[Help] SettingsModifier: Win32/PossibleHostsFileHijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by VietSushi, Mar 9, 2009.

  1. VietSushi

    VietSushi Private E-2

    An automatic scan of Windows Defender today caught this malware:

    SettingsModifier:Win32/PossibleHostsFileHijack

    I can't remove it using Windows Defender. Microsoft's site gives instructions on how to manually re-create a clean file, but every time I try to save it, I get a incorrect file path error.

    This malware is supposed to mostly come from Chat programs (Live, MSN, etc) I haven't used any of those programs since months ago. The malware is supposed to redirect most of my web address' to another address that I didn't type it, but the malware doesn't seem to be doing its job.

    Any help?

    I've ran through the list of programs that shouldn't be installed on the sticky on this forum and haven't found any. (Opera 10 using quick search based on the list of programs I have on my computer use Programs & Features.)

    I run Windows Vista SP1 Home Premium. Most people get this malware from Instant Messengers as I've read, I haven't been on Live Messenger or any other type (besides Gmail + Built-in chat) for months.
     
  2. VietSushi

    VietSushi Private E-2

    More detail:

    Microsoft's site says that the HOSTS file should say: 127.0.0.1 localhost

    I've reviewed my file and it says: 1 localhost

    I haven't had any redirections so far but, Opera 10 reloads a page sometimes with my pressing F5 or reloading it. This may just be Opera 10 because I haven't seen it happen in Google Chrome.

    (No edit button?)
     
  3. VietSushi

    VietSushi Private E-2

    Attached is a HijackThis log. Please check.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome.

    Haven't found any what?

    In order for me to help you what I need from you are the following logs: (we didn't request a HJT log, this is not a HJT log reading forum)

    • SUPERantispyware
    • Malware-Bytes anti malware
    • ComboFix
    • MGlogs.zip

    Attach those 4 logs (which will take 2 posts to complete) and then I can get to work on assisting you.

    Thanks
    kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds