Hijacked, passwords changing!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mikeinstlouis, Sep 11, 2006.

  1. mikeinstlouis

    mikeinstlouis Private E-2

    Hello,

    I have posted several logs in the past (at another forum) regarding a problem I have been having with someone who has nothing better to do than to mess with my computer from some remote location.

    I was on the phone last week and someone told me...hey..did you know that you just logged on to yahoo messenger? Well, it was not me. In fact, I have been logging on to several different sites, but it is not me

    My yahoo messenger passwords keep changing, so that I have to change them again.

    The problem started last Feb. To make a long story short, I got an email sent to me from another one of MY email programs telling me not to *#$& with a hacker....I do not know this guy personally nor do I care to meet him.

    I logged on to a friends computer, and this guy said he put a "worm" on his computer, thus getting my passwords.

    He still has access to my system

    I called the police. They were useless. The guy talked down to me like I was a moron. I am a surgeon, so I am not that dumb. This guy was a joke.


    Here is what I have done.


    I have run Norton Antivirus, corporate edition.
    I have run Panda, and several others online

    I have zone alarm (which he said was USELESS)

    I have submitted hijack this logs

    I have spybot and adaware and spyware doctor.

    The "cop" told me that I would never find it and to buy a new hard drive

    BEFORE, I do that...is he right?

    I think this guy put a worm or keylogger on my system that I can not find. I was told by "the cop" that I would never find it.

    If I DO have to reformat my harddrive, is there a good firewall that would protect this from happeneing again???

    ANY advice from someone who really knows this and feels comfortable helping would be appreciated.

    Thanks

    Mike in St. Louis
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Mike if their is some sort of malware/trojan/keylogger on your PC, then follow the below guide which should clean all of the easier issues and then highlight any other remaining ones,

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis

    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. mikeinstlouis

    mikeinstlouis Private E-2

    Thank you for your response. It will take me a while to download and follow all of the instructions.

    My question...I have read numerous sites online that say that they have keyloggers etc that are undetectable. My fear is that I have one of these. How likely is following your prodedure going to help me?

    I am not having problems per se...but someone I think is monitoring everything I do.

    Should all of this help?

    Thanks

    Mike in St. Louis
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    We will find out once you have attached the logs, while very possible that a keylogger may hide itself, it still will have an active .exe file, wht firewall do you have installed? if its just th ewindows one it will not alert you to any outgoing programs that require internet access, so get something like ZoneAlarm free ( available from the main downloads section of this site )

    If you have a firewall that alerts you to outgoing software then is their any strange applictions in the software list, eg. may have a name like dbjsue.exe * basically random letters/numbers*?

    Best thing Mike is to run through the guide and we can go from their.
     
  5. mikeinstlouis

    mikeinstlouis Private E-2

    I am working through the tutorial. My computer is running v.e.r.y. s.l.o.w.l.y.

    I am up to the bit defender scan...so far...nothing.

    I am running Zone Alarm free. The cop here in St. Louis told me it was worthless.

    Does this guy know what he is talking about? He started out the conversation telling me how busy he was cause he was such an excellent expert. That alone scared me. His advice was to get a new hard drive and pitch the old hard drive and a to get a firewall called Astaro.

    Thanks

    Mike
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ZoneAlarm is a good software firewall. It can sometimes be a little resource hungry on some PCs but all protection software will slow your PC down somewhat. For some applications like ZoneAlarm the amount it slows you down is a tribute to how effective a job it is doing. The free version of ZoneAlarm is quite good especially when you consider it is free. The Pro version is even better.

    As far as Astaro, I believe they make hardware firewall & software security applications to go along with the hardware. These are more meant for business use (small companies) than for a home user. And they can be quite expensive. What is your application (home or business)?
     
  7. mikeinstlouis

    mikeinstlouis Private E-2

    This is for my home. I am a doctor on call for a 48 hour shift. When I return home, I will hopefully have all of the requested logs. Bitdefender found nothing and the Panda found two items that I could not see because I ran it in safemode and I could not scroll to the part where I could see it (the pic was huge)

    I have yet to do the HJT log and the other two things....but I will...according to the directions that you guys gave.
     
  8. mikeinstlouis

    mikeinstlouis Private E-2

    Dear Friends at Major Geeks.

    I am done with the tutorial.

    Here is what I did.

    I did the house cleaning where I removed 2 items from my Norton Antivirus Quarantine.

    My hidden files etc were already viewable, but I double checked to be sure.

    I use only Norton Antivirus Corporate and Zone Alarm Free

    I ran the Ccleaner with no problems while in Safe Mode

    I ran the Windows Malicious Software Removal Tool while in Safe Mode (but in retrospect I believe I downloaded this and the Windows Defender to my desk top and ran them from there...is that ok?)

    Spybot S & D did not find any threats

    I ran the Windows Defender and I think it found one thing...a cookie...while in Normal Mode.

    While in Safe Mode, I ran Bit Defender and Panda. The Panda found two problems but since I was in Safe Mode, I could not get to the Save Report tab...I re-ran it in Normal Mode...if found 2 problems and I saved the report.

    I followed the HJT instructions (after removing a prior installation). I made a folder in my programs file, extracted and renamed to analyse.exe. I ran the program and I have the log for you guys.

    I have not yet done the Toggle System Restore, since I am unsure if this Keylogger/Worm nasty thing is off.

    I followed your instructions to the letter with the exception of running the malicious remover and windows defender from my desk top rather than a new folder on the c:\ root

    Here are my logs...I will redo it all again if it is not correct, please just let me know.

    Thank you guys SO MUCH for your time.

    Mike
     

    Attached Files:

  9. mikeinstlouis

    mikeinstlouis Private E-2

    And here are the rest of the attachments.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see an application that could be used by a hacker: LogMeIn

    Did you install LogMeIn and do you or have you used it? Is it password protected?

    What about Keylogger Hunter 2.1? Did you install this?

    Let's cleanup a few things!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
    O4 - HKLM\..\Run: [GNP Generic Host Process] C:\RECYCLER\RS-1-5-21-606747145-1085031214-725345543-500\taskmgr.exe

    After clicking Fix, exit HJT.
    Now empty your Recycle Bin!
    :
    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC and post a new HJT log.
     
    Last edited: Sep 18, 2006
  11. mikeinstlouis

    mikeinstlouis Private E-2

    Thank you. I will get to all that you told me to do, but I wanted to say that Yes..I installed the logmein.com....and it is password protected.

    I also installed the keylogger hunter under the advice of another site.

    I will post the new HJT log.

    THANK YOU!!!!!!!!:)
     
  12. mikeinstlouis

    mikeinstlouis Private E-2

    Here is the latest HJT log after following all of your instructions.
    The computer is still moving along very slowly..but I guess we can look at that after we find the nasty worm that is stealing my passwords. Thanks
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean!

    As far as a slow PC is concerned:
    • Is Ewido a free trial or paid version?
      • If free, uninstall it.
      • If paid, keep it and uninstall Windows Defender.
    Did that help?
     
  14. mikeinstlouis

    mikeinstlouis Private E-2

    Unsure if I am clean.

    My log is clean? Are you guys sure?

    I read on line about things like eblaster that say they are undetectable and the only way to get rid of them is with a reformatting of the hard drive. How can I be as sure as possible that this thing is clean? I trust you guys, but all these keylogging programs that I read about online say that they are undetectable. If this were your computer would you feel it was safe?

    Regarding the ewido, it is the free version. I can get into the slow thing if you guys really think I am cool with the nasties being gone. Thank you SO SO SO much for everything.

    Mike
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Unsure if I am clean.

    Based on the info that we are able to get from you via these logs. Yes we are sue. Are we 100% sure....no! We could only do that if we sat in front of your PC and used specialized tools to capture all packets being received and transmitted from your PC and then performing a decode/analysis on them. Nothing can hide at that level, but we simply cannot do that remotely.

    If you are so worried about having a keylogger problem, then repartition, format, and reinstall your OS but that will not address the other PCs that you may use to do stuff. You did say at the beginning that you logged on to a friends PC and that was where your problems began. Perhaps you are cleaning the wrong PCs. You should never logon to any of your own password protect accounts from another persons PC. How do you know what they are running on their PC and how do you know they do not have any malware issues.

    You should uninstall it, and observe how the performance of your PC changes. If it is still slow, you could have other non-malware problems causing issues. We see them all the time when antivirus, antispyware, and or firewalls are causing slow downs. If they are temporarily uninstall and the problems go away, you can zero in on which is the problem. If the problems do no go away, then you need to look at what other software is loading and also at potential Operating Systems issues. And yes, then you could also possibly expect super hidden background processes/keylogger issues.
     
    Last edited: Sep 20, 2006
  16. mikeinstlouis

    mikeinstlouis Private E-2

    I understand that we can never be 100% sure, but let me ask you..in your honest opinion...is it very unlikley that I have this thing still, or 95% sure? I know you cant give me an exact number, but how likely is it that I am clean.

    Thanks for you patients.

    Mike
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I can say is that it is unlikely but to be totally honest it is not impossible.

    Did you uninstall Ewido to see if it made a change in your performance?
     
  18. mikeinstlouis

    mikeinstlouis Private E-2

    Yes, I did uninstall the Ewido and it made no difference. In fact it appears to be worse. I unistalled my Norton Antivirus and totally updated it ...still slow. I uninstalled Zone Alarm and updated it to the Pro...still slow

    Honestly, if I click on the internet explorer icon to get the browser up and running, I can leave and get something to drink, come back and it may have loaded. It is SO SLOW>

    I was wondering if it was the hard drive going bad, but it seems to be perfect while in safe mode.

    How can I see what the resource hog(s) are and clean this thing up.

    Should I go to a different forum site since you feel I am clean?

    I am so tempted just to start over...any advice is appreciated. Thanks
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall ALL of Norton/Symantec and also uninstall Keylogger Hunter and then attach a new HJT log and a new log from ShowNew. Also with Norton uninstalled, how are things running.

    Also run this Using Sophos Anti-Rootkit and attach the log.


    If you look in Task Manager under Processes you can usually see which process are using large chunks of your CPU time. Don't make the mistake that many people make......System Idle is not a process. It is your CPU's idle time and this number should normally be very high (97 to 99 while you are not clicking anything or running a scan).
     
    Last edited: Sep 22, 2006
  20. mikeinstlouis

    mikeinstlouis Private E-2

    Thanks,
    I am in KC now..I have an uncle in the hosptial...will run when I get back to St. Louis

    M
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Best wishes to your Uncle!
     
  22. mikeinstlouis

    mikeinstlouis Private E-2

    Thanks for all of your help guys...but my hard drive is taking about 45 minutes just to load up a web page! I am going to go ahead with the reformat. I have taken off my valuble files.

    If you can direct me to a post where they give advice on how to prevent these keyloggers, I would be greatful

    Thank you so much for everything.

    Mike
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds