Stolen Password

Discussion in 'Malware Help (A Specialist Will Reply)' started by vtx, May 18, 2008.

  1. vtx

    vtx Private E-2

    Hello. Somebody stole my account number and password to my brokerage account and then placed some unauthorized trades :eek. I could have lost a substantial amount of money. In an effort to learn more about internet secuirty, I stated perusing the internet. I found out that Spy Doctor 5.5. was highly recommend by some and so I ran the trial version. When I said fix the problems, it said pay $30. I decided to see what else was out there and ended up running some free stuff: Spybot, Ad Aware and Windows Defender. After running these and fixing the problems they found, I reran Spy Doctor. Much to my disappointment, it still found high risk trojans. I have had McAfee running for almost a year and the stolen password probably took place just recently, as the fraudulent account activity occured last week. Where should I go from here??? Any help would be greatly appreciated. Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Be very careful with program names. I believe you mean Spyware Doctor and not Spy Doctor. While Spyware Doctor is a valid and pretty good program, it has been known to indicate false positives. Exactly what is it finding and where.

    If you wish to properly check your PC for malware, pease follow the instructions in the below link and attach the requested logs when you finish these instructions. However read all of the below message before taking any action.

    READ & RUN ME FIRST. Malware Removal Guide


    HOWEVER, I DO NEED TO GIVE YOU THE FOLLOWING WARNING SINCE YOU HAVE ALREADY HAD PERSONAL INFO STOLEN
    And rather than me rewriting similar info, you should also read the below:

    http://www.dslreports.com/faq/10063
    http://www.dslreports.com/faq/10451
     
  3. vtx

    vtx Private E-2

    Thank you for your reply.

    I attached the Spwyare Doctor results in a Word file. How serious are these infections?

    After reading the links towards the bottom of your post, particularly the first one, I don't know that I would have peace of mind unless I had a professional come to my home and assist me in reformatting and reinstalling my computer. I am not tech savvy and very regularly access personal bank, brokerage and retirement accounts on my computer.

    My plan this morning is to again call each financial institution and see if there has been any fraudulant activity. For those that have not been hacked, is it safe to just change my passwords via the public library? If not hacked would you still recommend that I have the insitutions change my account numbers?

    If a reformat and reinstall is best, whom would you recommend I call, and what type of service and cost should I expect?

    Thank you again for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do have some items that need to be cleaned up. However don't worry about items that are cookies since they are not problems.

    Yes no matter what you decide to do with your PC (clean it or format and reinstall) it would be in your best interest to change ALL passwords (for everything that uses a password - even your PC and logins to forums like here). Changing accounts number would be a good idea to. You have no way of knowing what info may have been stolen at this point. Just because other accounts of other logins have not been accessed yet, it does not mean that the hacker does not have all of that info.

    Most people believe that once your security has been compromised like this, that the only safe recourse is to start over. While cleaning the PC may work just as well, there are no guarantees. Thus where financial security comes into play, it may be safest to give yourself more piece of mind and reinstall.

    I really cannot say where you should go to have this done. Where you live and what's around can impact that decision. People in the Software Forum may be able to give you suggestions. And it could be quite expensive. Depends on how much additional software beyond Windows that you ask them to reinstall.

    Did you PC come with a factory restore type option (either a disk or a built-in partition)?
     
  5. vtx

    vtx Private E-2

    Hello again Chaslang,

    I decided to clean my computer and not reformat/reinstall. I am on the step that say to be sure that MSConfig is not being used to control Startups. How do I determine this?

    You asked: Did your PC come with a factory restore type option (either a disk or a built-in partition)?
    I do not know how to determine this either.

    FYI - when I checked the 'bad' programs list I found three and removed them:
    Viewpoint Manager (Remove Only)
    Viewpoint Toolbar
    Weather Services

    Thanks,
    Jeff
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions are in the link given in step 1 of the READ ME. You need to click the blue underlined text because they are all links.

    You would have to check your documentation or speak to who you purchased the PC from. However it does not matter if your plan is to clean the PC.
     
  7. vtx

    vtx Private E-2

    I tried to run the CCleaner a few times and the process would never complete. I clicked on the link for the download and then hit "run". I let it run for up to 45 minutes (and I have a cable modem ) and it just kept running. The header said:
    "Verifying CCsetup2007_slim.exe from files6.MajorGeeks.com"
    Even though it would say that the estimated time left was 1 sec left it would run for dozen(s) of minutes thereafter.
    Does it make a difference if I save the program to my computer, then double click on it from there to run it?

    Thank you.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!!!! Do not try to install the programs directly from the web. Download and SAVE the files to your PC first. Then run them directly from your PC once they have downloaded.
     
  9. vtx

    vtx Private E-2

    O.K. I got to the part where I need to download some tools. I tried to download the first one, SUPERantispware, and it looked like it was going to be a very quick download. When I clicked on it to begin, the download quickly counted down the seconds remaining until it got to the last second. Then the process seemed to just stop; it stopped with one second left; and nothing else would happen. It wouldn't finish. What would cause this? What do I do?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you download anything at all? Did you get CCleaner to download? Did you also get it installed? Did it also run? Try the other applications that we ask you to download.


    It is a multi-step process for each application and you must not confuse the steps
    1. First you download and save the file to your PC
    2. Then you install the program
    3. Then you Run the program and clean/fix/quarantine....etc whatever it finds
    4. Then you come here and attach the specific logs from the programs that we request logs from
     
  11. vtx

    vtx Private E-2

    Not sure what created the problem I described on my last post, but I have since tried again and everything worked. I understand now that I need to download, install and then run. Thanks for clarifying that. I was able to do that with CCleaner and then also with SUPERSpyware, which is the last step I have taken. I have attached the SAS log for review. Waiting for your reply before I go on to the next steps. Thanks so much for your help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We cannot do anything until all steps are completed and all logs are attached.

    One of the trojans you have is this:

    http://www.sophos.com/security/analyses/viruses-and-spyware/trojiyuss.html

    Click the More Information tab on this page to see all the info.

    Also you can read more at McAfee: http://vil.nai.com/vil/content/v_139049.htm
     
  13. vtx

    vtx Private E-2

    For ComboFix, the instrucions say to "shutdown/stop all of your protection software to the best of your ability". I have McAfee and wasn't sure what I needed to do, so I didn't do anything and just tried to run ComboFix to see if it would work. I immediately received an alarming message from McAfee that a trojan was just installed, or something to that nature. I responded by chosing the option that says to remove the Trojan, it said it could not be removed. I then began to look at McAfee in more detail to try to determine what "shutdown/stop" might mean. One screen listed three different areas of protection like this:
    1) Computer & Files
    Protected
    2) Internet & Network
    Protected
    3) E-mail & IM
    Protected
    There are various protections under each that I can disable through reconfiguring them. To my knowledge these protections are my main safegaurds against major problems. Am I to disable all services under each of the three areas while my computer is still connected to the internet? Since this seems dangerous, I wanted to double check with you that this is what I should actually be doing before running ComboFix.
    Also, Spybot gave me an alarming message as well. Unfortunatley, I accidentally closed that window before I could get any details.
    The alarming messages from McAfee and Spybot S&D both came immediately after I tried to run Combo-Fix, so am I safe in assuming that whatever these programs found is actually harmless and whatever "Trojan" that is now on my computer, according to McAfee, does not need any attention?
    Thanks for your help.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is the reason we said to shut down McAfee. You are not stopping a trojan from running!!!! You are stopping ComboFix from running. You need to allow it to run. You must not remove it. Try again and do not block it or remove it.

    Do not change any of your settings in McAfee. Just see if any processes can be terminated. But either way DO NOT block what we are trying to run from running.

    If you have Spybot's Teatimer enabled, you MUST disable it as was stated in the READ & RUN ME.
     
  15. vtx

    vtx Private E-2

    I attached the SuperAntiSpyware log in a previous post, so with this post's attachments, I believe I have attached all required logs.

    Looking forward to hearing from you about the number and nature of problems on my computer. Was a backdoor used?

    You found a trojan in my SuperAntiSpyware log and provided a couple links so I could get additional information (thanks). The trojan was password stealing, but was categorized as low risk. How could a password stealing trojan be low risk? Hoping this can be successfully removed, and that if you don't find any others you would consider my situation to be low threat (not too vulnerable to having additional passwords stolen).

    Thanks for all your help!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This we cannot answer. The only way you know if someone actually broke in and got info is when you find out that they are using it. You already implied in your first message that at least one password appeared to have have been stolen so I think you already have you answer. If you are really concerned about this, why did you wait 19 days to reply?


    You can read about how they rate their risk assessments here:

    http://www.mcafee.com/us/threat_center/outbreaks/virus_library/risk_assessment.html#Low

    Part of the assessment is the likelihood of getting the infection to begin with.

    It was already removed when you ran the scans. As far as whether anything remains or if any other info was stolen, we cannot guarantee anything which is why I posted what I did in message # 2.


    If you still wish to continue finish the cleaning process, I have some more minor items for you below.

    Uninstall this old Sun Java version: J2SE Runtime Environment 5.0 Update 6

    You appear to have some left overs from Symantec/Norton. You need to run the below and then reboot, and then run it one more time.

    Norton Removal Tool (SymNRT)


    Are the below items you setup/installed yourself?
    O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
    O24 - Desktop Component 0: (no name) - http://www.usna.usda.gov/graphics/usna/Hardzone/zones77.jpg


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O8 - Extra context menu item: &Search - ?p=ZS

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. vtx

    vtx Private E-2

    Chaslang....I've been very busy!

    I removed J2SE Runtime Environment 5.0 Update 6.

    I ran, rebooted and ran again Norton Removal Tool (SymNRT).

    I do not recall installing / setting up these items...

    O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
    O24 - Desktop Component 0: (no name) - http://www.usna.usda.gov/graphics/us...ne/zones77.jpg

    I probably don't need them and would like to get rid of them.


    I double-clicked C:\MGtools\analyse.exe and expected to see scan options so I could do a system scan only, but it never presented scan options. If I remember right, it didn't the first time I ran this tool. Also, when it finished running, it just let me know that it was finished and that it created a zip file. I was expecting a long list of lines to select from which would include those you referenced below:
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O8 - Extra context menu item: &Search - ?p=ZS

    What did I do wrong?

    I stopped following instructions here as I figured that additonal steps are probably supposed to be done only as each current step is successfully completed.

    I did get the following message via a window popup while MGtools was running...

    C:\WINDOWS\system32/cmd.exe
    C:\PROGRA~\Symantec\S32EVNT1.DLL. An installable Virtual Device Driver failed Dll initialization. Chosse 'Close' to terminate the application.

    It gave me Close and Ignore as options. I clicked Close. The message popped up almost immediately thereafter. I clicked Ignore the second time.

    Question unrelated to this particular post: I have read that you can get virus', malware, etc. on your computer by opening emails. Does this mean opening attachments to emails or just by merely opening the email itself? It the later is true: When you have a split pane email screen and you click on an email once in the pane that lists emails so that it is viewable in the other pane, but you don't double click on the email, which would enlarge it in the viewing pane, does that constitue opening the email?

    Finally, was I supposed to send a log from SpyBot - Search & Destroy?

    Thank you.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just add them to the HijackThis fix but the Service will most like not get fixed. We will need addtional steps top remove it.


    You are not double clicking on C:\MGtools\analyse.exe You are apparently thinking that I said to run C:\MGtools.exe which is not the same thing.


    So this is the proof that you are not doing what I asked. I requested that you run C:\MGtools\analyse.exe. Please run the correct program. analyse.exe is a file inside of the C:\MGtools folder. You can delete the C:\MGtools.exe file as you do not need it anymore since everything is already installed.

    Also note that the error you mentioned above was explained on the Using MGtools download page and you will need to apply the fix.


    From both but problems due to opening attachments are much much more likely.

    Yes!

    No!
     
  19. vtx

    vtx Private E-2

    I added these to the HijackThis fix

    O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
    O24 - Desktop Component 0: (no name) - http://www.usna.usda.gov/graphics/us...ne/zones77.jpg

    Hopefully the Service was fixed.

    The solution to the MGTools error I posted previously said that sometimes if you just select "ignore" that things will run o.k. This seemed to have been the case.

    I followed all the steps under combo fix to the point of putting the notepad file on Combo-Fix.exe and was prompted to run Combo-Fix, so I did. You said to "follow the prompts", but I did not receive any prompts that asked me to do anything after running. Did I do something wrong, again.:eek: Towards the end of the combofix run, or just after finishing, I received a Windows message saying that it could not open the file: pv.cfexe and that to open it, it needed to know what program created it. At about the same time I also received a messagee from McAfee saying it was trying to block something. I was going to put Allow, but first wanted to write down the exact message thinking that it may be useful in determing why I received the message above. After I went to get some paper to write it down, the message was gone! Do I need to do something differently and redo this whole step?
    I tried to close the window that said it cannot open the file: pv.cfexeit and it just kept popping up. I ended up outmuscling it, clicking on it a good twenty times over about 20 minutes. It finally gave up...:strong

    I attached the combofix log thinking it may be helpful for you to decide if I need to redo this step.

    Sorry to be pushing your patience Chaslang, remember it is not intentional!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the new MGlogs.zip file.

    And no, just clicking ignore witll no allow things to always work. It just allows the scans to continue instead of being aborted.


    The problems you had with ComboFix are due to McAfee. This was originally mentioned in the Using ComboFix instructions in the READ & RUN ME. You must try to stop McAfee from running and you must not permit it to block ComboFix's processes from running. ComboFix may have run okay. I will not know until I see the new MGlogs.zip file requested.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds