Getting Hi-jacked

Discussion in 'Malware Help (A Specialist Will Reply)' started by ferretlady3, Oct 15, 2018.

  1. ferretlady3

    ferretlady3 Private E-2

    Hi! My laptop keeps getting my settings hi-jacked - in Firefox as well as startup files and it's running very slow so I figured I'd turn to you guys since you've always helped in the past. Ran all the diag's as instructed and am attaching my log files (I'm sure it has something to do w/all the PUP files that were found!)

    Thanx a bunch!

    Dawn
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please remove everything found in ADWCleaner and Hitman. You did not run MGTools correctly.

    Please reboot after removing the above and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7,or Win8 or Win10 don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Rerun ADW and Hitman and attach the new logs.
     
  3. ferretlady3

    ferretlady3 Private E-2

    Thanx - I was having trouble w/MGTools cuz my anti-virus software, BitDefender Total Security, kept it from getting access to files. I disabled everything in BitDefender and even ended up removing it from my Startup so I could run the MGTools. Maybe I need to remove BitDefender. I'll try it again. Didn't know you needed the .bat file. I'll get rid of everything from ADwCleaner and Hitman and redo the MGTools. Oh, I have Win7 w/sp1 - forgot to add that in my original post.

    Thanx for answering so quickly! I'll repost the file needed from MG Tools, ADWCleaner and Hitman.

    Dawn
     
  4. ferretlady3

    ferretlady3 Private E-2

    Oh, I forgot to say that Hitman won't let me remove anything. It comes up as my trail period is over so I have to buy it to remove anything. Can I somehow get it out of cache, history or something? Last time I used it was probably about a yr ago so now every time I try to use it, it makes me buy it to remove anything. I CAN probably remove all the files by hand. I DO know how to go into my registry and find the files listed, unless you have some way I can re-download and use Hitman to get the trial period again so's I can remove the PUP files for free. I'll wait for your answer before I go further.

    Thanx!

    Dawn
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now just do the rest and be sure to tell me how things are running.
     
  6. ferretlady3

    ferretlady3 Private E-2

    Hi Tim,

    Ok ran ADWCleaner and let it remove everything found. That log file is attached. Copied [-HKU\S-1-5-21-1009334687-539450264-314055710-1000\Software\IM] and saved as fixME.reg to desktop using "save as" set to "all files". I tried to double click on it, but got this message: Cannot import C:\Users\ow\Desktop\fixME.reg: The specified file is not a registry script. You v=can only import binary registry files from within the egistry editor.

    I rebooted my machine (disabling my BitDefender since it gave me trouble last time w/MGTools) then I went to C:\MGTools\GetLogs.bat file as instructed and ran as admins'trd. Nothing came up for TrendMicro HijackThis license agreement so I just let it run. I've attached the MGlogs.zip file.

    Let me know if there's anything else I need to do. It's still running a bit slow and my screen kept going out while running MGTools but I haven't noticed anything being hijacked again - at least not yet.

    THANK YOU SO MUCH AGAIN!

    Dawn
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having, if any?
     
  8. ferretlady3

    ferretlady3 Private E-2

    Sorry it took me so long to reply. I was sick w/that flu going around and haven't been on the PC. So far everything seems to be ok. If I have any other issues, I'll let you know but I just got on for the first time today so I haven't ran a lot of things. Seems my home page isn't being hi-jacked any more either.

    Thank you so much again!

    Dawn
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know. If all is good, I will give you final cleanup instructions.
     
  10. ferretlady3

    ferretlady3 Private E-2

    I've been on my machine for a while, even logged off and rebooted again and all seems to be ok. What should I do for a final cleanup? And thanx so much again!!

    Dawn
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  12. ferretlady3

    ferretlady3 Private E-2

    Thanx a bunch again! As for Malwarebytes, the one on your site is a trial version so I went to cnet downloads and got the free version and installed it.

    Thank you so very, very much!!

    As always, you guys have been great and I recommend you to anyone I know who's having issues w/their computer!

    Dawn
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds