Trojan horse alert when accessing PayPal Website

pieren,

My apology for the delay. :o Sunday...

The RogueKiller report does not show malware, the Hosts file is OK, and there are no Domain Name System (DNS) hijacks showing where malware has an override on your computer's TCP/IP configuration to point at an undesirable DNS server.

Had a quick glance at the FRST report, and do not see anything there, but, will take a closer look.

Press on with using the program on Post #12, Temporary File Cleaner, and then do a Boot Time Scan with avast! to make sure malware can’t load itself into system memory:

Start the avast! user interface
In the left column, click: Scan Computer
Under Scan Computer, click: Boot-time Scan
In the next prompt, select: All harddisks
Click the orange bars on the Heuristics sensitivity, and set to: High
Check: Scan for Potentially Unwanted Programs
Check: Compressed (packed) archived files
Click: Schedule Now
Restart the computer.

If anything is found during the boot scan the prompts are self explanatory, follow their advice.
When done, please post the Scan Log, or, post a screenshot of the results:
http://www.sevenforums.com/tutorials/9733-screenshots-files-upload-post-seven-forums.html



Next, follow up with the free version of Malwarebytes : Malwarebytes Anti-Malware removes malware including viruses, spyware, worms and trojans, plus it protects your computer
Save to the Desktop.

Double-click the downloaded file to run MBAM.

When the installation begins, follow the series of setup wizard prompts pressing Next, and on the last prompt, press: Install
When done with this phase, press: Finish

MBAM automatically starts and takes you to the main console and to the Scanner tab.
On the Scanner tab:
Select: Perform Quick Scan

Click: Scan

When the scan is finished, a message box shows: The scan completed successfully. ..etc.

If anything is found, click Show Results to display all objects found.
Click OK to close the message box and continue with the removal process.
Make sure that everything is checked, and click: Remove Selected

When removal is completed, a report opens in Notepad.
(The log is automatically saved and can also be viewed by clicking the Logs tab).

If anything is found, please copy/paste the contents of the MBAM report and provide in your reply.


Also, post back on whether you are still getting the Bankfraud-BBE [Trj] notice.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Just an FYI when installing Malwarebytes,

Make sure to uncheck the box to start the trial of the pro version at the last screen.
 

Attachments

  • mbam.JPG
    mbam.JPG
    43 KB · Views: 5

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
Thanks, derekimo!

Not sure whether that entry was present the last time I installed MBAM.

Thanks for bringing it up to our attention. :)
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
You're welcome. :)
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
According to the topic regarding this at the Avast forums, it would appear this was a false positive from Avast. However, I'd still err on the side of caution to be on the safe side and run a few scans if you're unsure.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1Intel Core i7 2700K @ 3.5GHz (TurboBoost disa...16GB (4x4GB) Kingston HyperX DDR3 1600MHz @ 1...Nvidia EVGA GeForce GTX 1060 6GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
N/A (custom-built)
OS
Windows 7 Ultimate x64 SP1
CPU
Intel Core i7 2700K @ 3.5GHz (TurboBoost disabled)
Motherboard
ASUS P8Z68-V/GEN3
Memory
16GB (4x4GB) Kingston HyperX DDR3 1600MHz @ 1333MHz
Graphics Card(s)
Nvidia EVGA GeForce GTX 1060 6GB
Sound Card
Realtek High Definition Audio (motherboard integrated)
Monitor(s) Displays
NEC Multisync EX231W
Screen Resolution
1920x1080 @ 60Hz via DVI-D
Hard Drives
2x Western Digital 1TB SATA3 Caviar Black Internal HDD // 1x WD 500GB USB 3.0 "My Passport Essential" External HDD // 1x WD 1TB USB 3.0 "My Passport Essential" External HDD // 2x WD 2TB USB 3.0 "My Passport Essential" External HDD
PSU
Corsair Professional Series Gold AX850
Case
Antec 300
Cooling
Air-cooling
Keyboard
Steelseries 6Gv2
Mouse
Steelseries Sensei RAW Glossy, Logitech M500
Internet Speed
DSL (AT&T)
Antivirus
Microsoft Security Essentials
Browser
Pale Moon, Mozilla Firefox 12, Opera 12, Chromium, IE9
Other Info
Virtual Machines (VirtualBox):
* Japanese Windows XP Professional SP3
* Japanese Windows 7 Professional SP1
I'd still err on the side of caution to be on the safe side and run a few scans

Excellent point, King Arthur!

It is an interesting thread, and also points to vulnerabilities in Internet Explorer.

