Solved DHCPNameServer malware that keeps reappearing.

Cigam

New Member
Thread author
Mar 18, 2016
3
I have been working on a friend of mines computer, at my house instead of hers. I had done all of the virus/malware removal with no network connected in safe mode and normal mode. When I connect the desktop to a network it is from me doing an adhoc share from my linux laptop.

As soon as I saw it had malware in the DNS from roguekiller I would disconnect it from network, and then let roguekiller remove the dns. I cannot find any other malware in the system. Only when I have it connected to a network does roguekiller detect anything. I am at a loss of what to try next.

I am pretty sure she got hijcaked from someone pretending to be from rwglobal, and I found the mcafee installer from february 16, since I had previously installed avast and zemana anti-logger on her system, and now those are removed.

I have removed all malicious and unknown drivers, startups, services, etc and every malware I can find, but it still recreates the DNS hijack on the system. Currently AdwCleaner, and all the other malware scanners show the system as clean. Only rogue killer will detect the DNS changes.

Any thoughts?
 

Attachments

  • FRST.txt
    61.9 KB · Views: 5
  • Addition.txt
    36.5 KB · Views: 2

Cigam

New Member
Thread author
Mar 18, 2016
3
I ran malwarebytes and had it remove some non malware pups but here is the most recent roguekiller scan I did, and looking at it now, it looks like it might just be my adhoc connection from my linux machine. since it shows the 10.42.0.1 because if I remember correctly thats how linux does the numbering when doing an adhoc. what do you think?
 

Attachments

  • roguekiller20160323.txt
    6.7 KB · Views: 5

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top