Suspicion Of Malware Or Some Short Of Hijacking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sakoul, Jul 1, 2016.

  1. sakoul

    sakoul Private E-2

    Hi guys,
    Long story short.
    Most of the times i use an old Opera version as my internet browser on my laptop pc.
    Over the last year i have found my bank account hijacked etc.
    Lately i found some problems with online shopping and on top of that my Hotmail account seems to been spoofed.
    So i am suspecting that my laptop pc has been hijacked or has some malware in it.
    Can you please help me clean it or check to see if something bad is in it?
    My laptop pc runs on Windows Vista and i have installed Panda Cloud Cleaner and Malwarebytes Anti-Malware software in.
    Thank you

    SAKOUL
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. sakoul

    sakoul Private E-2

    Kestrel13,
    I completed the 5 scans asked.
    The TDSS Killer did not give me any threats so i am not uploading any relevant file.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.

    Re run Hitman Pro, enable/activate the free trial, and have it remove what it finds.

    C:\Users\MAKIS\AppData\Roaming\Ifzyo <<< What is this?

    Now that you are in normal startup again do this: Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Also do this:

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  5. sakoul

    sakoul Private E-2

    In your last respond you wrote:

    C:\Users\MAKIS\AppData\Roaming\Ifzyo <<< What is this?


    My answer is I HONESTLY DON'T KNOW :)

    Also,

    the HitmanPro file, the MGlog file and the Farbar files are attached

    Thanks for your help
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, forgive the delayed response. I am reviewing those logs right now. :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Users\MAKIS\AppData\Roaming\Ifzyo << Without clicking on anything, can you let me know what's inside this folder?

    Do you know what this is?
    C:\Users\MAKIS\AppData\Local\slagder.dll
     
  8. sakoul

    sakoul Private E-2

    The lfzyo folder looks empty. Should i delete it? If yes, how?

    The slagder thing don't know what it is. However, since my computer starts up in normal mode i get a window that says:
    Erro Loading C:\Users\MAKIS\AppData\Local\slagder.dll
    The specified module could not be found.

    What should i do?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's malware.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.

    • You should now have both fixlist.txt and FRST.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • Fixlog.txt

    Now do this:
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know how things are running!
     

    Attached Files:

  10. sakoul

    sakoul Private E-2

    I did what you said.
    Here are the files asked
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running? Please note, using an outdated browser is going to leve you more vulnerable to threats.
     
  12. sakoul

    sakoul Private E-2

    PC seems to work fine.
    However, after start up i keep having the sladger.dll window opening...

    On top of that, there are many processes running (since i am in normal start up mode) which is something annoying since i have to close almost all of them.
    Is there a way to prevent them from loading with start up (except for changing the start up mode that you mentioned is not good)???
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm... then there is still work to do. With having everything running at start up, you should be using a third party software to control them. Check out our downloads :

    http://www.majorgeeks.com/mg/sortname/processmanagement.html

    Do this now...

    SystemLook

    Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
    Download 32 Bit
    Download 64 Bit

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      slagder.dll
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  14. sakoul

    sakoul Private E-2

    There is a whole bunch of software in the link you provided....
    Which one should i install?
    The SystemLook file was uploaded as you asked
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can use the software I am about to have you download. Handy link to understanding how it works here. http://lifehacker.com/5425289/five-best-startup-management-tools
    In the meantime, do this:

    I'd like you to download Autoruns, save it to your desktop.

    Run Autoruns ( you will have to extract the contents from the ZIP file into its a new folder you create for it ( like AutoRuns on your Desktop ) and keep the Everything tab selected in AutoRuns. Then click on the File menu selection and select Save. Save this log file in default format to your Desktop. The default format and filename should be AutoRuns.arn

    Now put the AutoRuns.arn file into a ZIP file and upload this ZIP to your next message. ( you cannot upload the AutoRuns.arn file. It must be ZIP'ed/compressed ).
     
  16. sakoul

    sakoul Private E-2

    Here is the ziped file. I have it in .rar format.
    So what should i do with the start up programs?
    Which software should i download/use?
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you just right click and "send to compressed file" to zip the file up?
     
  18. sakoul

    sakoul Private E-2

    Yes
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK run Autoruns > ensure the 'everything' tab is selected. Scroll down until you see the entry we have been hunting for: (see screenshot I uploaded, untitled.jpg))
    Right click it > and delete it. Reboot the machine, does the message still appear?
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Users\MAKIS\AppData\Local\slagder.dll
     
  21. sakoul

    sakoul Private E-2

    It seems that sladger doesn't load. Thats good :)
    What should i do with the rest start up programs (skype etc).
    Do you suggest to stop some of them from running on start up?
    If yes, which ones?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh that's brilliant! Glad to hear it. Well with your other start up items, that you want to control, you can simply use Autoruns! :) I used it just yesterday to stop Ccleaner from running at start up, and it's done it's job.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  23. sakoul

    sakoul Private E-2

    I think step 7 you are mentioning is for protecting my PC on a permanent basis.
    However, there are so many software suggested for Malware, Virus protection etc.
    I am bit confused on which to install and run.
    Do you suggest any specific ones?
    Malwarebytes and CCleaner seem good. Any AVirus suggested? Is firewall necessary? Any other thing to add?
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can post about this in the software forum. :)
     
  25. sakoul

    sakoul Private E-2

    Kestrel13! thanks for your help...I am done with my new laptop...:)

    However today i tried to run the RED AND RUN ME FIRST MALWARE REMOVAL GUIDE for my old laptop.
    The CCleaner run was smooth.
    HOWEVER when i tried to run the Malware bytes software i got the message :

    mbam.exe Application Error
    The application failed to initialize properly(0xc000001d). Click on OK to terminate the application.

    I suspect that my laptop has a malware that does not let it run the Antimalware software...
    Can you please help me again?
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sure we can help. :) You must create a new thread though as it will get too confusing to have it posted here.
     
  27. sakoul

    sakoul Private E-2

    I set up a new thread as you said.
     
    Kestrel13! likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds