This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Stress Removal

Strange goings on - help!

33 min read

This thread's last reply is from March 28, 2008, 12:13 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Forgive me if it's not allowed to "talk shop" on this forum! :oops:

I know you guys are always very busy, so I didn't want to have someone needlessly wading through a HJT log.

Saturday I tried to buy some airline tickets on BMI Baby site, (never previously had a problem), at the final screen, I clicked the "Buy" button, and was returned to the start of the purchase procedure.
There was no explanation, no "X field requires completion" or any other information so I exited the site.
I managed to ascertain from BMI by phone that no purchase was apparent to them, and from my bank, that the card had not been debited. :|

Still suspicious, I scanned my PC with Spybot, Ad-Aware 2007, and AVG Antivirus.
Ad-Aware turned up "Win32.TrojanSpy.banker", which panicked me and I removed it. :pale:

To be sure, I ran a-Squared to check, success.
However, a-Squared then found something in the sys32 folder called Win32.processor.20 which it classed as a low risk process. :(
I was unable to find out about it, or what programme it might be associated with, so quarantined it.
I have searched the Sys 32 folder, and not found any file of this name.
Can someone advise if I should post a log?
Don't worry, it's fine to ask questions here.

Yes! You should post a log as soon as possible. Read the directions and posts at the top of the malware Removal forum for directions on how the process works. Post your log and then wait for help.

If I were in your position I'd also stay off the internet as much as possible other then to fix your machine here with the help. Until I knew what was going on.

You've done all the main stuff for removal so now it's best to get a log posted and then keep checking for a reply (it may take a few days).

:D
Drewcat,

Thanks for your advice.
I'll certainly post a log, I understand that it is best to re-name the HJT.exe file before running it (previous advice from this forum), so I'll do that first. ;)

Because I need to book some budget airline tickets from an offer that expires tomorrow (Tuesday Feb5th) I'll do that also. :)

This will teach me to beware of buying on the net at weekend! I was unable to contact either the airline or my bank to see if the transactions had indeed been made until this morning! Fortunately nothing, but I'm ordering a new card after I've bought my tickets!! :lol:

Thanks again for your help.

six-h
Hi,

You're risking your details being stolen. Your name, your whatever you put in. Everything you type is possibly up for grabs.

Can't you do it over the phone?
Drew
Hi Drew,

Your posting gave me a shock! :shock:
I thought I'd got lucky with my HJT log, posted this afternoon!
Looking at the site traffic, I'll not get a reply for about a week. :roll:

This morning I booked my airline tickets, and then phoned the bank again to confirm that this was the only transaction on that debit card since the last one I had done, it was, so I then cancelled the card - should be safe (I hope).

The only other detail they could harvest from that transaction would be my Name, Address, Phone No. and e-mail address, most of which is in the public domain anyway.

Since I'm a bit paranoid anyway, I don't tend to bank on my PC, I use the terminal in my bank, so my only exposure is when I buy off the net, just checked, the last transaction was with a credit card on September 17th last year, and no repercussions, so I guess this infection was after that date.

I just hope that AdAware did indeed remove this piece of digital doggy doo from my machine! :P

Just noticed that you are in Seattle, my ex wife's uncle was City Treasurer in Vancouver, and lived in Campbell Town.
In years gone by, the pictures they used to send of the scenery and wildlife there used to make me green with envy.
You certainly live in a beautiful part of the world.
It's on my Bucket-list to visit! :D

Thanks for your concern, Just hope I don't "rue the day"!!

six-h
Hi,

Sorry I tried not to give you a shock, that was the softest way I could come up with to tell you. Plus I was hoping to warn you before you did it, just in case some very personal information was needed.

I don't have any permissions to help you here so I can't try to. Only undergrads and up can. So I have to be careful not to go on about it because too many of us don't know what we are doing and give bad information when we aren't trained enough. It is a good rule to have, as you should get appropriate experienced help.

Once you get a helper they will explain it. It doesn't always take so long as it seems. Someone can take your log anytime. Someone might recognize the infection is one they have cleaned before and take it sooner etc. If after 3 days you still have no response, use the topic at the top "three day bump topic" to post a link to your post. However, again, if I were in your position I'd stay off that computer except to check the posts here and then to fix it. I've had to do it myself before so I don't say that from the point of someone who doesn't know what its like to stare at a computer you desperately want to use for days! Just be patient and wait, the help here is very good.

I'm a bit paranoid anyway,

hehehe - me too.

Seattle is wonderful. The islands off Washington/Canada are amazing! I love it here but freeze to death 10 months of the year. Come in August :lol:.

Just hope I don't "rue the day"

It's good you cancelled the card.
Most Credit Card Companies cif you call the can give you a one time use # that is not linkable back to your card or the other option is use a prepaid credit card or stores shoping card something that if it gets stolen and you have 2 cents on it the they get 2 cents no more not linked to you. Just my parinoid take on online shopping.
Hey, eaglehorse!

I like the sound of that!
It kinda matches my paranoid lifestyle!!
I'll make some enquiries.

Funny, but before I had a computer, I never thought that they were all out to get me!
:hiding:
Thanks.
six-h
Hey Eaglehorse,

Thanks for that info, that helps me also. I know my father keeps one card that has a low limit on it for internet use. I think getting that one time use number is a pretty good idea.

I had a checkbook stolen once well twice, but the one I am speaking of now is the last time. Man those people are so fast to start using your checks its insane.

A lady at a store called us to tell us she had refused a woman who had an ID in my name! So not only was she out with my checks, she had already managed to get an ID with my name on it..... She wasn't caught then but awhile later I got a call from a police dept. saying they found my checks in someones car that they busted. Still to this day I suffer credit issues from a large retail store because they won't accept the paperwork and fact it was a stolen check.

When that happens to you- you have to get a form to fill out for each company the checks were written to, copies of each check, then get it notarized and send them to the company. Then hope the company does the right thing. It's a real pain because normally they have written checks to a lot of places. Although there is better protections in place today.

Oh and even if you know who did it, the cops don't care nor do the people set up specifically to take care of check fraud. I could not get anyone to even go question the man who had detailed my car and stolen the checkbook I had accidently left inside it, despite his own boss saying he had taken it. It was then I realized why criminals do this, they don't even really have to worry about getting caught.

There is something to be said for being paranoid....
Well theres my protect your stuff rant lol
Grrrr!
:cat:
Drewcat

A sorry tale indeed, it must be a nightmare to sort out, and as you say the repercussions rumble on for years.
The maddening thing about it is the guy responsible just swans off and there is little if any attemt made to catch him/her, or should I say "IT".

I don't know how these people have the nerve to do these things, I know I couldn't.
Well....I'd need to wear a diaper!!

Hope you don't get any more nasty surprises :)

I've not been able to find out about "disposable" cards, but the next best thing seems to be as you say, use one card for the net, with a low value account, (with no overdraft facility) to minimise any possible losses.
The things we have to do to keep what's ours!
Then along comes the government, and steals it anyway! lol

six-h
I'd need to wear a diaper



Yea, its awful. But I believe in karma, universe always catches up with people. Then on it's way by, it stops to harass me for fun.
Excuse my $0.02 but Karma is twin of Murphey and he(I think it is a he maybe a she) follows me arround. Especially at work. :D Just a bit of humor life is to short to take to seriously. About the CC bit I cannot take full credit my sis told me about it I only pass along info . Smile it makes people wonder and if all else fails help someone makes 2 people fell better. :bigsmurf: Enough of my warped humor and butting in :oops:
Yes, some say Karma is a she lol. I know murphy too.

It is the universes cruel sense of humor that scares me!
- Tip - Never look into the sky and say "IS that enough!? Are YOU finished messing with me yet?!". I won't tell you what happens after that because you probably wouldn't believe me, but suffice to say, I would never tempt it like that again lol.


Come to think of it, it hasn't messed with me for a long time.
:hiding:

:lol:

You didn't butt in Eagle!
Drewcat,
Yes, I sort of believe in Karma, ....
If only I could witness it in action
It'd be soooo satisfying :laughing8:

Eaglehorse,
Thanks, to your smart sister!
Tell her to keep the good ideas comming! :idea1:

six-h
If only I could witness it in action
It'd be soooo satisfying


One day you will
and
It is :)

Best of luck with your fixing. Let us know how it goes.