Websites Were Being Hijacked

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by maglib, Jan 4, 2018.

  1. maglib

    maglib Private First Class

    I kept on being redirected to websites I didn't type. Here are my logs. Please let me know if I need to do anything else. Happy New Year.
    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still need ADWCleaner and Hitman.
     
    maglib likes this.
  3. maglib

    maglib Private First Class

    sorry. I missed hitman step and just failed on the adw upload. Doing hitman, it didn't allow me to ignore anything.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please remove these items in ADW:

    Adware.pokki, C:\Users\Default\AppData\Local\Host App Service
    Adware.pokki, C:\Users\Default User\AppData\Local\Host App Service
    Adware.pokki, C:\Users\fbmag\AppData\Local\Host App Service

    And these reg. entries:
    Adware.pokki, [Key] - HKU\S-1-5-21-2493785166-1293178697-3009174516-1001\Software\Host App Service
    Adware.pokki, [Key] - HKU\S-1-5-21-2493785166-1293178697-3009174516-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
    Adware.pokki, [Key] - HKCU\Software\Host App Service
    Adware.pokki, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service

    These items in RogueKiller:
    ¤¤¤ Processes : 1 ¤¤¤
    [VT.Unknown] igfxEM.exe(7944) -- C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_a834c52195a141e8\igfxEM.exe[7] -> Found

    ¤¤¤ Registry : 6 ¤¤¤
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a5a493af-d60e-4caf-8b4d-96968ad1f3ab} | DhcpNameServer : 10.10.0.1 ([]) -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{fc784e19-91f0-4bee-af5e-f75bd202b41d} | DhcpNameServer : 150.206.1.3 ([New Zealand]) -> Found

    Reboot and rescan with both ADW and RogueKiller and attach the new logs.
     
    maglib likes this.
  5. maglib

    maglib Private First Class

    It appears my son ran and removed everything adware showed last round and removed ASC.... He's back in school so won't touch it again. I didn't find what you told me to remove and I see a report from when I was away got produced.

    How do I delete:
    These items in RogueKiller:
    ¤¤¤ Processes : 1 ¤¤¤
    [VT.Unknown] igfxEM.exe(7944) -- C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_a834c52195a141e8\igfxEM.exe[7] -> Found

    Thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those logs are clean. What malware issues are you still having?
     
    maglib likes this.
  7. maglib

    maglib Private First Class

    right before I did what you said. My site was hijacked to one of those sites saying do not turn off.... I had to shut down google chrome

    This may be the history of what I got hijacked too... not sure.
    Important Information45.55.39.132


    3:39 PM

    Important Informationcurationservices.com


    3:39 PM

    Important Informationadverrd.global.ssl.fastly.net
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not about to click on those. So what is the current status?
     
    maglib and Imandy Mann like this.
  9. maglib

    maglib Private First Class

    so far nothing.... we shall see if anything comes up as it was very random last time. thanks Tim.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  11. maglib

    maglib Private First Class

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser?
     
  13. maglib

    maglib Private First Class

    google chrome
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  15. maglib

    maglib Private First Class

    Done. thanks Is there any forum on safest chrome settings to set up?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  17. maglib

    maglib Private First Class

    Thanks, I could not find instant search? Did all the settings.
    I have a question on form fill data. Is there another way to have default forms filled in as I am often doing forms online so shutting this will cause me to do lots of typing.
    Thank you for all your time.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's a matter for the software forum.
     
  19. maglib

    maglib Private First Class

    thanks TimW. I just ran CCleaner and I'm back to having the same issues. I downloaded Ccleaner from majorgeeks, any chance there was an issue with a version of this?
    This time it does not show in chrome history. I got to one of those danger do not shut down huge screens I know are fake.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download ZHPCleanerto your desktop.
    Close all applications (including your web browsers and antivirus)
    Double-click on ZHPCleaner to run the tool.
    If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    Please click the "J'accepte/I agree" button.
    First press the "Scanner" button. Be patient, the scan may take some time.
    Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.
     
    maglib likes this.
  21. maglib

    maglib Private First Class

    will try this.... thanks as it came back again. I tried to snip it this time.
     

    Attached Files:

  22. maglib

    maglib Private First Class

    Here is the file from zhpcleaner.txt
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are clicking on links that are infected.
     
    maglib likes this.
  24. maglib

    maglib Private First Class

    hmm the link I was going into was finance.yahoo.com at the time. Otherwise I'm going through a number of tax sites prior. Possibly sites getting hijacked?
    I need to do this for my work. Any options?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I just tried your link and no problems. Try that link in a different browser.
     
  26. maglib

    maglib Private First Class

    No problems, this screen just seems to come up once a week... and then it doesn't strangely it can be at any site, it just happened today that it was on the finance site.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this for Chrome:
    http://www.majorgeeks.com/files/details/wot_for_chrome.html

    Rerun ADWCleaner and also
    download Zemana Malware Removal to your desktop and run it please.
    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
    maglib likes this.
  28. maglib

    maglib Private First Class

    thanks here is report. I think both these items are ok?
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How about ADW?
     
  30. maglib

    maglib Private First Class

    I realize I ran ultra adwark killer ... is that okay?
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's fine. Next time it happens, be sure to remember what link you clicked on and report it. Use Firefox for a while. See if it happens with that browser.
     
    maglib likes this.
  32. maglib

    maglib Private First Class

    so nothing on the ultraadware killer report needs to be cleaned up? Just leave it?
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just leave it.
     
    maglib likes this.
  34. maglib

    maglib Private First Class

    I wanted to know your thoughts on needs for a key scrambling software such as Key Scrambler or Ghost Press as a number of people I know got hit by key loggers recently on Facebook. I was sent a few but did not click.
    I volunteer time on a tax help site and for local people here so I'm often doing online searches. I also get a ton of emails from people who have infested laptops.... I've helped a few but as you can see, tech support is not my forte. I can help you with US taxes though... LOL
    Thanks again.
     
    Last edited: Feb 13, 2018
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you post that inquiry in the software forum.
     
    maglib likes this.
  36. maglib

    maglib Private First Class

    @TimW so I looked up the phone number that was coming up on the virus alert 855-291-6646 claiming to be windows and there are some tips to remove on other sites that I'm not sure I can trust. If you just search the phone number you will find tons of tips. Any of these sites legitimate?
    I had issues running some of my stuff on anything but chrome so I'm back to chrome and it keeps happening. Seems more often on any site that has a messenger board.
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Need a link.

    In the meantime:
    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
    maglib likes this.
  38. maglib

    maglib Private First Class

     
  39. maglib

    maglib Private First Class

  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are not the links I asked for. I want a link to the website that produces the malware alert.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds