Dreaded Bitcoin / Keylogger Threat.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Oooops!, Dec 6, 2019.

  1. Oooops!

    Oooops! MajorGeek

    I've been threatened with a bitcoin / keylogger / pay up now within 48 hours kind of threat.
    The person used my own e-mail address as the "sender".

    Am I safe after running full scans with the below programs?

    SUPERAntiSpyware
    Malwarebytes
    Spybot - Search & Destroy
    Windows 10 AntiVirus

    Is there a keylogger detection program that I need to try?
    Thank you.
    :confused::oops:
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would have no idea without seeing the logs you have and the logs needed from the Read and Run First instructions.
     
  3. Oooops!

    Oooops! MajorGeek

    Attached AdwCleaner logfile.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    FYI...you can attach 5 logs in a post. :)
     
  5. Oooops!

    Oooops! MajorGeek

    Attached what I could.
     

    Attached Files:

  6. Oooops!

    Oooops! MajorGeek

    MG Tools
    - Had to save MG Tools to desktop.
    - Disabled antivirus.

    Problem...
    - A window appears, "Registry editor is requesting your permission", I accept, but it gets stuck in a constant loop asking the same question, very difficult to get out of. Even tried using "Esc".
    - The window is still open, a small icon at the bottom of my screen is flashing, not sure if I can get out of it.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is supposed to be directly on the C: drive so why is it trying to run in a command prompt?
     
  8. Oooops!

    Oooops! MajorGeek

    I'm sorry, I have limited computer knowledge, I'm not able to answer your question.

    At the bottom of my screen, (task bar?), one square when I hover my cursor over it, shows a preview of a black window C:\WINDOWS\system32\cmd.exe.

    Another square on the bar is flashing orange. When I hover my cursor over it, it says, "Registry editor is requesting your permission". When I accept, it goes to the black window, then back to the permission window. It's stuck in a loop of asking me to accept. I have to constantly press Esc to get out of it.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click and close window.

    Now go back to the desktop where you have MGTools.exe and right click it and run as administrator.
     
  10. Oooops!

    Oooops! MajorGeek

    Thank you.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can't find any malware in your logs. Is there something going on that is concerning you?
     
  12. Oooops!

    Oooops! MajorGeek

    Hi, yes.

    I'm fairly cautious with what I do on the internet, where I go and what I click on. I basically visit the same sites.

    I'm used to receiving suspicious / junk e-mail from time to time, but this one seemed different, sudden and persistant. I would report it under the "phishing" tab in my e-mail, then block the senders e-mail address. I noticed the last part after the @ sign started repeating. I was able to block it as a whole and once I did, I received the threatening e-mail... (they used my e-mail address as the senders name, my e-mail program recognized it as "junk"). No attachments or links were opened.

    various names @ opensubscribe
    various names @ usesubscribe

    I knew the e-mail was likely a scam, but when they turned it around and used my own e-mail address, it scared me for a moment wondering if they could actually do any harm.

    Thank you for your help, I appreciate your time very much.
    Many, many, thank yous!!!
    :)
     
    Last edited: Dec 6, 2019
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     
    Oooops! likes this.
  14. Oooops!

    Oooops! MajorGeek

    Hi.

    I've noticed a couple of images that now appear after the above steps have been done.

    In some folders, I'll see an image of what looks like a jagged wheel.
    Sometimes this wheel is named "desktop" or "picasa".

    Also, after I edit a document in OpenOffice, I'll see an image that appears only for a second, to the left of the file.
    This image is named .~lock.1. and includes the name of the document that I was working on.

    I've tried to delete the wheel images, but they come back.
    Thank you.
    Image.JPG Image2.jpg
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run the MGClean.bat?
     
  16. Oooops!

    Oooops! MajorGeek

    I found the C:\MGtools folder, but it's empty.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you will need to re-download MGTools.exe, run it and then do the clean up with MGclean.bat.
     
  18. Oooops!

    Oooops! MajorGeek

    Think I've got it now, had to click on run as Administrator, or else it goes into that crazy loop again.
    (The .~lock.1. picture still flashes for a sec, but that's ok).

    Thank you.
    Merry Christmas Eve.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds