Dnsunlocker "virus"

Discussion in 'Malware Help (A Specialist Will Reply)' started by Burrell, Mar 6, 2016.

  1. Burrell

    Burrell MajorGeek

    Hey,

    For the last 4-5 days I've been having redirection issues and advert pop-ups in my browsers. I ran MBAM and SuperAntiSpyware and removed 700 ish tracking cookies which raised my suspicion, since then I done some googling and believe I have a virus of some kind.

    The other computers on my network also seem to have this same issues, although I'm not sure about this yet.

    I have gone through the read me and my logs are attached, hopefully you guys can help me get back to normal :)
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I cannot open that! You need to upload logs individually! Thanks :)
     
  3. Burrell

    Burrell MajorGeek

    Woops!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Got the MGlogs.zip, too?
     
  5. Burrell

    Burrell MajorGeek

    Sorry
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries, I have to pop out for a moment. When I come back, I'll review all the logs. ;)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and let it remove all that it finds except for:

    PunkBuster items.

    Your MGlogs.zip is very incomplete... run it again ensuring that protection software is disabled, that UAC is turned off, and that you are indeed running it as admin.

    Explain which browsers are affected.
     
  8. Burrell

    Burrell MajorGeek

    Ah, I think may have stopped it prematurely.

    I ran hitman and deleted everything apart from PB like you said. Chrome is the only browser I use 99% of the time, it doesn't seem to be re-directing any more like it used to.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you saying that Google Chrome was the only browser you were experiencing redirects in?
    And am I correct in assuming after running Hitman, everything is okay now?
     
  10. Burrell

    Burrell MajorGeek

    Yes, both correct.

    Am I all good now? :)
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Few bits left to take out.... and I'd like to dig a bit deeper still to cover all angles...


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Users\chris\AppData\Local\Zaamzim.dat
    C:\Users\chris\AppData\Local\Zaamzim.exe.config
    C:\Users\chris\AppData\Local???????????????????
    C:\ProgramData\35400069-00a7-0
    C:\ProgramData\35400069-0521-1
    C:\ProgramData\35400069-26a7-0
    C:\ProgramData\35400069-2fc3-0
    C:\ProgramData\35400069-4aa1-0
    C:\ProgramData\519cd056-2437-1
    C:\ProgramData\519cd056-4065-0
    C:\ProgramData\{02b3ad4e-312c-1}
    C:\ProgramData\{1d85bdfd-112c-0}
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.



    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds