Hotmail/Microsoft.com Hijacker #1

Discussion in 'Malware Help (A Specialist Will Reply)' started by xxdekaxx, Apr 30, 2007.

  1. xxdekaxx

    xxdekaxx Private E-2

    Hello,
    I have followed all the procedures outlined in the READ AND RUN me first post and wish to submit the log files for additional help.

    I believe i have a hijacker on this machine that is preventing anyone from going to Hotmail.com, MSN.com or Miscrsoft.com on this machine. When i attempt to goto one of these web sights the browser takes a long amount of time trying to connect before finally giving a message the web sight is not available.
     

    Attached Files:

  2. xxdekaxx

    xxdekaxx Private E-2

    Re: Hotmail/Microsoft.com Hijacker #2

    Additional files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What browser are you using?
    If it is Internet Explorer, please try the below and tell me if the same problem occurs:

    Mozilla FireFox
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not appear to have any malware problems based on your logs. However you did not attach the CounterSpy log as requested but I would assume it did not find any real issues.

    However I do question who created and what the below files are for?
    Code:
    C:\Program Files\
    del_temp.bat  Apr 27 2007         270  "Del_Temp.bat"
    spyware.bat   Apr 27 2007         840  "Spyware.bat"
    
    They were created on April 27 th.


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software
     
  5. xxdekaxx

    xxdekaxx Private E-2

    Thanks for the welcome and the help, i normally can work through these problems on my own but this one is kicking me arse!

    This computer im working on is the one the Crew use to check there email so there is no telling who or what has been put on this machine. I work on an offshore drilling rig currently assigned in Australia.

    Ok CounterSpy found nothing, sorry i forgot that one but it didn't generate anything except a "no problems found message".

    The 2 bat files you mentioned in your second post i have removed from this machine but i saved them in case you might want me to send them to you in case you want to try and figure out what they are. I will not post them here as they could be something nasty but if you want them i have them in a zip file and can email them to you if your curious and want to have a look.

    I attempted to go to Hotmail using Firefox from my memory stick or U3 drive and that was unsuccessful. Not that i thought it would make any difference i actually installed Firefox on this machine just to see ,myself personally i do not use IE i use Firefox and SeaMonkey. Installing Firefox on this machine did not make a difference either.

    Just to let you know i have already made sure the windows firewall setting where put back in default and i have also attempted to access Hotmail, Microsoft and msn with the windows firewall turned off and nada.

    We have multiple machines on this network and this is the only machine i am having this problem with.

    I try msn.com it times out and says Connection was reset (Firefox)

    I try hotmail.com it times out same message (firefox)

    I try Microsoft.com it times out same message again (firefox)

    Hopefully something can be figured out before i admit defeat and do the dreaded format and reinstall rolleyes
     
    Last edited: May 1, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try a few other things!

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Now click Start, Run, and enter ipconfig /flushdns and click OK!


    Now please download DelDomains and unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    (Now you will need to "Immunize" with Spybot again because deldomains will remove all of the sites Spybot adds.)



    Did any of the above change anything?

    And yes, put those two files into a ZIP file and just attach them to your next message. If they are really anything nasty, I can just delete it, but no one can run something in a ZIP file by mistake. They would have to do it on purpose.




     
  7. xxdekaxx

    xxdekaxx Private E-2

    I will go ahead and attach those bat files anyway but i figured out what they where, my company uses an online IT support group called the Techcess Group, anyway they are scripts they ran on this machine to try and sort this problem and from what i found out they threw in the towel a couple of weeks ago just like they do with most difficult issues and leave it up to us Electronics's Techs to sort.

    Techcess attempts to manage out IT remotely and they do fine for simple task but anything complicated my kids do a better Job.

    One of the files was a script to run Spybot and the other was a script to delete the temporary internet folder.

    I did exactly what you instructed and am still having the same problem with this machine.

    Something else i just noticed thats real strange, on every user login the Window Update shortcut is missing and the only place i can find a shortcut now to windows update is through the Help and Support Center window.

    Its even missing those shortcuts when i log in as "Administrator" which is also very strange because the no one except the ET's and IT's have access to this login.

    And no it will not access windows update either, basically anything related to Microsoft as far as the web is concerned is inaccessible.

    What next and again thanks for all the help.
     

    Attached Files:

    Last edited: May 4, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're problems do not appear to be related to malware. It seem more like a configuration issue or a setting on your end that is blocking them.

    Have you tried using a different browser? I asume you are using IE. Try FireFox.

    Do you go thru a router to get to the internet? If so, have you tried bypassing the router?

    Do you have multiple PCs on your network? Do the other PCs connect okay?

    Why is the below running?
    C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe

    You can delete the below two files since you don't need them and they things that you could have easily done on your own.
    C:\Program Files\Del_Temp.bat
    C:\Program Files\Spyware.bat


    Uninstall the Sunbelt CounterSpy trial since we are finished with it now!


    Let's do a check for rootkits just to be safe.

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds