So my computer at startup has 2 programs that I have to close down in windows manager that are ¨system functions¨but take up 500,000k to 1,000,000k in my ram space randomly since this malware from i think trotux has been on my computer from a program I accidentally installed.
I it also installed it´s own search bar and was opening to it´s own homepage in all my browsers. As soon as i installed malwarebytes it stopped that, but I still get adds that the malwarebytes pro is blocking.
Sometimes I am also getting DNS error on this computer only in the network when the other ones are working fine. I got all the logs and am going to post them below like it says to in that main post they directed me to. Thanks for your help I really appreciate it If there is anything I can do to help back please let me know. Thanks again.
Malwarebytes Anti-Malware
www.malwarebytes.orgScan Date: 20/07/2016
Scan Time: 16:52
Logfile: 20-07-16.txt
Administrator: Yes
Version: 0.0.0.0000
Malware Database: v2016.07.20.03
Rootkit Database: v2016.05.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Michael
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 333939
Time Elapsed: 13 min, 21 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
Results of screen317's Security Check version 1.014 --- 12/23/15
x64
(UAC is disabled!) ``````````````Antivirus/Firewall Check:``````````````[/u]
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````[/u]
AVG Web TuneUp
Java 8 Update 45
Java version 32-bit out of Date! Adobe Flash Player 22.0.0.209
Mozilla Firefox (47.0.1)
Google Chrome (51.0.2704.106)
Google Chrome (SetupMetrics.pma..)
````````Process Check: objlist.exe by Laurent````````[/u]
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````[/u]
# AdwCleaner v5.201 - Relatório criado 20/07/2016 às 17:59:44
# Atualizado 30/06/2016 por ToolsLib
# Banco de dados : 2016-07-19.2 [Servidor]
# Sistema operacional : Windows 7 Professional Service Pack 1 (X64)
# Usuário : Michael - MICHAEL-PC
# Executando de : C:\Users\Michael\Downloads\adwcleaner_5.201 (2).exe
# Opção : Limpar
# Apoio :
https://toolslib.net/forum***** [ Serviços ] *****
[-] Serviço Excluído : WtuSystemSupport
[-] Serviço Excluído : vToolbarUpdater40.3.1
***** [ Pastas ] *****
[-] Pasta Excluído : C:\ProgramData\apn
[-] Pasta Excluído : C:\ProgramData\avg web tuneup
- Pasta Excluído : C:\ProgramData\Application Data\apn
- Pasta Excluído : C:\ProgramData\Application Data\avg web tuneup
[-] Pasta Excluído : C:\Program Files (x86)\WinZipper
[-] Pasta Excluído : C:\Program Files (x86)\avg web tuneup
[-] Pasta Excluído : C:\Program Files (x86)\TXQQBrowser
[-] Pasta Excluído : C:\Program Files (x86)\Common Files\AVG Secure Search
[-] Pasta Excluído : C:\Users\Michael\AppData\Local\avg web tuneup
[-] Pasta Excluído : C:\Users\Michael\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
[-] Pasta Excluído : C:\Users\Michael\AppData\Roaming\eCyber
[-] Pasta Excluído : C:\Users\Michael\AppData\Roaming\TSv
[-] Pasta Excluído : C:\Users\Michael\AppData\Roaming\WinZiper
[-] Pasta Excluído : C:\Program Files\Common Files\AVG Secure Search
[-] Pasta Excluído : C:\Users\Michael\AppData\Roaming\Profiles\yzzfdyu4.default
***** [ Arquivos ] *****
[-] Arquivo Excluído : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\caq6ts9r.default\extensions\[email protected]
[-] Arquivo Excluído : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\caq6ts9r.default\searchplugins\avg-secure-search.xml
[-] Arquivo Excluído : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_land.pckeeper.software_0.localstorage-journal
[-] Arquivo Excluído : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.newtabtvplussearch.com_0.localstorage-journal
[-] Arquivo Excluído : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.searchinsocial.com_0.localstorage-journal
[-] Arquivo Excluído : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] Arquivo Excluído : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
[-] Arquivo Excluído : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.plyrics.com_0.localstorage-journal
***** [ DLLs ] *****
***** [ WMI ] *****
***** [ Atalhos ] *****
[-] Atalho Desinfectado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Atalho Desinfectado : C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[-] Atalho Desinfectado : C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Atalho Desinfectado : C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[-] Atalho Desinfectado : C:\Users\Michael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Atalho Desinfectado : C:\Users\Michael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Tarefas agendadas ] *****
[-] Tarefa Excluída : Browser Updater Task(Core)
***** [ Registro ] *****
[-] Chave Excluída : HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
[-] Chave Excluída : HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
[-] Chave Excluída : HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
[-] Chave Excluída : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] Chave Excluída : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaaiabcopkplhgaedhbloeejhhankf
[-] Chave Excluída : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.001
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.7z
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.arj
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.bz2
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.bzip2
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.cab
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.cpio
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.deb
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.dmg
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.fat
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.gz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.gzip
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.hfs
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.iso
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.lha
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.lzh
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.lzma
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.ntfs
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.rar
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.rpm
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.squashfs
- Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.swm
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.tar
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.taz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.tbz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.tbz2
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.tgz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.tpz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.txz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.vhd
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.wim
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.xar
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.xz
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.z
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WinZippers.zip
[-] Chave Excluída : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
[-] Chave Excluída : HKCU\Software\Google\Chrome\Extensions\chfdnecihphmhljaaejmgoiahnihplgn
[-] Chave Excluída : HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
[-] Chave Excluída : HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
[-] Chave Excluída : HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
[-] Chave Excluída : HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
[-] Chave Excluída : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[-] Chave Excluída : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
[-] Chave Excluída : HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
[-] Chave Excluída : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
[-] Chave Excluída : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Chave Excluída : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Chave Excluída : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Chave Excluída : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Chave Excluída : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Chave Excluída : HKLM\SOFTWARE\hdcode
[-] Chave Excluída : HKLM\SOFTWARE\AVG Tuneup
[-] Chave Excluída : HKLM\SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
[-] Chave Excluída : HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[-] Chave Excluída : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SrpnFiles
[-] Chave Excluída :
[x64] HKLM\SOFTWARE\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[-] Chave Excluída : HKU\.DEFAULT\Software\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
[-] Chave Excluída : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4ba46856BF57969F6A36
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89BB7852687BDC34B9A81E01C7FF9173
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56c49B56F6B83E293C15
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A97C590397DCC454AA8923563BAB10E4
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B08932C78B697C244BE7BA3E6FF09B62
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927c4E9B7BC1D3FD1E49F
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327dc64C9A8B641A9E89646
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81fa428925F22ACB3A965
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09f45BAFAAE1D7546ED4
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050b2e46B9C4B67A8F59577
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606d43BB064BD63CBD87E
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3255D95681398614190EDF0A4F3F77DB
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28c944FBC7579CF4949414
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3dc1468548785DC856EDA
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8d249B526503432F99D4
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[-] Chave Excluída : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Chave Excluída : [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\pcspeedup
[-] Valor Excluída : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
[-] Chave Excluída : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\winzipersvc
[-] Chave Excluída : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\qkseeService
***** [ Navegadores ] *****
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Excluído : br.ask.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Excluído : aol.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Excluído : bopakagnckmlgajfccecajhnimjiiedh
*************************
:: Chaves "Tracing" excluídas
:: Configurações Winsock restauradas
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [13081 bytes] - [20/07/2016 17:59:44]
C:\AdwCleaner\AdwCleaner[S1].txt - [13816 bytes] - [20/07/2016 17:24:13]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [13229 bytes] ##########