Debit Card # compromised

Discussion in 'Malware Help (A Specialist Will Reply)' started by hybridzero35, Feb 14, 2011.

  1. hybridzero35

    hybridzero35 Private E-2

    Hi majorgeeks!

    I haven't used this stuff in a long time. Today I just found out computercops was taken down (yea I'm late in the news!). I used to frequent that site for checking up certain suspicious programs. But now it's down, I am lucky that there are still helpful volunteers out there, because I have completely zero idea what I'm doing in terms of looking for hackers. Anyways, my debit card was compromised and I called my bank to shut it down on the second. Didn't even give them time to process the transaction (however it needs to process for me to get recredited).

    Anyways, enough of background and here's the relevant information. I don't click on random ad's, frequent only a couple sites for years now. Don't click on spam mail. I've ordered from sites that I frequent as well, nothing suspicious. However, at that time I did switch to Chrome and maybe it wasn't as well protected as my Firefox, this is why I'm thinking it's possible I got some type of trojan, hacker, or logger. Uninstalled Chrome right away.

    1. Did you use any other PCs to make purchases at anytime?
    no
    2. What online stores?
    Nothing out of particular.
    3. Have you contacted all stores to ask them about any potential issues?
    No, but they're large corporations so either they won't tell me or it didn't happen. Most likely the latter.
    4. Does anyone else ever have access to your PC?
    Nope. It was a phishing scam either way.
    5. Have you changed the passwords on your PC and to all of your online accounts ( all accounts everywhere ) including email accounts?
    Yes.
    6. Why do you have LimeWire running at startup and have you had this active while doing online purchases? This leaves your PC open for unauthorized access!!! You should uninstall this and stop using it or anything like it.
    No limewire. Not for 10 years on a different computer.

    So far, I've ran ComboFix, Malwarebytes, CCleaner, and HiJackthis. Here are the logs too.

    Thanks
    Phil
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need you to attach the other requested logs:
    SAS
    RootRepeal --> if it will run
    C:\MGLogs.zip
     
  3. hybridzero35

    hybridzero35 Private E-2

    I have 64bit so root repeal will not run. However, here are the other two files. Thanks for pointing this out.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you have done the regular things to protect yourself ( changing passwords, etc.) my guess is that you may have been a victim of a walk by card cloner as I am not seeing any malware in your logs.

    However, do you know what these are:
    C:\jaxgyxqw.txt
    C:\wedaolu
    C:\ZBMWX

    If not, delete them.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  5. hybridzero35

    hybridzero35 Private E-2

    Thank you big time. I can rest assured that my crap isn't being spread across the internet... yet.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds