Isp Keeps Closing Connection Because Of A Virus, I Find No Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by m4s4, Sep 17, 2016.

  1. m4s4

    m4s4 Private E-2

    About a week ago my ISP cut my internet, because they see a virus or something. I called them and they opened it back up after I had ran their antivirus scan and found nothing. But now 2 days ago this happened again. I asked for details and they say it was a PSN account stealing attempt, even tho no one has been using our playstiation in the last month at least. It had happened 3 times in 5 days, everytime it was close to noon. The only device that has been used in our wifi is my PC. I've ran all the scans that were adviced in the read and run me first thread, and here are the logs
    The tdsskiller and mbam logs don't want to be attached so I'll try to attach them in a reply
     

    Attached Files:

  2. m4s4

    m4s4 Private E-2

    Nope, it still just says "The file is empty" even tho it clearly has stuff when I try to edit it. What should I do?
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, m4s4

    Are you following the steps given for running the tools exactly? Why are you trying to edit the logs?
     
  4. m4s4

    m4s4 Private E-2

    Hello dr.moriarty
    Thanks for a quick reply, yes I did follow all the steps exactly. I pressed "edit" on the log txt to see if it actually contained something and did see a lot of text, didn't actually edit anything. But malwarebytes has got an update since when that guide was written and some buttons are labeled different. But I'm pretty sure I got it right.
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hmmm... haven't dealt with such problems. If the logs were created and "Saved", navigate to them and compress them into a zip file and upload... I'll go from there with them. *Just make sure that they are .txt format before zipping.
     
  6. m4s4

    m4s4 Private E-2

    Yes, I will do that. But the hitman log is not in txt format, and I did as adviced in that thread, is that okay?
    Thanks for your quick help!
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome. Stand by while I quickly run Hitman myself to see what I can find out....
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hitman Pro 3.7.14 Build 276

    Next to the Buy Now radio button > in blue Save Log > choose "save directory" - file type = "Save as type - Text Log files(*.log)". What happens then?
     
  9. m4s4

    m4s4 Private E-2

    It was saved as a .log file, I saved it and attached it. So is it good?
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes - all logs are okay. Give me time to review them and I'll post a fix afterwards.
     
  11. m4s4

    m4s4 Private E-2

    Thanks a lot.
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome. Have you knowingly setup a proxy?
     
  13. m4s4

    m4s4 Private E-2

    I don't think so...
    I had softether vpn, deleted it before this all started and I have tor browser installed. But no other proxying stuff as I am aware, nothing that should be running now. My connection with my ISP is a 4g dongle with an assigned dynamic ip so I can open ports on it, that makes some things weird.
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Ok, please run this tool.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.

    EDIT: And you're aware of Tftpd32 and LOIC.exe which Hitman Pro doesn't like?
     
  15. m4s4

    m4s4 Private E-2

    Okay, I ran it. Here's the logs
     

    Attached Files:

  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Did you see my EDIT to previous reply?
     
  17. m4s4

    m4s4 Private E-2

    Emm yes I am aware of LOIC, but whats Tftpd32?
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  19. m4s4

    m4s4 Private E-2

    Yea, now I remember, I downloaded that.
     
  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Let's start with this -

    NOTES: I would not allow uTorrent.exe to auto-run at startup --- very risky as it opens your PC up to the world. *You're getting very close to only having 15% free space remaining on both your OS and Data drives.

    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Users\Matti\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Please disconnect your internet before performing this fix!

    Re-run Hitman Pro, activate/enable the free trial and allow it to remove:
    Malware => dllhost.exe.exe
    Potential Unwanted Programs​
    After reboot and when you are back in Windows, rescan with HitmanPro and upload the new log.

    Now, re-run RogueKiller.exe. (Vista/Windows7/8/10 users should right-click and select "Run as Administrator")
    After it finishes the scan, select the following tabs and then select any of the below that exist and then click the Remove Selected button.
    ¤¤¤ Registry ¤¤¤ <== all PUPs
    ¤¤¤ Files ¤¤¤
    Then immediately reboot your PC.

    Now run a new scan with RogueKiller and save a log as in the original instructions and upload that new log.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, please upload it here in your next reply.
     

    Attached Files:

  21. m4s4

    m4s4 Private E-2

    I finally got it all done, I'm sorry for taking so long. Anyway, here are the logs.
    In rogue killer I didn't find any "tabs" in the scan results, but I removed all things that had the folder icon next to them (there was 1) and all PUPs (but not PUMs) that had the regedit icon next to them. Also, I seem to have lost all my cookies, but that's not a big problem though.
    Also, just as I got this written, I saw a windows command prompt quickly flash on the screen, so some program I haven't noticed before just ran.
    And another edit, I cleaned my desktop, but I kept the 2 desktop.ini files that seem to be hidden. What should I do with them?
     

    Attached Files:

  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The two desktop.ini files are normally hidden files, so leave them.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Upload JRT.txt to your next message.
    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Upload this log to your next reply.
    How is your machine running now?
     
  23. m4s4

    m4s4 Private E-2

    So here's the logs again.
    My machine seems to be running all good, like it has always done. The problem here is that my ISP keeps shutting down my connection because of malicious activity caused by a virus.
    Thanks yet once again for all this help.
     

    Attached Files:

  24. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Using AdwCleaner.exe previously downloaded:
    • Double click on AdwCleaner.exe to run the tool. (Vista, Win7/8/10 users should right-click and "Run As Administrator")
    • Click on the Scan button.
    • When the scan has completed, click on the Clean button.
    • Press OK when asked to close all programs and follow the on-screen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Upload this log to your next reply.
    We're down to performing minor cleanup, now. But if you wish, you could run this online scanner. {The scan takes 2 hr +- so be patient}
    eSet Online Scan
     
  25. m4s4

    m4s4 Private E-2

    Okay, here is the AdwCleaner log.
    This time booting up, I got this new error message, but nothing bad seems to have happened.
    I am going to sleep soon and will leave the online scanner running through the night.
    Thanks.
     

    Attached Files:

  26. m4s4

    m4s4 Private E-2

    It does seem like those instructions are a bit outdated, the program looks way different nowadays. Also the link, where it says "Please go here" in the very beginning, no longer works. It tries to go to eset.com/int/home//products/online-scanner/ which gives a 404, but I tried eset.com/int/home/products/online-scanner/ and it seems to work? I'll try to follow these instructions as good as I can and post the log.
     
  27. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your error.png comes back as related to Razer Synapse
     
  28. m4s4

    m4s4 Private E-2

    Oh, then its nothing to worry about. That thing likes crashing after updates.
    Thanks again.
     
  29. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Just go here ==> https://www.eset.com/us/online-scanner/ and click on the SCAN NOW radio button > save the esetonlinescanner_enu.exe Binary file to your Desktop > then right-click and choose "Run as Administrator".
     
  30. m4s4

    m4s4 Private E-2

    So the eset online scan v2 thing crashed on me twice after 4 hours of working, so I found myself the scanner version 1 and ran it. It took almost 7 hours, and found infected files and cleaned some. Where can I find the log? I got a list of threats, is that enough?
     

    Attached Files:

  31. m4s4

    m4s4 Private E-2

    What should I do with the detected files? Should I delete everything in quarantine or do I have to do something else?
     
  32. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, delete everything in quarantine. Although they are prevented from causing any more trouble now, there's no reason for them to remain. The scanner log should reinforce to you what programs and applications that you don't need to have on your system, right? Especially the hacks, cracks, and infected torrents...

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  33. m4s4

    m4s4 Private E-2

    Okay, I believe this has fixed my issue. I just got my internet back once again, and if the problem isn't gone and this happens again in the next month, I can just post here again, right?
    The help has been awesome, is there another way to support you people, other than the t shirt shop which seems to be down for maintenance?
     
  34. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds