My accounts have been compromised...

Discussion in 'Malware Help (A Specialist Will Reply)' started by bl00ey, May 5, 2010.

  1. bl00ey

    bl00ey Private E-2

    Up until today I thought I kept my system pretty clean, however I have had a few of my accounts compromised and I can't seem to find out how they got my information.
     

    Attached Files:

  2. bl00ey

    bl00ey Private E-2

    Thanks in advance for any help.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Was this before or after you installed KeyScrambler?

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\lgfwunis.exe

    I would like you to do an online scan:
    Using BitDefender Online Scan.
     
  4. bl00ey

    bl00ey Private E-2

    They were compromised before the I installed the keyscrambler. An hour or so after I installed that I worried about it's security so I uninstalled it, I guess not everything was uninstalled though.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log was clean. I don't understand why you removed Keyscrambler if you were concerned about security. Plus I am not seeing anything in your logs at this point that could be cause for concern. You didn't mention what accounts were compromised. Did you alert you bank (s)? Did you use a different computer to change any online passwords?

    What issues are you still having?
     
  6. bl00ey

    bl00ey Private E-2

    My accounts got compromised. I ran scans and found nothing that explained how they got compromised in the first place. I feared a keylogger that I or the scans weren't seeing so I installed keyscrambler that I came across on mozilla. At that point I had never heard of it, I decided to give it a try.

    I uninstalled it for a few reasons. I had never heard of it and I worried that maybe it could be keeping track of my keystrokes instead of scrambling them. Secondly, I have never had a problem on my computer that I could never take care of myself. I always keep it clean and up to date, and everything that I've ran on this computer since I discovered the compromises have come up clean, so I didn't think I really needed keyscrambler but rather to find out the underlying issue (which I hoped you'd see but there's nothing). Thirdly, not only my email and bank account were affected, my world of warcraft account was too and keyscrambler would not help with logging into WoW.

    Yes the bank was notified and all my passwords have been changed from a separate computer.

    I am not having any issues according to all the scans, they have come up clean all along. I just needed someone else to look and see if there was something I was missing. I don't understand how my information was obtained if nothing is being found on my computer. So my computer is and has been safe since the beginning which must mean that my information was got in some other fashion... but I don't know how.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It well could have through your email. That is one area that you need to clean out yourself. But it is a guess.

    Here are general guidelines for dealing with infected email accounts:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    Let me know if something comes up, but since you are not having any issues at this time, then:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  8. bl00ey

    bl00ey Private E-2

    I only use online based email, but it is my suspicion that my gmail account is in fact where it all started. I have changed anything important that I had going there to a fresh non gmail account and will close that account now.

    Thanks for your help, it's put my mind to ease about my computer. :)
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds