hijacked possibly

Discussion in 'Malware Help (A Specialist Will Reply)' started by drj1900, Nov 19, 2013.

  1. drj1900

    drj1900 Private E-2

    I believe my computer has been infected and hijacked. I had improper activity on e-mails and banking.

    I have windows 8

    I have not been able to run MG Tools it freezes I really need help resolvin these issues
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the logs from Hitman Pro and TDSSkiller that were requested.

    You also need to rerun Malwarebytes and this time allow it to fix what it detected. You log shows you took no action.

    This does not mean this computer is infected. Information could have been compromised if you ever used any other PC to access your bank account or email account. Also could be intercepted via improperly protected wireless connections.



    When did it freeze? How long did you wait? It could take 15 to 20 minutes to finish running. Did you run it properly??? For example did you do all of the following:
    1. Shutdown protection software first
    2. Disable UAC
    3. Use Right Click and Select Run As Administrator to run MGtools.exe
     
  3. drj1900

    drj1900 Private E-2

    I have attached Hitman, TDKiller and MGTools zip.

    Thanks very much for your assistance and time

    John
     

    Attached Files:

  4. drj1900

    drj1900 Private E-2

    After my last post I turned my computer back on and got a message that my desktop is not available.

    Just a blank screen although the recycle bin briefly appeared. I cannot access anything now
     
  5. drj1900

    drj1900 Private E-2

    I did a system restore back to November 17th and recovered my desktop. Next I did HihackThis and tried to analyze the results. When I attempted to analyze the log I got the following message.

    For some reason your system denied write access to the Hosts file. If any hijackd domains are in this file HijackThis may NOT be able to fix this. If that happens you need to edit the file yourself. To do this click start run and type

    Notepad: C:\WINDOWS\System32\domains\etc\hosts

    Other messages during this process were;

    Cannot find file C:\Program Files (x86) Trend Micro\HijackThis\hijackthis log.
    Do you want to create a new file yes no cancel

    Also when I hit analyze I got the message “no internet connection” . But my computer did have an internet connection available.

    This is actually where my beginning problems began
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    You should not be running HijackThis or anything else unless we ask you to do so. The below is a quote from the READ & RUN ME. See the last bullet item
    Uninstall the below junkware:

    Iminent

    Then rerun Malwarebytes and see if it still detects any of this Iminent stuff. If it does, make sure that you select all the items and allow them to be fixed. Then save the log after fixing and attach the new log.


    Are you having any current malware problems?

    Do you know what the below items are as seen in RogueKiller?
    [RUN][SUSP PATH] HKCU\[...]\Run : Starfield Updater ("C:\Users\johnson\AppData\Local\Workspace\WorkspaceUpdate.exe" [7]) -> FOUND
    [RUN][SUSP PATH] HKCU\[...]\Run : Workspace Status ("C:\Users\johnson\AppData\Local\Workspace\workspacestatus.exe" [7]) -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-4223917168-3260533592-693802220-1001\[...]\Run : Starfield Updater ("C:\Users\johnson\AppData\Local\Workspace\WorkspaceUpdate.exe" [7]) -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-4223917168-3260533592-693802220-1001\[...]\Run : Workspace Status ("C:\Users\johnson\AppData\Local\Workspace\workspacestatus.exe" [7]) -> FOUND
     
    Last edited: Nov 21, 2013
  7. drj1900

    drj1900 Private E-2

    I could not find the junkware Iminent you mentioned in the uninstall programs.

    TDSSKiller no fhreats
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! Did you not read my last message with the instructions about not doing anything we do not request?

    I did not ask you to run Roguekiller, AswMBR, TDSSKiller, or MGtools again.

    I did ask what those items in RogueKiller were and I also asked if you were having any malware problems. I also asked you to run Malwarebytes and fix anything it finds and attach the new log from it.

    It is there. Do the below to remove it.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
    Last edited: Nov 23, 2013
  9. drj1900

    drj1900 Private E-2

    Sorry for sending the added information, I thought you needed it.

    I followed your instruction for copy and paste of the registry entry and got the following message rejection.

    Cannot import C:\users\johnson\desktop\fixme.reg: The specified file is not a registry script. You can only import bunary registry files from within the registry editor
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means you did not create the file properly. There can be no blank lines or anything else above the Windows Registry Editor Version 5.00 line
     
  11. drj1900

    drj1900 Private E-2

    I re-tried without any space in-between and got the same message as I did before. I don't know what I am doing wrong
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you loading it into notepad to save it or are you using a different program?

    Rename your fixme.reg file to fixme.txt and attach it to your next message for me to look at at. You cannot attach files with the .reg extension which is why I'm asking you to rename it first.
     
  13. drj1900

    drj1900 Private E-2

    I changed the name in notepad and attached the file
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Take a look at the file you posted and compare it to what I gave you.

    You have asteriks in the file. You have extra line feeds and you have ---End Quote--- text in it. That is not what was in my fix. You need to make the file look exactly like what I gave you. The below is what you have which is not what I gave you.
     
  15. drj1900

    drj1900 Private E-2

    I re-did the registry entry and it was successful. What do you need me to do next?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  17. drj1900

    drj1900 Private E-2

    Chaslang
    Everything seems to be working OK. Thank you very much for all your time and efforts, I greatly appreciate you for your help.

    I will follow your recommendations regarding malware and keeping my computer clean..................THANKS AGAIN

    John
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds