Spyware / Malware / Virus Removal
Email Hacked Again
9 min read
tritons
Topic Starter
I was unable to access my computers for a few days and my previous thread got closed
(http://forums.whatthetech.com/index.php?showtopic=117716&st=15)
My email got "hacked" into again earlier today and sent out the spam links once again.
I was finally able to run the Eset online scan as advised to do so in the other thread by Patndoris, here are the results:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=b5b1e2eb3102e742a5b9429d80c9f788
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-04-19 04:04:14
# local_time=2011-04-18 09:04:14 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 43733631 43733631 0 0
# compatibility_mode=1032 16777189 100 94 0 45509649 0 0
# compatibility_mode=2561 16777214 0 14 139888984 139888984 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=248393
# found=14
# cleaned=0
# scan_time=12600
C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\15\64929f4f-10490efb multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\33\30feb821-4094f4af multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\35\3d54c723-2c7e096f multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\52\31bba1f4-255dec89 probably a variant of Win32/Agent.DYXWUMY trojan (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\Nil\Desktop\Craagle\CRAAGLE.rar Win32/Adware.Craagle application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Mozilla Firefox 4.0 Beta 10\plugins a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\PDF Annotator\loader.exe probably a variant of Win32/HackTool.Patcher.N application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\patch.exe a variant of Win32/HackTool.Patcher.A application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\msa.exe.vir a variant of Win32/Kryptik.BDG trojan (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\Cursors\swmbli.bak1.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir Win32/Sirefef.A trojan (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\hgjlm.bak2.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\hgjlm.ini.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\hgjlm.ini2.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I
patndoris
Welcome back to the forums! I'm afraid I don't have good news for you.
Your online scans are showing signs of infection by Sality, which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs. This infection replicates, and can infect removable media as well as executable files throughout the computer.
Using a known clean computer,
Please read the following for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall
Considering the above information, please let me know if your choice is to reformat, or if you would like to procede wtih cleaning.
Your online scans are showing signs of infection by Sality, which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs. This infection replicates, and can infect removable media as well as executable files throughout the computer.
Using a known clean computer,
- change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
- DO NOT change passwords or do any transactions while using the infected computer because the new passwords may be compromised.
Please read the following for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall
Considering the above information, please let me know if your choice is to reformat, or if you would like to procede wtih cleaning.
tritons
Should I start backing up my files onto an external hard drive?
patndoris
Sometimes the best solution is to format and reinstall Windows. You will have the reassurance that the system is clean after you do. You certainly can backup your files to an external hard drive, but please be sure to read the tips below and make sure those files are clean before you put them back on the system after reformatting.
You can find instructions on how to reformat here. Please print out the instructions so you can follow them as needed during your reformat.
After reinstalling the operating system you will want to visit Microsoft's Windows Update Sitet http://www.windowsupdate.com. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Please remember, if data was backed up prior to the format, before placing that data back into a clean hard drive, have it scanned with AntiVirus programs. Use more than one program, since AntiVirus scanners use databases that are not identical, and one may find malware that another does not. If the data is reported as clean after running a few virus scans (IMO would use three or more), it should be safe to place it in the clean hard drive.
===============
Some additional sources you may want to consider:
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.
Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender:http://www.bitdefender.com/scan8/
You can find instructions on how to reformat here. Please print out the instructions so you can follow them as needed during your reformat.
After reinstalling the operating system you will want to visit Microsoft's Windows Update Sitet http://www.windowsupdate.com. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Please remember, if data was backed up prior to the format, before placing that data back into a clean hard drive, have it scanned with AntiVirus programs. Use more than one program, since AntiVirus scanners use databases that are not identical, and one may find malware that another does not. If the data is reported as clean after running a few virus scans (IMO would use three or more), it should be safe to place it in the clean hard drive.
===============
Some additional sources you may want to consider:
- AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
If you don't have one here are some of the better AV products.
Avira AntiVir
Avast!
AVG Anti-Virus (Free version available)
Microsoft Security Essentials
Or visit this link for a listing of some online online & stand-alone antivirus programs:
Virus, Spyware, and Malware Protection and Removal Resources
- Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly. If you don't have one see links below for some free options:
Sunbelt Kerio OutPost
PC Tools Firewall Plus
Online Armor Free
For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.
Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender:http://www.bitdefender.com/scan8/
tritons
Looks like I'll be reformatting. I am in the process of backing up my files now.
I found a set of recovery discs that it seems like I had created a while back, do you think these discs will contain Win XP that is currently installed on my machine?
patndoris
If you have Windows Recovery discs you should be well on your way. After you reformat, It is important that you visit http://www.windowsupdate.com. If there are new updates to install (and there will probably be quite a few), install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
tritons
OK, will be back to report on how it goes.
tritons
Im using my recovery discs and upon restart these are the options I got:
1. recovery of factory default software - recover to out-of-box state
2. erase the hard disk - delete all the data and partitions from your hard disk
3. recover of system backup - recover the system from the TOSHIBA Backup Utility
Which option do should I choose??
patndoris
I'd like to point you to our Windows Forum. They are more knowledgeable about reformatting and the associated steps to go along with that. You can post there and let them know that you are reformatting due to malware infection and they should be able to answer all your Windows related questions.
Let me know if they are not able to help you.
Let me know if they are not able to help you.
tritons
OK so I reformatted and now am ready to transfer over my old data.
How do I go about scanning that old data thats on my external hd before I transfer it over to the clean machine?
Do I transfer over the folders then scan? Or is there a way to scan them from my external before they are dragged to my machine?
patndoris
You will have to plug your external drive into your newly formatted computer. You should be able to scan all drives using Malwarebyes (Full Scan) as well as your Antivirus program on a full scan. You can also use something like SuperAntiSpyware to scan all your drives on a full scan as well. Until the files have been scanned and confirmed OK, I would NOT transfer them to the new machine.
tritons
Scanned my external hd files that I will be transferring over to my clean machine and here were the results:
1. AVG - no threats found
2. Emsisoft Anti-Malware (a2)
Emsisoft Anti-Malware - Version 5.1
Last update: 4/20/2011 4:20:50 PM
Scan settings:
Scan type: Custom Scan
Objects: Memory, Traces, Cookies, E:\
Scan archives: On
Heuristics: On
ADS Scan: On
Scan start: 4/20/2011 6:01:43 PM
C:\Documents and Settings\Nil\Cookies\nil@advertising[2].txt detected: Trace.TrackingCookie.advertising!A2
C:\Documents and Settings\Nil\Cookies\nil@doubleclick[1].txt detected: Trace.TrackingCookie.doubleclick!A2
C:\Documents and Settings\Nil\Cookies\nil@mediaplex[2].txt detected: Trace.TrackingCookie.mediaplex!A2
C:\Documents and Settings\Nil\Cookies\nil@serving-sys[2].txt detected: Trace.TrackingCookie.serving-sys!A2
E:\My Computer 4-19-2011\C Drive\My Documents\Downloads\Foxit.Phantom.PDF.Suite.v2.1.0.0731.ZWT.[setup.&.portable]\crack_ZWT_zfp2000\keygen.exe detected: Riskware.Patch.FoxitReader!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\keygen.exe detected: possible-Threat.Keygen!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\zwt.nfo detected: Win32.SuspectCrc!IK
Scanned
Files: 465219
Traces: 732355
Cookies: 31
Processes: 79
Found
Files: 3
Traces: 0
Cookies: 4
Processes: 0
Registry keys: 0
Scan end: 4/20/2011 8:23:27 PM
Scan time: 2:21:44
3. Malwarebytes Anti-Malware
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6408
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/20/2011 9:58:22 PM
mbam-log-2011-04-20 (21-58-18).txt
Scan type: Full scan (E:\|)
Objects scanned: 280231
Time elapsed: 1 hour(s), 13 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
e:\my computer 4-19-2011\C Drive\my documents\software serials & keys\zone alarm\keygen.exe (RiskWare.Tool.CK) -> No action taken.
Is it safe to transfer the files over? Or do these threats need to be taken care of beforehand?
1. AVG - no threats found
2. Emsisoft Anti-Malware (a2)
Emsisoft Anti-Malware - Version 5.1
Last update: 4/20/2011 4:20:50 PM
Scan settings:
Scan type: Custom Scan
Objects: Memory, Traces, Cookies, E:\
Scan archives: On
Heuristics: On
ADS Scan: On
Scan start: 4/20/2011 6:01:43 PM
C:\Documents and Settings\Nil\Cookies\nil@advertising[2].txt detected: Trace.TrackingCookie.advertising!A2
C:\Documents and Settings\Nil\Cookies\nil@doubleclick[1].txt detected: Trace.TrackingCookie.doubleclick!A2
C:\Documents and Settings\Nil\Cookies\nil@mediaplex[2].txt detected: Trace.TrackingCookie.mediaplex!A2
C:\Documents and Settings\Nil\Cookies\nil@serving-sys[2].txt detected: Trace.TrackingCookie.serving-sys!A2
E:\My Computer 4-19-2011\C Drive\My Documents\Downloads\Foxit.Phantom.PDF.Suite.v2.1.0.0731.ZWT.[setup.&.portable]\crack_ZWT_zfp2000\keygen.exe detected: Riskware.Patch.FoxitReader!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\keygen.exe detected: possible-Threat.Keygen!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\zwt.nfo detected: Win32.SuspectCrc!IK
Scanned
Files: 465219
Traces: 732355
Cookies: 31
Processes: 79
Found
Files: 3
Traces: 0
Cookies: 4
Processes: 0
Registry keys: 0
Scan end: 4/20/2011 8:23:27 PM
Scan time: 2:21:44
3. Malwarebytes Anti-Malware
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6408
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/20/2011 9:58:22 PM
mbam-log-2011-04-20 (21-58-18).txt
Scan type: Full scan (E:\|)
Objects scanned: 280231
Time elapsed: 1 hour(s), 13 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
e:\my computer 4-19-2011\C Drive\my documents\software serials & keys\zone alarm\keygen.exe (RiskWare.Tool.CK) -> No action taken.
Is it safe to transfer the files over? Or do these threats need to be taken care of beforehand?
patndoris
E:\My Computer 4-19-2011\C Drive\My Documents\Downloads\Foxit.Phantom.PDF.Suite.v2.1.0.0731.ZWT.[setup.&.portable]\crack_ZWT_zfp2000\keygen.exe detected: Riskware.Patch.FoxitReader!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\keygen.exe detected: possible-Threat.Keygen!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\zwt.nfo detected: Win32.SuspectCrc!IK
It would appear the first entry contains a crack. We do not support the use of illegal Pirated/Warez/Cracked software. Helping a person who insists on using such software, could be construed in the eyes of the law to be aiding and abetting a crime.
I will tell you, if it were me, I would not transfer any of these files to a new machine and would immediately delete them.
tritons
I don't need nor use those files anyway, besides that is it safe to transfer over everything else?
patndoris
Based on the logs you provided, while we can't be 100% sure, I would be comfortable transferring the files (minus the 3 above) to the computer at this point.
Let me know if you have any further questions 
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI