[HELP] Stubborn Malware keeps producing

Haredasri

New Member
Thread author
Feb 17, 2018
8
Hi! I've been dealing this issue since 15th February 2018, where I noticed that my connection to the Internet via Edge browser could not execute well, but other installed browsers; Chrome and Internet Explorer could browse smoothly (up until yesterday 16th February which happened whenever I left my computer idle, the browsers would produced different problem relating to DNS. Thankfully I could fully browse the internet after each restarts)

This issue happened when I noticed I downloaded a virus file, which installed Mail.ru. I believe this is virus so I intended to uninstall everything and clean my registry via CCleaner. I thought I have cleaned it, but chrome still got traced of it staying in my computer. So I decided to install Kaspersky Total Security running the trial version to track down those viruses. It did tracked and deleted those files, but the problem remains unsolved. I, then, installed Malwarebytes, still to no avail. Then I install ADWcleaner and found some more traces. Tried to clean it, but the problem remains. I then downloaded RogueKiller, which by far, tracked most of those hidden malware, but the result is still the same. No positive result. Moving on, I installed Zemana Anit Malware, but the result is constant. I'm confused up until I saw my Windows Defender threat history. Apparently, it constantly updated me with a virus called Skeeyah.A!rfn, Tiggre!rfn, and DetraHere.B!rfn. It cleans the viruses, but the malware keeps on staying. I believe it has integrated itself into the windows process and would keep producing if deleted whenever I am connected to the internet.

As of 18th February, I tried to install Rkill > Malwarebytes scan > ADWCleaner > Hitman Pro. Restarted and problem remains.

I have also produced two support tickets at Microsoft.com and Tomshardware (attached links)

Edge and all other Microsoft Apps couldnt connect to the Internet Error Code: INET_E_RESOURCE_NOT_FOUND

[Help] Most Microsoft Applications Could Not Connect to Internet! - Windows 10

*When I have a looked at the FRST.txt, I was shocked beacause I didn't use TOSHIBA (I use Lenovo) and I never installed Firefox Browser.

I hope this information helps. Thanks in advance!
 

Attachments

  • FRST.txt
    63.8 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    2.5 KB · Views: 13

Haredasri

New Member
Thread author
Feb 17, 2018
8
Hello,

I had troubled downloading the fixlist at first since it requires permission but i managed at last to download it with a rename on it Fixlist (1).txt. Then I ran Notepad with Admin permission and renamed it without the "(1)". I ran Farbar and it gave me the usual three errors, which were as the attached images belows

vLH4NRR.jpg


FFW7OOv.jpg


1u7z0Rl.jpg


After I clicked Yes to all those three, I ran the fix and below is the file.
 

Attachments

  • Fixlog.txt
    3 KB · Views: 3

Haredasri

New Member
Thread author
Feb 17, 2018
8
Hello,

I had troubled downloading the fixlist at first since it requires permission but i managed at last to download it with a rename on it Fixlist (1).txt. Then I ran Notepad with Admin permission and renamed it without the "(1)". I ran Farbar and it gave me the usual three errors, which were as the attached images belows

vLH4NRR.jpg


FFW7OOv.jpg


1u7z0Rl.jpg


After I clicked Yes to all those three, I ran the fix and below is the file.


*Update: I've resolved the three errors by moving the FRST64.exe to my desktop and rerun the fixlist. The fixlist remains the same as the one I uploaded
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

Haredasri

New Member
Thread author
Feb 17, 2018
8
After updating the FRST64.exe and moved the application [After no errors re-run]

*This is a shared and a second-hand laptop. In anyways of piracy detected, I'm unaware of it as most of the applications running under my control is currently on-trial.
 

Attachments

  • FRST.txt
    63.3 KB · Views: 1
  • Addition.txt
    45 KB · Views: 1

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
We need to kill this one from recovery:


Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.
  • Now you should get a window like this where you need to click Troubleshoot.
Windows-10-2.jpg

  • In the next window, click Advanced options and select Command Prompt.
  • Now you should log in into your account and after that Command Promptwindow.
notepad.png
Access the notepad and identify your USB drive

In the Command Prompt please type in:
Code:
notepad
and press Enter.
  • When the notepad opens, go to File menu.
  • Select Open.
  • Go to Computer and search there for your USB drive letter.
  • Note down the letter and close the notepad.


FRST.gif
Scan with Farbar Recovery Scan Tool

Once back in the command prompt window, please do the following:
  • Type in e:\frst64.exe and press Enter.
    You need to replace e with the letter of your USB drive taken from notepad!
  • FRST will start to run. Give him a minute or so to load itself.
  • Click Yes to Disclaimer.
  • In the main console, please click Scan and wait.
  • When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile.

Transfer it to your clean machine and include it in your next reply.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Download attached fixlist.txt and save it to your USB flashdrive as fixlist.txt

>> Boot into Recovery Environment


Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
  • Press the Fix button once and wait.
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your USB flashdrive.


>> Exit out of Recovery Environment and post me the log please.



Try to boot Windows normally...
 

Attachments

  • fixlist.txt
    2 KB · Views: 2

Haredasri

New Member
Thread author
Feb 17, 2018
8
Hi sorry for the late reply. The malware seems to be removed completely. But Edge and other Microsoft Applications continue to not making any connection to the internet. Luckily, the Windows Update could function backs to normal (before this, the update couldn't even install)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top