Redfefnir
2013-05-22, 01:01
Well, I get pulled away for a few days and the thread gets archived! Understandable, but hopefully we can continue, and if not, well. That's that then. I finally had the time to sit down and run the requested scanner, which I really didn't want to leave on overnight, but had too.
Quote from what I was to-do:
0k. thanks for the info. Not sure why Roguekiller is flagging those .exe on your desktop. They dont appear to be cracks or keygens.
In any case we can remove the proxy setting. Run Rougekiller again, after the prescan is done click the scan button. Once thats done click on the Registry tab and uncheck everything but this one:
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (203.232.208.116:8080
Then click the delete button to remove the checked item.
You can get a copy of the free version of malwarebytes which you can use as another antimalware app: Let see if it digs anything up.
Please download the free version of Malwarebytes to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program.
Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click *Remove Selected.*
*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*
When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post the log in your reply.
NOTE: The free version must be updated manually and a scan started manually.
http://forums.spybot.info/showthread.php?68481-Infected-Computer-Hacked-Account
So I ran Roguekill a few nights ago when I could and didn't find any sort of Proxy or HKCU in the results, nothing that looked close unfortunately. Then I went on a trip and had to take care of the house (that pesky lawn) with some fire department and ambulance corp events respectfully and finally ran Malwarebytes overnight last night. It didn't find anything, which hopefully means I'm on the up and up and won't be having any account theft issues.
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.05.20.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Cameron :: CAMERON-PC [administrator]
5/20/2013 10:00:10 PM
mbam-log-2013-05-20 (22-00-10).txt
Scan type: Full scan (C:\|D:\|F:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 812763
Time elapsed: 3 hour(s), 25 minute(s), 22 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Quote from what I was to-do:
0k. thanks for the info. Not sure why Roguekiller is flagging those .exe on your desktop. They dont appear to be cracks or keygens.
In any case we can remove the proxy setting. Run Rougekiller again, after the prescan is done click the scan button. Once thats done click on the Registry tab and uncheck everything but this one:
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (203.232.208.116:8080
Then click the delete button to remove the checked item.
You can get a copy of the free version of malwarebytes which you can use as another antimalware app: Let see if it digs anything up.
Please download the free version of Malwarebytes to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program.
Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click *Remove Selected.*
*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*
When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Post the log in your reply.
NOTE: The free version must be updated manually and a scan started manually.
http://forums.spybot.info/showthread.php?68481-Infected-Computer-Hacked-Account
So I ran Roguekill a few nights ago when I could and didn't find any sort of Proxy or HKCU in the results, nothing that looked close unfortunately. Then I went on a trip and had to take care of the house (that pesky lawn) with some fire department and ambulance corp events respectfully and finally ran Malwarebytes overnight last night. It didn't find anything, which hopefully means I'm on the up and up and won't be having any account theft issues.
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.05.20.08
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Cameron :: CAMERON-PC [administrator]
5/20/2013 10:00:10 PM
mbam-log-2013-05-20 (22-00-10).txt
Scan type: Full scan (C:\|D:\|F:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 812763
Time elapsed: 3 hour(s), 25 minute(s), 22 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)