No Idea

Discussion in 'Malware Help (A Specialist Will Reply)' started by JustJay, Aug 24, 2010.

  1. JustJay

    JustJay Private E-2

    Never had had a pop for my anti virus telling me I had anything. Though yesterday, the online game I play emailed me and shut down my character due to it being compromised. The last time my Avira said I had something trying to attack to my pc was probably a year ago. I ran the first 3 scans and going to post those logs.

    Rootapeal stalled overnight so I quit it after it was running for almost 18 hours, it was on the same thing from almost 10 hours ago as I just woke up.

    So if you want I'll run the scan from root and mgtool later if needed.

    Malware and Spyware showed nothing so no idea what is wrong. Combo said in the log that it already deleted a couple things so maybe in the logs you all can help.

    Thanks for any help.

    Jay
     

    Attached Files:

  2. JustJay

    JustJay Private E-2

    Just did the mgtool. Here is it's log.

    Thanks again for any help if anything is wrong.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. JustJay

    JustJay Private E-2

    Thanks a ton.
     
  5. JustJay

    JustJay Private E-2

    Any updates??

    Computer is running faster since the scans. So no idea what combofix deleted but it made my pc run a lot faster.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you read this?

    Don't Bump! It Only Hurts You!!!
    That's good to hear.

    Not seeing much to do here, we can tidy up the registry though:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. JustJay

    JustJay Private E-2

    Thanks so much and sorry for the bumping.

    One last quick question.

    If there wasn't anything wrong with those scans then how was my account hacked?

    I downloaded just now the free outpost firewall since I was only using the windows firewall.

    I just have no idea since I guess my computer was ok, how my gaming account was compromised and hacked?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The only thing I can suggest is that you use a different computer to change your password on your game> and if you continue to have issues with it, contact the web site. :)
     
  9. JustJay

    JustJay Private E-2

    Still being hacked or most likely keylogged. Everytime I log into the game(wow) Outpost firewall says in it's event logs that it has block a WOW>EXE keylogger but they are still changing my password and everything.

    No clue how this happened since you said my logs are clean and every scan I've done has showed them to be clean.

    One question is that I recently bought a new wired router so I can have netflix on my wii as well. Can that make it easier for hackers to get at my pc? I'm just grasping straws here.

    Any help again I'll be really thankful for.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If your firewall is BLOCKING it, then it did not get in! Outpost is obviously doing it's job ;)

    As I said, do ask the people at WOW as online gaming is not my thing.
    You can visit the networking forum to further discuss this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds