Possible keylogger

Discussion in 'Malware Help (A Specialist Will Reply)' started by BrankoZ, Dec 1, 2009.

  1. BrankoZ

    BrankoZ Private E-2

    I play an online game (GuildWars). I didn't log in for a few weeks, and when I did my account was empty of nearly all in-game money and items. I contacted support, and they informed me that my account was blocked because it was, "...accessed by gold sellers from China". They suggested that this may have been caused by a keylogger. Most of my logs appeared fairly clean from what I'm able to tell, but wanted a second opinion on whether there's something I can't see. I tried to follow all the instructions to the letter. First four attached here. You guys have been great in the past. Thanks in advance for whatever.
     

    Attached Files:

  2. BrankoZ

    BrankoZ Private E-2

    Fifth attachment
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Kes13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing anything much to do here... let's start with the below:

    Is your copy of Spyware Doctor 6.0 a free trial (which is useless anyway) or paid for software? If it's simply a trial then please uninstall it from Add/remove Programs.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Windows\temp\0446ad60-40a6-40f4-93c5-b253e9a90f57
    C:\Users\Brian\AppData\Local\temp\$.ficn$
    C:\Users\Brian\AppData\Local\temp\159d6bc1-ad91-4858-8ad0-5ec87bfb6073.mht
    C:\Users\Brian\AppData\Local\temp\a.wnd.tmp
    C:\Users\Brian\AppData\Local\temp\DLL_{16C9924C-C42A-4790-BD18-27BDCA4B23C1}.ini
    C:\Users\Brian\AppData\Local\temp\e163fb4b-bd33-4061-b5df-1da4fa284081.mht
    
    Folder::
    C:\Windows\temp\0446ad60-40a6-40f4-93c5-b253e9a90f57
    C:\Users\Brian\AppData\Local\temp\2704-1-2009-12-2-2-10-35-679
    C:\Users\Brian\AppData\Local\temp\FCTB000061017
    C:\Users\Brian\AppData\Local\temp\is5C23.tmp
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. BrankoZ

    BrankoZ Private E-2

    Hello Kestrel - Thank you for your reply, sorry it took me a while to respond. I'm relieved to know there wasn't much on the logs. I'm pretty careful about what I do online, and frankly I don't believe this gaming company that it was something I did that led to my account being hacked; I think they're just not admitting that their login servers were compromised.

    Anyway, here are updated logs. Couple problems with the instructions. I disabled the Resident Shield in AVG, and exited Comodo Firewall, but ComboFix still recognized them as open. I didn't know how else to close them, and wasn't comfortable just ending the processes with HJT. Also after ComboFix restarted the laptop, Comodo loaded up again and I think may have affected how the log was prepared. Seemed to proceed OK after I told Comodo to allow but thought I'd let you know.

    FYI Spyware Doctor was the free version I got through Google Packs, I uninstalled before proceeding per your directions. Please let me know if I can do anything else, and thank you again for your time and efforts.

    Regards,
    BZ
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Getting there... a couple files I wanted dead are back though... let's try another tool.

    1. Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    2. Now run Ccleaner! (Not the registry section)


    3. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from avenger.

    4. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. BrankoZ

    BrankoZ Private E-2

    Attaching new logs as instructed. Thanks again.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Stubborn...stubborn.....!

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    C:\Users\Brian\AppData\Local\temp\a.wnd.tmp
    C:\Users\Brian\AppData\Local\temp\013dcd84-9f3d-4285-b763-45dadc46a5e7.mht
    C:\Users\Brian\AppData\Local\temp\06f557d3-eab2-439e-b314-832eb925a8fa.mht
    C:\Users\Brian\AppData\Local\temp\0ab4a576-c779-42d8-9204-3aa5f1557e76.mht
    C:\Users\Brian\AppData\Local\temp\40cf5f6a-c820-425f-99d5-1570bf9ec867.mht
    C:\Users\Brian\AppData\Local\temp\41ac4bb9-bc41-4738-b81e-6e64fb3d15a4.mht
    C:\Users\Brian\AppData\Local\temp\5f063f77-d78f-4e0b-9b86-e2a77a8ce4a5.mht
    C:\Users\Brian\AppData\Local\temp\62e26489-0aea-4176-a918-a5a1b0acaf70.mht
    C:\Users\Brian\AppData\Local\temp\6aac6766-c7bb-4468-adfd-e41ba5a43d65.mht
    C:\Users\Brian\AppData\Local\temp\714e8853-baa1-4440-9105-6442e4bbb150.mht
    C:\Users\Brian\AppData\Local\temp\728cf8b5-eea6-4545-9dbb-612428e15740.mht
    C:\Users\Brian\AppData\Local\temp\918ca182-f411-4e08-bc6a-32d568eb9d0b.mht
    C:\Users\Brian\AppData\Local\temp\9cfa13da-3f17-4528-895e-217d6dc4bb8e.mht
    C:\Users\Brian\AppData\Local\temp\b9326cbd-fc15-4ba9-b3c6-a5b3bb7e4f7d.mht
    C:\Users\Brian\AppData\Local\temp\bb5f5484-baf8-44ec-8e1a-cf9876608710.mht
    C:\Users\Brian\AppData\Local\temp\c0eda62f-2a67-4413-b6dc-ae1ade6c620d.mht
    C:\Users\Brian\AppData\Local\temp\d24d7cbd-7bef-4031-9cd4-f4ac29f245f6.mht
    C:\Users\Brian\AppData\Local\temp\e8e3bd42-2902-41d4-9884-46db3da7e816.mht
    C:\Users\Brian\AppData\Local\temp\f3128dc1-ab11-411e-902d-2aa452a681a2.mht
    C:\Users\Brian\AppData\Local\temp\SSUPDATE.EXE
    C:\Users\Brian\AppData\Local\temp\$.ficn$
    
    :Commands
    [emptytemp]
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • Do not reboot the machine.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from OTM.
     
    Last edited: Dec 10, 2009
  9. BrankoZ

    BrankoZ Private E-2

    All processes killed
    ========== FILES ==========
    C:\Users\Brian\AppData\Local\temp\a.wnd.tmp moved successfully.
    C:\Users\Brian\AppData\Local\temp\013dcd84-9f3d-4285-b763-45dadc46a5e7.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\06f557d3-eab2-439e-b314-832eb925a8fa.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\0ab4a576-c779-42d8-9204-3aa5f1557e76.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\40cf5f6a-c820-425f-99d5-1570bf9ec867.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\41ac4bb9-bc41-4738-b81e-6e64fb3d15a4.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\5f063f77-d78f-4e0b-9b86-e2a77a8ce4a5.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\62e26489-0aea-4176-a918-a5a1b0acaf70.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\6aac6766-c7bb-4468-adfd-e41ba5a43d65.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\714e8853-baa1-4440-9105-6442e4bbb150.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\728cf8b5-eea6-4545-9dbb-612428e15740.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\918ca182-f411-4e08-bc6a-32d568eb9d0b.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\9cfa13da-3f17-4528-895e-217d6dc4bb8e.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\b9326cbd-fc15-4ba9-b3c6-a5b3bb7e4f7d.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\bb5f5484-baf8-44ec-8e1a-cf9876608710.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\c0eda62f-2a67-4413-b6dc-ae1ade6c620d.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\d24d7cbd-7bef-4031-9cd4-f4ac29f245f6.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\e8e3bd42-2902-41d4-9884-46db3da7e816.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\f3128dc1-ab11-411e-902d-2aa452a681a2.mht moved successfully.
    C:\Users\Brian\AppData\Local\temp\SSUPDATE.EXE moved successfully.
    C:\Users\Brian\AppData\Local\temp\$.ficn$\index folder moved successfully.
    C:\Users\Brian\AppData\Local\temp\$.ficn$ folder moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Brian
    ->Temp folder emptied: 108392 bytes
    ->Temporary Internet Files folder emptied: 13688095 bytes
    ->Java cache emptied: 77208652 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    I messed up and rebooted the machine...

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33222 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 12877276 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 99.10 mb


    OTM by OldTimer - Version 3.1.2.2 log created on 12102009_200848

    Files moved on Reboot...

    Registry entries deleted on Reboot...
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oay then, whilst we are both online let's do the below and let's not reboot or shut down:

    Let's use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    
    KILLALL::
    
    File::
    C:\Users\Brian\AppData\Local\Temp\$.ficn$
    C:\Users\Brian\AppData\Local\Temp\a.wnd.tmp
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.
     
  11. BrankoZ

    BrankoZ Private E-2

    Good morning - Attaching requested logs. FYI, as I'd noted in my first reply, I disabled the Resident Shield in AVG, and exited Comodo Firewall, but ComboFix still recognized them as open. I didn't know how else to close them, and wasn't comfortable just ending the processes with HJT.

    Thanks again,
    BZ
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sigh...still there, let's try this another way:

    1. Copy all text in the quote box (below)...to Notepad.

    • Save the Notepad file on your desktop...as delfile.bat... save type as "All Files"
    • http://i526.photobucket.com/albums/cc345/MPKwings/batfileicon.gif
    • delfile.bat <<------------- you should see this on your desktop.
    • Double click on delfile.bat to execute it.
    • A black CMD window will flash, then disappear...this is normal.
    • The files and folders, if found...will have been deleted and the "delfile.bat" file will also be deleted.

    2. Download the MBR Rootkit Detector to your desktop.

    • Doubleclick mbr.exe and follow prompts.
    • A black DOS window will quickly appear then disappear.
    • When mbr.exe is finished it will create a log on your desktop.
    • Copy and paste contents of that log file to your next reply.

    3. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from MBR Rootkit Detector
     
    Last edited: Dec 16, 2009
  13. BrankoZ

    BrankoZ Private E-2

    MBR may not have finished. I got the Windows error dialog box that says, "A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available".

    In the MBR.exe window, there were four lines:

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK

    I'm attaching the MGTools log. I'm also attaching the error box and MBR window as a JPG but I wasn't sure that you'd want to open an unknown attachment...
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  15. BrankoZ

    BrankoZ Private E-2

    Here you go. Found a few things so hopefully this helps. I truly appreciate your help.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, now do the following:

    The first two items listed:

    C:\MGtools\Process.exe Win32/PrcView application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\PlaySushi\PSText.dll.vir Win32/Adware.Gamevance application cleaned by deleting - quarantined,

    one is part of MGTools and the other is just stuff it's finding in combofix's back up directory.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    I need to speak to Chaslang about something so please be patient with me :)
     
  17. BrankoZ

    BrankoZ Private E-2

    Here's the MGT file. No hurry.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi again, and thanks for your patience.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      dir:
      C:\Users\Brian\AppData\Local\temp\$.ficn$
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  19. BrankoZ

    BrankoZ Private E-2

    done
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean. :wine


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work through the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds