0 interesting service(s) found. Result 0xc00d0bca.
    =====Updating Install list for UI.
    Install list not generated or parsed for this install type.
    Finished updating install list.

    [*WMC Logging begun at 2015/04/12 - 17:53:30. Logging at level: '4'. OS is NT. OSVer is 6.1.7601.0.17514. System Lang is 1033. Prev version system is 12.0.7601.17514. Setup version 12.0.7601.17514.]
    Setup commandlines are "C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /Play -Embedding.
    Services information URL is : 'http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86'.
    Unable to establish connection: 0xc00d0bca.
    Service data gathering complete: 0 interesting service(s) found. Result 0xc00d0bca.
    =====Updating Install list for UI.
    Install list not generated or parsed for this install type.
    Finished updating install list.


    I also found in Appdata
    remotecache.zip
    a screenshot of my userID


    DOES ANYONE KNOW "BACKEND CONSTRUCTOR"
    i GOOGLED AND SOMETHING CAME UP "DUPLICATI"
    WHAT IS SWTAGGING?

    ANY SUGGESTIONS?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds