Author Topic: Help, PC infected with malware  (Read 3544 times)

0 Members and 1 Guest are viewing this topic.

Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Help, PC infected with malware
« on: August 20, 2019, 02:14:04 PM »
I hope I've attached the files correctly
« Last Edit: August 20, 2019, 02:15:59 PM by rich.thompson »

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help, PC infected with malware
« Reply #1 on: August 20, 2019, 07:30:11 PM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
HKLM\...\Run: [boinctray] => C:\Program Files\BOINC\boinctray.exe [69920 2018-10-11] (University of California, Berkeley -> Space Sciences Laboratory)
HKLM\...\Run: [boincmgr] => C:\Program Files\BOINC\boincmgr.exe [9063712 2018-10-11] (University of California, Berkeley -> Space Sciences Laboratory)
CHR HomePage: Default -> hxxp://www.goal-nav.com/
CHR StartupUrls: Default -> "hxxp://www.goal-nav.com/"
CHR DefaultSearchURL: Default -> hxxp://www.goal-nav.com/search?q={searchTerms}
C:\Program Files\BOINC
EmptyTemp:
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Re: Help, PC infected with malware
« Reply #2 on: August 21, 2019, 11:10:47 AM »
Thank you for your reply, I'm not as savvy to this, so please help in finer detail

Go to File -> Save As WHICH FILE?

Make sure that  UTF-8 is selected as Encoding (left side of Save button) I'M HOPING THAT UTF-8 IS OBVIOUS

HOPEFULLY I CAN THEN FIGURE THE REST OUT

Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help, PC infected with malware
« Reply #3 on: August 21, 2019, 12:18:48 PM »
Quote
Go to File -> Save As WHICH FILE?

Open Notepad (click Start button -> type notepad.exe -> press Enter)
Copy text from code block below and paste it into Notepad


Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Re: Help, PC infected with malware
« Reply #4 on: August 21, 2019, 12:34:33 PM »
I give up, I'm obviously too thick to figure out your instructions

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help, PC infected with malware
« Reply #5 on: August 21, 2019, 12:41:43 PM »
Do you know what notepad is and how to open it?

Then see post from @Sass Drake

copy the text inside the code box in to the notpad vindow and save it on your desktop with the name fixlist.txt


EDIT: Have created and attached file here for you, see below ... download it and save to desktop, then run as @Sass Drake instructed






« Last Edit: August 21, 2019, 02:09:02 PM by Pondus »

Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Re: Help, PC infected with malware
« Reply #6 on: August 21, 2019, 03:18:41 PM »
Thank you, I was struggling.
I have attached the file as requested

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help, PC infected with malware
« Reply #7 on: August 21, 2019, 03:30:28 PM »
@Sass Drake Will Reply when he is back online

Is your problem solved?


Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Re: Help, PC infected with malware
« Reply #8 on: August 21, 2019, 03:34:27 PM »
I have no idea, it all started with an email from someone listing all my passwords

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Help, PC infected with malware
« Reply #9 on: August 21, 2019, 03:50:37 PM »
That May have Been one of those scam mails

I will post a link when i am online on my computer

Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Re: Help, PC infected with malware
« Reply #10 on: August 21, 2019, 03:53:20 PM »
The email contained MY passwords, so obviously I'm worried


Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help, PC infected with malware
« Reply #12 on: August 22, 2019, 06:08:48 PM »
I have no idea, it all started with an email from someone listing all my passwords

Can you copy that mail here?

Offline rich.thompson

  • Newbie
  • *
  • Posts: 8
Re: Help, PC infected with malware
« Reply #13 on: August 22, 2019, 06:43:28 PM »
Funny thing is I DON'T have a web cam lol

Save Yourself <SaveYourself53@7971.com>
Tue 20/08/2019 02:57
Hey, I know your password is: Marlin001

Your computer was infected with my malware, RAT (Remote Administration Tool), your browser wasn't updated / patched, in such case it's enough to just visit some website where my iframe is placed to get automatically infected, if you want to find out more - Google: "Drive-by exploit".

My malware gave me full access and control over your computer, meaning, I got access to all your accounts (see password above) and I can see everything on your screen, turn on your camera or microphone and you won't even notice about it.

I collected all your private data and I RECORDED YOU (through your webcam) SATISFYING YOURSELF!

After that I removed my malware to not leave any traces.

I can send the video to all your contacts, post it on social network, publish it on the whole web, including the darknet, where the sick people are, I can publish all I found on your computer everywhere!

Only you can prevent me from doing this and only I can help you out in this situation.

Transfer exactly 1600$ with the current bitcoin (BTC) price to my bitcoin address.

It's a very good offer, compared to all that horrible shit that will happen if I publish everything.

You can easily buy bitcoin here: www.paxful.com , www.coingate.com , www.coinbase.com , or check for bitcoin ATM near you, or Google for other exchanger.
You can send the bitcoin directly to my address, or create your own wallet first here: www.login.blockchain.com/en/#/signup/ , then receive and send to mine.

My bitcoin address is: 194iizBy5K9AVDqTBvzDAWR6t9MrrqvseZ

Copy and paste my address, it's (cAsE-sEnSEtiVE)

I give you 3 days time to transfer the bitcoin.

As I got access to this email account, I will know if this email has already been read.
If you get this email multiple times, it's to make sure that you read it, my mailer script is configured like this and after payment you can ignore it.
After receiving the payment, I will remove everything and you can life your live in peace like before.

Next time update your browser before browsing the web.





Mail-Client-ID: 3547708280

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Help, PC infected with malware
« Reply #14 on: August 22, 2019, 08:36:52 PM »
Fraud mail trying to scam you. Your PC is clean.