While running scans, it would be a good idea to include the following:

Security Check:
http://screen317.spywareinfoforum.org/
Save to your Desktop.
Double-click: SecurityCheck.exe
Follow the onscreen instructions inside the black box.
When done, a Notepad report opens automatically, called: checkup.txt

Pay attention to the items identified in red.
SecurityCheck may produce some false warnings, but it is a good idea to check its entries anyway.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
According to the topic regarding this at the Avast forums, it would appear this was a false positive from Avast. However, I'd still err on the side of caution to be on the safe side and run a few scans if you're unsure.

False positive my Aunt Fanny! Someting is definitely going on and either no one really knows what is going on or they don't want to admit fault. I first detected and removed the trojan with SAS, then got it again before Avast finally detected it on a scan and started blocking it when going into PayPal. When I checked today, I was no longer getting the block popup. What's curious is PayPal notified me by email that I needed to update my password a couple, three days ago. Not trusting a link in an email, I went directly to the site and, when I tried to log in, I again was told I needed to update my password. Supposedly, PayPal was doing this with everyone and was requiring more secure passwords. I've already changed my passwords and usernames for my bank accounts, etc. and I'm going to my credit union tomorrow to block the card PayPal is using and both get a new one and open a debit account (no credit to draw against that way) strictly for internet purchases and add money only when making purchases.

I've already run various scans several times and I'm running Avast again right now. I'll run MBAM Pro and SAS free after that.
 

My Computer My Computer

At a glance

Win 7 Ultimate 64 bitIntel i7-3930KKingston HyperX Genesis 32GB Kit (8x4GB Modul...MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
Good going Lady Fitzgerald!! ;)
I've never seen an account (that I frequent) to send an e-mail asking me to update my password!

This is a 'phishing' e-mail to gather more information. :mad:
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Good going Lady Fitzgerald!! ;)
I've never seen an account (that I frequent) to send an e-mail asking me to update my password!

This is a 'phishing' e-mail to gather more information. :mad:

I have, although it's rare (and I still don't trust links in emails). And the fact that I got the same message when I went to PayPal directly instead of via the link suggests that this one was legitimate.

I've finished my scans and I'm still clean.
 

My Computer My Computer

At a glance

Win 7 Ultimate 64 bitIntel i7-3930KKingston HyperX Genesis 32GB Kit (8x4GB Modul...MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
I haven't gotten any email to change passwords on PayPal and I'm unaware if I've been asked to change my password, but I'm playing it safe and trying to avoid going to PayPal's website until all of this subsides.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1Intel Core i7 2700K @ 3.5GHz (TurboBoost disa...16GB (4x4GB) Kingston HyperX DDR3 1600MHz @ 1...Nvidia EVGA GeForce GTX 1060 6GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
N/A (custom-built)
OS
Windows 7 Ultimate x64 SP1
CPU
Intel Core i7 2700K @ 3.5GHz (TurboBoost disabled)
Motherboard
ASUS P8Z68-V/GEN3
Memory
16GB (4x4GB) Kingston HyperX DDR3 1600MHz @ 1333MHz
Graphics Card(s)
Nvidia EVGA GeForce GTX 1060 6GB
Sound Card
Realtek High Definition Audio (motherboard integrated)
Monitor(s) Displays
NEC Multisync EX231W
Screen Resolution
1920x1080 @ 60Hz via DVI-D
Hard Drives
2x Western Digital 1TB SATA3 Caviar Black Internal HDD // 1x WD 500GB USB 3.0 "My Passport Essential" External HDD // 1x WD 1TB USB 3.0 "My Passport Essential" External HDD // 2x WD 2TB USB 3.0 "My Passport Essential" External HDD
PSU
Corsair Professional Series Gold AX850
Case
Antec 300
Cooling
Air-cooling
Keyboard
Steelseries 6Gv2
Mouse
Steelseries Sensei RAW Glossy, Logitech M500
Internet Speed
DSL (AT&T)
Antivirus
Microsoft Security Essentials
Browser
Pale Moon, Mozilla Firefox 12, Opera 12, Chromium, IE9
Other Info
Virtual Machines (VirtualBox):
* Japanese Windows XP Professional SP3
* Japanese Windows 7 Professional SP1
I don't get anymore the popup alert from Avast when opening PayPal website.

Probably it was a false positive
 

My Computer My Computer

At a glance

Microsoft Windows 7 Ultimate 64-bit 7601 Mult...Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz8,00 GBATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Dell XPS 8300
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Motherboard
Dell Inc. 0Y2MRG
Memory
8,00 GB
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
(1) ATI High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) ST31500341AS (2) Generic- Compact Flash USB Device (3) Generic- MS/MS-Pro USB Device (4) Generic- SD/MMC USB Device (5) Generic- SM/xD-Picture USB Device
Antivirus
ava
Back
Top