This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Email Hacked Again

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was unable to access my computers for a few days and my previous thread got closed (http://forums.whatthetech.com/index.php?showtopic=117716&st=15) My email got "hacked" into again earlier today and sent out the spam links once again. I was finally able to run the Eset online scan as advised to do so in the other thread by Patndoris, here are the results: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=b5b1e2eb3102e742a5b9429d80c9f788 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-04-19 04:04:14 # local_time=2011-04-18 09:04:14 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 43733631 43733631 0 0 # compatibility_mode=1032 16777189 100 94 0 45509649 0 0 # compatibility_mode=2561 16777214 0 14 139888984 139888984 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=248393 # found=14 # cleaned=0 # scan_time=12600 C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\15\64929f4f-10490efb multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\33\30feb821-4094f4af multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\35\3d54c723-2c7e096f multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Nil\Application Data\Sun\Java\Deployment\cache\6.0\52\31bba1f4-255dec89 probably a variant of Win32/Agent.DYXWUMY trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Nil\Desktop\Craagle\CRAAGLE.rar Win32/Adware.Craagle application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Mozilla Firefox 4.0 Beta 10\plugins a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\PDF Annotator\loader.exe probably a variant of Win32/HackTool.Patcher.N application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\patch.exe a variant of Win32/HackTool.Patcher.A application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\msa.exe.vir a variant of Win32/Kryptik.BDG trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\Cursors\swmbli.bak1.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir Win32/Sirefef.A trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\hgjlm.bak2.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\hgjlm.ini.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\hgjlm.ini2.vir Win32/Adware.Virtumonde.NEO application (unable to clean) 00000000000000000000000000000000 I
Welcome back to the forums! I'm afraid I don't have good news for you.

Your online scans are showing signs of infection by Sality, which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs. This infection replicates, and can infect removable media as well as executable files throughout the computer.

Using a known clean computer,
  • change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the new passwords may be compromised.
Though Sality has been identified and we can try to remove it, because of it's back door functionality and ability to embed itself in so many executable files, Your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of infection, the best course of action would be a reformat and reinstall of the OS. If it were on my PC, I would not hesitate for even a moment to do so. Making this decision is based on what the computer is used for, and what information can be accessed from it.

Please read the following for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

Considering the above information, please let me know if your choice is to reformat, or if you would like to procede wtih cleaning.
Sometimes the best solution is to format and reinstall Windows. You will have the reassurance that the system is clean after you do. You certainly can backup your files to an external hard drive, but please be sure to read the tips below and make sure those files are clean before you put them back on the system after reformatting.

You can find instructions on how to reformat here. Please print out the instructions so you can follow them as needed during your reformat.

After reinstalling the operating system you will want to visit Microsoft's Windows Update Sitet http://www.windowsupdate.com. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Please remember, if data was backed up prior to the format, before placing that data back into a clean hard drive, have it scanned with AntiVirus programs. Use more than one program, since AntiVirus scanners use databases that are not identical, and one may find malware that another does not. If the data is reported as clean after running a few virus scans (IMO would use three or more), it should be safe to place it in the clean hard drive.

===============

Some additional sources you may want to consider:

  • AntiVirus Software
    It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
    If you don't have one here are some of the better AV products.

    Avira AntiVir
    Avast!
    AVG Anti-Virus (Free version available)
    Microsoft Security Essentials

    Or visit this link for a listing of some online online & stand-alone antivirus programs:
    Virus, Spyware, and Malware Protection and Removal Resources
  • Firewall
    I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly. If you don't have one see links below for some free options:

    Sunbelt Kerio OutPost
    PC Tools Firewall Plus
    Online Armor Free

    For a tutorial on Firewalls and a listing of some other available ones see the link below:
    Understanding and Using Firewalls


Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender:http://www.bitdefender.com/scan8/
Looks like I'll be reformatting. I am in the process of backing up my files now. I found a set of recovery discs that it seems like I had created a while back, do you think these discs will contain Win XP that is currently installed on my machine?
If you have Windows Recovery discs you should be well on your way. After you reformat, It is important that you visit http://www.windowsupdate.com. If there are new updates to install (and there will probably be quite a few), install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Im using my recovery discs and upon restart these are the options I got: 1. recovery of factory default software - recover to out-of-box state 2. erase the hard disk - delete all the data and partitions from your hard disk 3. recover of system backup - recover the system from the TOSHIBA Backup Utility Which option do should I choose??
I'd like to point you to our Windows Forum. They are more knowledgeable about reformatting and the associated steps to go along with that. You can post there and let them know that you are reformatting due to malware infection and they should be able to answer all your Windows related questions.

Let me know if they are not able to help you.
OK so I reformatted and now am ready to transfer over my old data. How do I go about scanning that old data thats on my external hd before I transfer it over to the clean machine? Do I transfer over the folders then scan? Or is there a way to scan them from my external before they are dragged to my machine?
You will have to plug your external drive into your newly formatted computer. You should be able to scan all drives using Malwarebyes (Full Scan) as well as your Antivirus program on a full scan. You can also use something like SuperAntiSpyware to scan all your drives on a full scan as well. Until the files have been scanned and confirmed OK, I would NOT transfer them to the new machine.
Scanned my external hd files that I will be transferring over to my clean machine and here were the results:

1. AVG - no threats found

2. Emsisoft Anti-Malware (a2)
Emsisoft Anti-Malware - Version 5.1
Last update: 4/20/2011 4:20:50 PM

Scan settings:

Scan type: Custom Scan
Objects: Memory, Traces, Cookies, E:\
Scan archives: On
Heuristics: On
ADS Scan: On

Scan start: 4/20/2011 6:01:43 PM

C:\Documents and Settings\Nil\Cookies\nil@advertising[2].txt detected: Trace.TrackingCookie.advertising!A2
C:\Documents and Settings\Nil\Cookies\nil@doubleclick[1].txt detected: Trace.TrackingCookie.doubleclick!A2
C:\Documents and Settings\Nil\Cookies\nil@mediaplex[2].txt detected: Trace.TrackingCookie.mediaplex!A2
C:\Documents and Settings\Nil\Cookies\nil@serving-sys[2].txt detected: Trace.TrackingCookie.serving-sys!A2
E:\My Computer 4-19-2011\C Drive\My Documents\Downloads\Foxit.Phantom.PDF.Suite.v2.1.0.0731.ZWT.[setup.&.portable]\crack_ZWT_zfp2000\keygen.exe detected: Riskware.Patch.FoxitReader!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\keygen.exe detected: possible-Threat.Keygen!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\zwt.nfo detected: Win32.SuspectCrc!IK

Scanned

Files: 465219
Traces: 732355
Cookies: 31
Processes: 79

Found

Files: 3
Traces: 0
Cookies: 4
Processes: 0
Registry keys: 0

Scan end: 4/20/2011 8:23:27 PM
Scan time: 2:21:44

3. Malwarebytes Anti-Malware

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6408

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/20/2011 9:58:22 PM
mbam-log-2011-04-20 (21-58-18).txt

Scan type: Full scan (E:\|)
Objects scanned: 280231
Time elapsed: 1 hour(s), 13 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
e:\my computer 4-19-2011\C Drive\my documents\software serials & keys\zone alarm\keygen.exe (RiskWare.Tool.CK) -> No action taken.


Is it safe to transfer the files over? Or do these threats need to be taken care of beforehand?

E:\My Computer 4-19-2011\C Drive\My Documents\Downloads\Foxit.Phantom.PDF.Suite.v2.1.0.0731.ZWT.[setup.&.portable]\crack_ZWT_zfp2000\keygen.exe detected: Riskware.Patch.FoxitReader!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\keygen.exe detected: possible-Threat.Keygen!IK
E:\My Computer 4-19-2011\C Drive\My Documents\Software Serials & Keys\Zone Alarm\zwt.nfo detected: Win32.SuspectCrc!IK


It would appear the first entry contains a crack. We do not support the use of illegal Pirated/Warez/Cracked software. Helping a person who insists on using such software, could be construed in the eyes of the law to be aiding and abetting a crime.

I will tell you, if it were me, I would not transfer any of these files to a new machine and would immediately delete them.
Based on the logs you provided, while we can't be 100% sure, I would be comfortable transferring the files (minus the 3 above) to the computer at this point. Let me know if you have any further questions :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI