Suspicious Behavior Online and Off

Discussion in 'Malware Help (A Specialist Will Reply)' started by AngelsWilliam, Oct 24, 2012.

  1. AngelsWilliam

    AngelsWilliam Private First Class

    My first sign that I was in trouble was when I logged in to LastPass (password keeper extension for browsers), rather than take me to my password vault as usual, it took me to a blank page. But, like a dummy, I merely shrugged and thought, "Hm, that's strange," and went about my business.

    The next sign was I got 2 e-mails in as many weeks from Twitter telling me that my angelswilliam account's password had been reset because a suspicious application had accessed it. Aware that the e-mail could be a phishing one, I opened my browser (I use Google Chrome) and physically typed twitter.com and went to my angelswilliam account. It said I could not access my account until I reset my password. Same the second time around. And, obviously, I changed my password between the two times this happened. I changed the password again, as well as the associated e-mail.

    I also have a Livejournal account with the ID angelswilliam. All the personal messages were deleted the next time I logged in after the Twitter issue. I changed the password for this account; and, as said above, the associated e-mail.

    However, the suspicious behavior remains. My browser and system have also been running very slowly.

    I'm attaching as many logs as I can to this message, and will reply with the rest. (I asked that the previous ticket be closed because that issue no longer exists.)
     

    Attached Files:

  2. AngelsWilliam

    AngelsWilliam Private First Class

    Here are SAS and MBAM.

    Thanks for your help!
     

    Attached Files:

  3. AngelsWilliam

    AngelsWilliam Private First Class

    I also should probably mention that the last "there's a Java update available" gave me 7.9, but when I went to do your "dump the Java cache," there was no Java icon. So, I did your get the newest Java version and downloaded it, and that solved the problem. 7.9 was 128MB, the version you guys have is only in the double digits.

    That's probably a significant issue, too.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not appear to be having malware problems. Your logs are all clean. The only questionable item I saw was the below but this could be related to some software you run.

    C:\Documents and Settings\Carol\Application Data\mainhst.zgh
     
  5. AngelsWilliam

    AngelsWilliam Private First Class

    Soon after I posted this, there was a huge MS update, part of which included a genuine MS Office check (mine is) and 2 updates that would only be updated if the genuine check proved positive. I had been having issues the last two times I used Word with it closing down on me, which I know is a characteristic of big-brother MS thinking you're running a copy. (I've heard horror stories of them slowly shutting down people's computers for good if they "detect" they're running a copy of Windows, right or wrong.)

    Anyway, at the end of the update, it told me the two Word updates could not be installed, which, I assumed, met I failed the "genuine" test. This pissed me off, so I went to the update site. It took a LOOOOOOONG time, but it said the only update I needed was the genuine MS Office update; so, I went ahead and downloaded it. Once I'd downloaded it, I checked my download history, and it showed that the two MS Office security updates had downloaded successfully! WTH?

    Anyway, I'm wondering if maybe MS "detecting" that I had a "copy"--NOT (I spent over $200 for the pro version because I was a med transcriptionist at the time, thank you very much)--was the reason for all my troubles. I'm pretty sure the troubles started after the other mega-security update this month.

    Could that be what caused all this? I have the name, company name, and phone number of the guy who sold it to me just in case. He always buys his stuff online, but it was wrapped with the serial number on the outside and everything!:confused

    That questionable item: Could it be related to Diablo II Expansion or Spotify? I think those are the only two new pieces of software I've installed since I last submitted logs. I missed playing Diablo multiplayer with my ex and his friend SO MUCH, and Wal Mart had the Battle Chest for under $20, so...I just hadta. *grabby hands*
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Doubt it. I have a test PC with a legal copy of MS Office running on it and I have had the notice about need to install that same update for a very long time. And I just ignore it on this test PC. I don't install any updates on it because I use it for testing malware. ;) And I don't have any problems like you mentioned. I even get warnings from Excel when I open it that it needs to be certified. I also ignore them without a problem.

    I don't recommend that others ignore updates. As I stated, this is just a test PC that I can reimage at anytime to start over again.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
     
  7. AngelsWilliam

    AngelsWilliam Private First Class

    I started having looooooots of trouble with Google Chrome, and TDS Killer and MBR Check gave the same results they did last time. Someone keeps hacking into all my angelswilliam accounts--ONLY my angelswilliam accounts--which are only used for fandom. The first two times it was Twitter and Livejournal; the third time it was Facebook. (Facebook is getting much better about security; they shut my account down immediately because it was getting accessed from an unusual place by an unknown device and e-mailed me about it.)

    Anyway, I know I'm going to get torn a new one for this, but I restored my computer back to last Friday and ran Combofix and MGTools--ONLY those two programs. As I watched MGTools, the results were different from any I'd ever seen before and kinda scared me. I'm attaching both logs for your review.

    Thanks,
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are still clean other than one item that is questionable but not always malware. Your MBR is showing as unknown. It is possible that this is just due to how Dell setup and partitoned the drive.

    Do you have your Windows XP boot CD? We can use it to re-write the MBR, but do note that you should backup your data before doing this. While in most cases it works without a problem, there is always a risk. Also there is a risk that fixing the MBR to be a standard Windows MBR will make a Dell Recovery Partition not useful if you ever need it in the future. In fact running fixmbr from the Windows boot cd will even give you are warning about this. However this is the only thing in question and MBR infections have quite often been related to password stealers.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds