Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ebay/capitalone asking for ATM Pin, and computer freezes


  • This topic is locked This topic is locked
6 replies to this topic

#1 voltagexx

voltagexx

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 24 January 2010 - 02:49 PM

I've been having this problem for a while and can't figure out what is going on! My computer freezes up randomly, and I can move the mouse but do nothing else. Additionally, sometimes ebay and capitalone.com (those are the only sites I've experienced it on so far) ask me for my credit card number, atm pin, etc. after I log in (obviously I have not typed them in, as I realize that is not legit). I've searched everywhere to find solutions and nothing has worked. Someone please please help me, as it is starting to really drive me crazy.
Also, something I've noticed recently that never happened before, sometimes when I'm typing in a search bar or anything like that, where it finds results based on what you've typed, it lags really bad and I have to type one letter about every 5 seconds or it will start skipping letters. Hopefully that makes sense. Anyways, have at it everyone, and thank you SO much in advance for anyone who can give me a hand.

BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,325 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:13 PM

Posted 24 January 2010 - 03:15 PM

Run a scan using Super Antispyware free. Be sure to update SAS after downloading, installing and before scanning.
http://www.superantispyware.com/
Allow SAS to remove whatever it finds.
Post the log here from SAS.

If SAS does not find anything other than cookies, scan with Bid Defender's online scanner.
http://www.bitdefender.com/scan8/ie.html
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 voltagexx

voltagexx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 24 January 2010 - 03:55 PM

I ran the quick scan on SAS and removed all items found. Here is the log.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/24/2010 at 03:44 PM

Application Version : 4.33.1000

Core Rules Database Version : 4512
Trace Rules Database Version: 2324

Scan type : Quick Scan
Total Scan Time : 00:17:33

Memory items scanned : 576
Memory threats detected : 0
Registry items scanned : 451
Registry threats detected : 3
File items scanned : 9823
File threats detected : 102

Adware.Tracking Cookie
C:\Documents and Settings\Tom and Sarah\Cookies\tom_and_sarah@atdmt[1].txt
C:\Documents and Settings\Tom and Sarah\Cookies\tom_and_sarah@ad.yieldmanager[1].txt
C:\Documents and Settings\Tom and Sarah\Cookies\tom_and_sarah@invitemedia[1].txt
C:\Documents and Settings\Tom and Sarah\Cookies\tom_and_sarah@ads.bleepingcomputer[1].txt
C:\Documents and Settings\Tom and Sarah\Cookies\tom_and_sarah@doubleclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@sales.liveperson[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@sales.liveperson[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@richmedia.yahoo[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@richmedia.yahoo[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@xiti[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@microsoftsto.112.2o7[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@specificmedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@stopzilla[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@stopzilla[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@cashbackaccount.bing[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@specificmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@avgtechnologies.112.2o7[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@cdn4.specificclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@specificmedia[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@specificclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@viacom.adbureau[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@112.2o7[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.burstnet[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.burstnet[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@bluestreak[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@stats.townnews[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@stats.townnews[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@pointroll[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.undertone[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@tacoda[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@mediaforgews[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@mediaforgews[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@doubleclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@questionmarket[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@doubleclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@chitika[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@interclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@interclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ad.yieldmanager[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ad.wsod[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@eyewonder[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@tacoda[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@adbrite[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ad.wsod[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@technologyquestions[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@revsci[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@revsci[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@revsci[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ad.yieldmanager[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.bleepingcomputer[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@2o7[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@tribalfusion[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@tribalfusion[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@atwola[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@burstnet[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@burstnet[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@andomedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@at.atwola[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.burstbeacon[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@atwola[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.vuze[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.vuze[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@media6degrees[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@andomedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@at.atwola[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ar.atwola[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.burstbeacon[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.stopzilla[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@collective-media[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@collective-media[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@adecn[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.stopzilla[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@media6degrees[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@invitemedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@atdmt[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@www.technologyquestions[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@trafficmp[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@invitemedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@atdmt[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@atdmt[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@advertising[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@a1.interclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@burstbeacon[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@kontera[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.fulldls[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.pugetsoundsoftware[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.pointroll[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@content.yieldmanager[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@inl.adbureau[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@overture[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@realmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@cdn.at.atwola[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@content.yieldmanager[5].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@content.yieldmanager[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@content.yieldmanager[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@edge.ru4[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@imrworldwide[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@imrworldwide[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@imrworldwide[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.infinisource[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\tom_and_sarah@ads.veoh[1].txt

Trojan.Agent/Gen-Alureon
HKU\.DEFAULT\Software\h8srt
HKU\S-1-5-21-776561741-926492609-839522115-1004\Software\h8srt
HKU\S-1-5-18\Software\h8srt

Adware.eXactAdvertising-Installer
T:\C DOWNLOADS\DOWNLOADS\VOLUTIVE1.EXE

#4 buddy215

buddy215

  • Moderator
  • 13,325 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:06:13 PM

Posted 24 January 2010 - 04:07 PM

Run a full scan and allow SAS to scan all files.
Post back the results.

Use the program in the link below to clean up the temporary files, logs, etc
before the SAS scan.
http://www.atribune.org/ccount/click.php?id=1

Scan your computer for important missing security updates. Use Secunia
online scanner. http://secunia.com/vulnerability_scanning/online/

You can block the third party cookies that SAS removed from ever installing on
your computer. Follow the instructions in the link below.
http://www.howtogeek.com/howto/windows-vis...cookies-in-ie7/
You should block the cookies before running the SAS scan as it will remove any
third party cookies that are now on your computer.

If you use a browser other than IE, let me know.
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#5 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,012 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:13 PM

Posted 24 January 2010 - 04:08 PM

Hello,

You have a bad rootkit aboard. Please follow the instructions in ==>This Guide<==.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<==

If you cannot produce the DDS logs, then post back here and we will provide you with further instructions.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#6 voltagexx

voltagexx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 24 January 2010 - 04:24 PM

Hello,

You have a bad rootkit aboard. Please follow the instructions in ==>This Guide<==.

Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<==

If you cannot produce the DDS logs, then post back here and we will provide you with further instructions.

Orange Blossom :thumbsup:

I have done as you asked, and the requested topic is HERE. I look forward to further help you can give me in removing the rootkit you mentioned.

#7 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,012 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:07:13 PM

Posted 24 January 2010 - 04:31 PM

Hello,

It will be someone else that will assist you. I was able to recognize the baddy from your log from seeing it in other topics I've followed.

Now for the hard and frustrating part: waiting.

Now that you have posted a log, you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a HJT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the HJT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the HJT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the HJT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days, up to a week or more perhaps less, to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users