Stymied at Step 4 of Malware Removal Guide

Discussion in 'Malware Help (A Specialist Will Reply)' started by inneedofgeek, Sep 25, 2015.

  1. inneedofgeek

    inneedofgeek Private E-2

    Hi,
    I am doing my best to follow all the steps in the Malware Removal Guide, despite feeling exposed & vulnerable.
    I am at step 4: disable disk emulation software.
    I have downloaded Defogger from the bleeping computer website, but when I go to open it, I get this security warning: this file does not have a valid digital signature that verifies its publisher.
    So, the freak out level has gone up somewhat.
    Please advise.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's fine, just continue on. :)
     
  3. inneedofgeek

    inneedofgeek Private E-2

    "Okay" she said, nervously.:eek
    I see this is a trust excercise, so trust I will.
    Thank you and will be back with logs soon.
     
  4. inneedofgeek

    inneedofgeek Private E-2

    Hi, again,
    I have finished with my scans and am sending my logs.
    I have Trusteer Rapport installed on my computer and a couple of weeks ago I noticed it reported that it had activated anti-keylogging when I signed into my yahoo email. I didn't think anything of it because the report says the following:

    "The following password submissions were protected by the character replacement feature. Trusteer Endpoint Protection has prevented access to the original keystrokes from most common keyloggers. This does not necessarily mean you have keyloggers on your PC. However, applications on your PC that tried to log keystrokes while you were entering information to the websites below have failed."

    And then it lists the date, time and web address for each instance where anti-keylogging was activated.

    I assumed it was protecting me, but then a credit card I use online had fraudulent purchases, so I checked the report again and saw that every time I attempt to log in to my email account anti-keylogging gets triggered. And, the last time I used that credit card online, I had to go into my yahoo email to retrieve the log-in info for the website I made the purchase on. I used a link from within my email to go to the website and make the purchase. I made the purchase and a fraudulent purchase was made the following day.

    And, now, here I am. Please help
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing much to do.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.

    Re run Hitman Pro and have it delete all it finds.

    Give Ccleaner a run, not the reg scanner just the cleaner itself, to be rid of a chunk of temp files.

    You need to use a different computer and change all your online passwords. Then you need to contact your bank and all credit card accounts and just alert them to the fact that your personal info may have been compromised if you have not already done so.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds