Logs - Exploited? - Data Security Breach Information

Discussion in 'Malware Help (A Specialist Will Reply)' started by drcarl, Jul 23, 2013.

  1. drcarl

    drcarl Staff Sergeant

    Greetings Geeksters,

    TIA.

    I believe I've been exploited. Perhaps it was a pop-up disguised as a Silverlight update; something I'd long ago decided I didn't want, then installed, so, I hurriedly supposed I wanted the update. Silly me.

    Now I have to say this one is cool (the bad kind of cool), it's artful in its nastiness. It's not a constant inconvenience, just an occasional one. Sly. As I surf, I occasionally get either >>an offer<< within a new smaller window, or a "Data Security Breach Information" with a paragraph and an opportunity to get all three major credit reports for FREE!, also in a smaller new window. (I thought they had to supply one for free anyway?!?). I didn't follow/click that path, but I bet they'd be asking for a SSN - for all the good that'd do them - lol. The rest of the message reads like this:

    Attention ICANN Visitor,

    Data Security Breach Information

    We want to make you aware of a significant incident that has occurred. There was a massive system breach at Global Payments, a company that processes credit card transactions for a number of companies, including Visa, Mastercard, American express, Discover and other major credit card brands. Files containing personal credit card information were compromised. We are urging you to check your credit profile for any activity that you did not authorize.​

    I've got something they can check...besides, I am a Dear Carl, not a Dear Visitor...

    ANYway, I have follow the READ & RUN ME FIRST instructions. I'll attach the logs. I can't really say whether or not I am "still having problems" yet I do know that one of the scans, HitmanPro I think, found a bunch of malware. I really wanted to tick the fix it button, but I followed instructions and did not, so, I assume the baddies are still there.

    At first, I opened but did not run TDSSKiller. I believe it made a log anyway, so, it's attached here, then TDSS #2 (after I ran it), then HitmanPro...and, therefore, I hit my maximum and the MGLog will be in the next post.

    Please advise. Like everyone, I wanna be clean.

    Thank you for all you have done, do, and continue to do.

    You help the net be a safer and better place.

    Best,

    ~drcarl
     

    Attached Files:

  2. drcarl

    drcarl Staff Sergeant

    The 6th file....MGLogs zip attached

    ;)
     

    Attached Files:

  3. drcarl

    drcarl Staff Sergeant

    .
    I am adding this well-written description that another user posted elsewhere on the forum. Rather than following the instruction provided for him, I await your leadership... patiently... lol

     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rescan with Hitman and have it delete all it found.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now tell me what issues remain, if any.
     
  5. drcarl

    drcarl Staff Sergeant

    TimW,

    Thank you for your reply and direction. I followed the steps and things are looking good, yet, I am hesitant to claim being in the clear until after more time has passed. This exploit was (I hope it's a "was") a real smooth one...not "in your face" like most of them...just a little ad here, and a little redirect there... (A$$H0L3 TIME WASTERS)

    Log attached. I'll repost here if any problems rear their ugly heads.

    Thank you agin TimW and any and all MGeeksters!

    Best,

    ~drcarl
     

    Attached Files:

    • JRT.txt
      File size:
      6.9 KB
      Views:
      2
  6. drcarl

    drcarl Staff Sergeant

    Oh no. Another pop-up ad that was not asked for and appears in smaller new window. (BTW, I have AdBlockPlus running on Chrome) Also noticed more of the same...small square ad in lower right. Nutz! At least now the ad video or text is absent and just the box appears.

    I re-ran JRT and it removed "pc speed up" :
    "Successfully deleted: [Folder] "C:\Program Files (x86)\pc speed up"​
    ...which on review of the first JRT log, it "failed to remove"

    I ran CCleaner's Cleaner and Registry tool. Rebooted. Ran JRT again (as administrator). Nothing found. Attached JRT logs 02 and 03. Ran Hitman Pro (as admin): -0- threats. Ran MGTools and attached log. Ran analyse.exe and attached log.

    I notice that programs (CaptureWiz, DSClock) previously set to launch on startup no longer do, and the start with Windows tick box is clear - So, I am re-checking/ticking them as I notice I'm missing things.

    Now what? *sigh*

    (Thanks for your help)


    PS - I started keeping a list of malware notices/pop-ups in case that matters at all; most current at the top.

    Pop-up sites:

    ----------before (and during) the SECOND cleanup - boo hoo------------------

    http://www.cbs.com/shows/star_trek_deep_space_9/?ttag=mktg_ntp_SD_vid_0601_fa
    (appeared while browsing MG in Chrome)
    http://www.cbs.com/shows/the_twilight_zone/?ttag=mktg_ntp_CTZ_vid_0712_fa
    (opend while viewing HowToGeek)
    http://winnervisitors.com/a/cs/top/3.php?target=Revouninstaller.com
    (the pop-up above appeared after I started Revo Uninstaller)
    http://www.cbs.com/shows/elementary/video/?ttag=mktg_ntp_E_vid_0125_fa
    http://www.match.com/en-us/landing/...36_10189437_1112204_10189447_1x1&CPV2=okcupid

    ----------before the FIRST cleanup------------------

    http://www.pogo.com/?sourceid=camEGP_Gamevance_LandingPageLoad_RON_FreePogo_Homepage_Landingpageload
    http://lifestyleinsights.org/score/notice-r.php?keyword=Ww.amazon.c
    http://www.beautyriot.com/celebriti...&utm_source=trafficvance&utm_term=Okcupid.com
    http://winnervisitors.com/a/cs/top/8.php?target=Icann.org
    http://www.folica.com/?s_sku=cj_&s_...utm_medium=affiliate&utm_campaign=paff3087676
     

    Attached Files:

  7. drcarl

    drcarl Staff Sergeant

    I am still troubled with this pest.
     
  8. drcarl

    drcarl Staff Sergeant

    Still troubled, adding to list of pop-up ads.

    OMG! Since the problem kinda feels like an extension in that it seems to be browser-related, I re-reviewed what extensions I have enabled in chrome. I found something [damn; forgot the name. I think it was "TopArcadeHits"] that offered 2000? of the best arcade hits. I didn't want that. Goodbye extension!

    We'll see.... maybe fixed.

    QUESTION: I ran RogueKiller and it found some entries noted under the Registry tab. I want to hit "delete" yet am wary of reg edits without someone telling me to go for it. So, pleaSe see attached report...is it safe to delete these?

    Thanks,

    ~drcarl

    Continuing list of pop-up destinations, new on top:

    http://www.basictalk.com/?CMP=ONB-FLS-OTHER-FUTAD-2013-BASICTALK-VER1-PHONE

    ----------before (and during) the SECOND cleanup - boo hoo------------------
    http://www.cbs.com/shows/star_trek_deep_space_9/?ttag=mktg_ntp_SD_vid_0601_fa
    (appeared while browsing MG in Chrome)
    http://www.cbs.com/shows/the_twilight_zone/?ttag=mktg_ntp_CTZ_vid_0712_fa
    (opend while viewing HowToGeek)
    http://winnervisitors.com/a/cs/top/3.php?target=Revouninstaller.com
    (the pop-up above appeared after I started Revo Uninstaller)
    http://www.cbs.com/shows/elementary/video/?ttag=mktg_ntp_E_vid_0125_fa
    http://www.match.com/en-us/landing/...36_10189437_1112204_10189447_1x1&CPV2=okcupid

    ----------before the FIRST cleanup------------------
    http://www.pogo.com/?sourceid=camEGP_Gamevance_LandingPageLoad_RON_FreePogo_Homepage_Landingpageload
    http://lifestyleinsights.org/score/notice-r.php?keyword=Ww.amazon.c
    http://www.beautyriot.com/celebriti...&utm_source=trafficvance&utm_term=Okcupid.com
    http://winnervisitors.com/a/cs/top/8.php?target=Icann.org
    http://www.folica.com/?s_sku=cj_&s_...utm_medium=affiliate&utm_campaign=paff3087676
     

    Attached Files:

    Last edited: Jul 24, 2013
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  10. drcarl

    drcarl Staff Sergeant

    Thanks TimW - here it is
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still having issues? If so, what.
     
  12. drcarl

    drcarl Staff Sergeant

    I might be OK since I trashed the "TopArcadeHits" extension in Chrome. I think it might take some time to tell.

    Meanwhile, I'd love to delete what RogueKiller found. Log with Post #8. I wonder if it's safe to press the delete button within RK?

    And, thanks for your consideration here....
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can delete the log. Just right click and chose delete. Let me know if you have any more issues.

    In the mean time:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix
      (This uninstall will only work as written if you
      installed
      ComboFix on your Desktop like we requested.
      )
      • Click START then RUN and enter the below into the run box and then click OK.
        Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows
          defaults.

    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the
      C:\MGtools\enableUAC.reg
      file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file
      to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush
        your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  14. drcarl

    drcarl Staff Sergeant

    OK, got it. Right-click to delete logs.

    Now, please view the attached screenshot.

    These look more like "entries" or "items" than a "log."

    What I am asking about (I believe in posts #8, #12 and now #14) is this: Inside the RogueKiller software application, after a scan, under the "Registry" tab, there are about 8 pre-checked entries which appear to be candidates for deletion. Is it safe to delete them?

    There is also an IP address listed under the "Hosts" tab. Is there something to be done with that?

    I'll carry-on with the other instructions.

    Thanks you,

    ~drcarl
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just leave them alone. They are fine. No need to mess with that. Just normal things that RogueKiller finds but is nothing to worry about.
     
  16. drcarl

    drcarl Staff Sergeant

    Thanx TimW
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds