Need Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by phil3e, Oct 21, 2017.

  1. phil3e

    phil3e Private E-2

    Chrome started running slow did a reset it did not help. When I ran Malwarebytes it found something. Not sure if system is clean. I ran the scans and would appreciate it if somebody could help me with them. Win 7 -64, i7 860 cpu, 16gb ram, SSD
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re-run RogueKiller and click the Registry tab and locate these detections - select and delete them.
    Code:
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.134.188.115 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.134.188.115 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{02BCDCBA-7148-401A-9998-F0C464DBB438} | DhcpNameServer : 10.134.188.115 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{40E58F27-0F73-4556-9E6D-EA53D9575140} | DhcpNameServer : 10.134.188.115 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{9B49E5C0-9B70-4C32-BA74-8B90B0790F7D} | NameServer : 10.4.0.1 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{9B49E5C0-9B70-4C32-BA74-8B90B0790F7D} | DhcpNameServer : 10.4.0.1 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{02BCDCBA-7148-401A-9998-F0C464DBB438} | DhcpNameServer : 10.134.188.115 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{40E58F27-0F73-4556-9E6D-EA53D9575140} | DhcpNameServer : 10.134.188.115 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{9B49E5C0-9B70-4C32-BA74-8B90B0790F7D} | NameServer : 10.4.0.1 ([])  -> Found
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{9B49E5C0-9B70-4C32-BA74-8B90B0790F7D} | DhcpNameServer : 10.4.0.1 ([])  -> Found
    
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Upload it to your next message.

    Re-run AdwCleaner and choose to clean all detections.

    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.

    Now run both RogueKiller and AdwCleaner and upload those new logs too.

    *Tell me how your PC is running now.
     
  3. phil3e

    phil3e Private E-2

    Thanks for very fast response. I finished the removal and ran programs. Here are the new log files. Chrome and Opera seem to be running at full speed now. I had plugged in my Windows 10 drive and have been using it except, for running the cleaning. Not a big fan of 10 but it was free.
     

    Attached Files:

    Last edited: Oct 22, 2017
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome. Are you using a proxy?

    *Tell me how your pc is running....
     
  5. phil3e

    phil3e Private E-2

    Air VPN with Eddie but have not opened the program since this problem started. No proxy but I downloaded OSTOTO about 3 weeks ago I believe it caused some problems.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Aaah... was taking a precaution by digging abit..:)

    Ready for our final steps?
     
  7. phil3e

    phil3e Private E-2

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If you are running Win 7/8/10, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work through the below link:
    Safe surfing!
     
  9. phil3e

    phil3e Private E-2

    HijackThis is not in add remove or any where that I can find
     
  10. phil3e

    phil3e Private E-2

    I still have adwcleaner in my root C drive and desktop but no uninstall. ZHPCleaner appears to only be on the desktop ok to just delete them?
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    That's strange because there is a HJT Log embedded in the MGLog.zip file. I won't worry about it though.

    And - yes it's okay just to delete those executables.
     
  12. phil3e

    phil3e Private E-2

    all finished , thanks doc for all the help
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome! :cool:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds