Hello, could really use some help

I purchased a key to upgrade a few weeks ago. Since then i have had two system failures and one all out vicious hack. I would really like to speak with someone in regards to the hack and the nature of it. Also, I tried to activate glasswire after this latest episode and it will not accept my key. I can prove in detail I am the buyer and I need your advise on setting it up correctly to prevent another hack. Thanks and I look forward to your response.
Sincerely,

DG

I suggest you send your concern and your request directly to the Glasswire helpdesk rather than to the Forum.

Hello @Moodruid,

What kind of hack did you have? Please note GlassWire is not an antivirus and cannot replace your antivirus. We recommend you use an antivirus and GlassWire simultaneously because GlassWire works with your antivirus. Unfortunately there is no way to prevent all hacks, but hopefully GlassWire can protect against some hacks and help you notice hacks that already occurred.

Thank you for getting back with me. At the time of the hack I was using subscription WebrootSecureAnyware, subscription Malawayre and the free AV 360 Total Protection as well as Glasswire. Surprisingly, the only one that picked something up was 360. I’m not sure what kind it was but I can tell you the results. Took over the router and gained control of my wireless electronics. Rampaged thru my system gaining access to all email accounts and cloud storage sites. Then, they started communicating with me thru my cell via txt. Showed pictures of things they downloaded from computer and cloud, Said they were LifeHackers and people do not like their methods but the outcome is to make you aware of your vulnerabilities. I have to admit, it was the strangest conversation that even I have had the mis-pleasure of experiencing. They asked why I did not get the higher level Glasswire and better AV software. I had a hard time wondering if this was actually a real occurrence or a companies way to educate and inform. He proceeded to tell me how to fix my security up with Wpa2 and how to ensure they are plugged in correctly. Unfortunately, it was real. They left my system with a master boot password that kept me locked out of getting to bios. Even taking out the back up power supplies I still could not bypass. Got DELL on the phone, they couldn’t bypass. So I lost a hard drive. I was able to track down where the virus came from. The installation of a driver downloading software. The email I have from them confirming my order and the installation links is still in my gmail account and has the virus attached. Plus, it turns out that the two unauthorized purchases with my card were to the company safecart that provides it. About the strangest and unsettling night I have experienced. I ended up taking all the action necessary to secure my accounts, increase security on my email accounts, and xfinity will be out to inspect how everything is hooked up. Turns out I already do have the wpa2 security but during the initial install the cable was not plugged in correctly which left it not engaged. Microsoft and google are looking into the unauthorized access to my accounts and have tracked an IP to Sunnyvale California. I guess we will see what happens. In the meantime, I just want to get back up and running and better protected. The Glasswire is not recognizing my passcode to activate it anymore. So I need to speak to someone in the help center that can work with me on this. Every time I click on the link though it brings me to the main page to access the forums, FAQ, Alert Dictionary, quick start, and user guide. I do not see an option to actually call or talk with someone. Could you please point me in the right direction to how I can get in touch with the company and get this resolved?

@moodruid I’m very sorry that happened to you. Please try activating GlassWire again with your original activation code and it should work now. Next time when reinstalling Windows or switching to a new PC you can go to the top left GlassWire menu and choose “Deactivate” and you probably won’t have to ask us to reset the code, but we’re always glad to help regardless.

I’m glad 360 Total Protection was able to find your virus and stop it. They have a great product.

Thank you Ken. I will give the code a try. Is there a way of being able to upgrade to the next level up and just pay the difference in cost from the two? Or would that involve a new order for the PRO product? Thanks

1 Like

WSA monitors unknown processes and files so when determined bad in the WIN Cloud Database it can rollback to the pre-infection state. I use WSA with Glasswire and love the Combo even though WSA has and outbound firewall the settings does not show on Windows 8 or Windows 10 so the reason I like Glasswire with WSA.

Thanks,

Daniel :grinning:

1 Like

@Moodruid I don’t think having the Pro version instead of the Basic version would have made a difference with your hack problem, but if you want to upgrade you can order another Basic code and let me know when it’s done, then I’ll email you a Pro code manually.

Thank you.

1 Like

@Ken_GlassWire your quite right as the OP says his Router has been compromised. So the OP would need to reset the Router and even look for Firmware updates for there particular Router and make sure the security settings are correct like changing the Routers Password and use the highest Security Setting WPA2-PSK with AES encryption with a very good password.

Daniel :grinning:

Microsoft MVP Consumer Security

Very good point. I have reset the router but I’m not sure how to go about checking on firmware updates. Is that something Xfinity would need to do or can I check from my pc? And how could I get the AES encryption going? :slight_smile:

Also, do you have any idea where I could send this virus to and have it analyzed? I still have it locked in my email account. It is attached to the certificate of purchase and the actual download exe.

What is the Name an Model of your Router? Then I can find some info for you.

Daniel

Microsoft MVP Consumer Security

It is an Arris, model number: TG1682G. Thank you! :smile:)

You have allot of reading to do! http://media2.comcast.net/anon.comcastonline2/support/help/faqs/wireless_gateway/HOW5220_Wireless_Gateway_3_UserGuide_06_19_15.pdf for now reset is on page 34 and look here for Wi-Fi setup and security http://setuprouter.com/router/arris/tg1682g/wifi.htm

HTH,

Daniel

Looks that way LOL. But, I didnt have anything else to do tonight, so…:slight_smile: Thanks!!!

@Moodruid You could upload the virus to VirusTotal.com, but I think it’s better to just delete it just in case you accidentally re-infect yourself again somehow.

It just turned out to be a PUP/PUA: Here is more info from VirusTotal: https://www.virustotal.com/en/file/88a6c5c5370ca0ea4fc3839602bd6085cefae3adbbe75a9d2f13d7c9d8f0fc4e/analysis/1450149329/ as he sent me the email. Also Webroot SecureAnywhere detected it.

Daniel

Microsoft MVP Consumer Security

1 Like

Hello gentlemen. My apologies for being away for the last couple of days but I have been swarmed again by those things and had to, yet again, do another clean wipe install of my Windows 7 Home Premium. One day into rebuilding from that, yet again swarmed. This time, on top of that, I’m dealing with all the lovely registry bugs caused by an unstable wusa.exe application. Malwarebytes tech team has taken upon themselves to find out why this is happening. I just finished doing a full Farbars recovery tool scan for them and sent off Mals and Webbies threat assessment logs to give them as much info as possible. I think it is out of hurt pride since Mal premium has not caught one of these buggers. Webroot stands at 12 snags out of 14 scans and even Core Securities has nabbed a few himself. The latest round however was the most interesting one. Webbie started to show up as infected to me, and apparently, I was looking infected to him. I had his threat detection set at lethal response that the little bugger actually tried to erase me a few times. I’m getting a lot of risk alerts coming in from Glasswire as well. Is there anyway to export those logs? He is detecting multiple DNS changes, Host value changes, etc… So I thought you might be interested at seeing his logs. Hope everyone else is doing better than my current situation LOL. Thankfully, I will be getting a laptop over Christmas so I will just retire this poor guy, douse him in bleach and rubbing alcohol, and give him a fiery farewell on his trip to Valhalla ;).

Contact Webroot support and they will deal with any malware as this seems very odd to me! https://www.webrootanywhere.com/servicewelcome.asp

Thanks,

Daniel