WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


[INACTIVE] NetUtils2016: PC badly affected after installing program

2 posters

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
There are many program entries in the logs for your computer for WildTangent games... Do you want to keep those? I ask, because they are showing a “hidden” flag next to them, which is suspicious activity unless you installed them yourself.

I also have noticed the use of P2P and cracks/keygens in your logs. This is highly unsafe, and the source of infection, including, as of recent, the prevalence of ransomware. Ransomware is a highly dangerous infection, which locks down your files/folders/PC requiring you to pay the hacker in order to restore access to your system. In addition, antivirus and anti-malware software cannot always “catch” an infection to block it... Therefore, I recommend the removal of uTorrent and any other programs related to torrenting. You'll be glad you did...! Smile...

Oh and did you upgrade from Windows XP to Windows 10?

Fix with Farbar Recovery Scan Tool
Notice to outside readers: This fix was created for this user for use on that particular machine.Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work! Therefore, if you placed FRST.exe in your “Geek Police” folder, then make sure fixlist.txt goes in the same location as FRST.exe.


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart of your computer, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
Thank you for your advice and instructions. I will make those changes regarding utorrent.
I bought the pc with Windows 10 preinstalled.
I didn't install Wild Tangent Games or had any idea that it was installed on my pc. How do i remove that ?
I have carried out your instructions regarding Farbar recovery scan tool and I have attached the Fixlog.txt.
I await your comments
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Very well... Now for the WildTangent Games, go to Start > type in appwiz.cpl and hit enter or choose the result from the search list. Then, in that list, look for the following entry: WildTangent Games. Please uninstall that, and it should remove all of the games along with it.

Then, please do the following:
Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




Malwarebytes' scanner
If this program is already installed: Skip the installation and run only the scan!
Download and install: Please download Malwarebytes' scanner to your desktop.

  • Double-click mb3-setup-consumer-3.x.x.xxxx and follow the prompts to install the program.
  • Click Finish.
  • On the Dashboard, click the 'Check for Updates' button.
  • After the update completes, then, on the Dashboard, select Settings.
  • Click on Protection.
  • Ensure that Scan for rootkits is checked. If not, check it.
  • Return to the Dashboard and click the 'Scan Now' button.
  • A Threat Scan will begin. Please allow it to progress through the scanning process.
  • When the scan is complete, if there have been detections, click Quarantines Selected button to allow the program to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

How to get logs: (Export log to save as txt)

  • After the restart once you are back at your desktop, open Malwarebytes once more.
  • Click on the Reports tab > Scan Report. (if you have done more than one scan in the past, select the most recent that shows the Date and time of the scan just performed. Press View Report button.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Find the log on your Desktop and Attach that saved log to your next reply.

(Copy to clipboard for pasting into forum replies or tickets)




Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 TDSSKillernumber1


  • If an infected file is detected, the default action will be Cure, click on Continue.

    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 TDSSKillernumber2

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 TDSSKillernumber3


  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 TDSSKillerlastone3


  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents the report here.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have deleted all Wild Tangent games as per your instructions.
I have run Farbar Recovery Scan Tool again and attached logs.
I ran Malwarebytes once more and again it stuck on Heuristics Analysis with no sign of activity,so i closed it again. I have attached a screen capture of the 9 threats identified that couldn't be removed due to the scan sticking.The screen capture will be in a separate message that will follow this one.
I ran TDSSKiller.exe and it found no problems. The log is attached.
I await your comments.
Thank you again

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have been unable to post the screen capture due to size restrictions. The 9 threats found are all PUP files,process modules and registry keys.  Is there another program like Malwarebytes i could use instead?
thanks.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Okay, let's see what we can do here... This will be a bit rigorous...

Please download the latest version of Hitman Pro

  • After the download completes please double click the program to run it.
  • Accept the terms of the license agreement and click Next
  • Let the scan run. It will not take long
  • When the scan finishes, and all the files have been uploaded to the Scan Cloud, click Next
  • Click Next again. At the bottom left you will see Export Scan Results To XML File. Click that and save it in a convenient location
  • Upload log.xml here for review please


Sophos Virus Removal Tool
Download Sophos Free Virus Removal Tool and save it to your desktop.

  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program


Scan with herdProtect

Please download herdProtect by Reason Software (portable edition) and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on the HerdProtect icon and select Run as Administrator to install the scanner.
  • It will ask for the location - leave the default one (%ProgramFiles%) or select another, convenient one.
  • Agree to the terms, select Launch herdProtect and click Finish.
  • Click Scan. It may take a while, depending on your system and connection specs. Please be patient.
  • When it finishes click on Save Results.
  • A Notepad with a report should open.

Please include the contents of that report in your next reply.
This type of scan often produces false positives. In any case do not remove on your own any of its findings! Removal will be made after the careful analysis of the scan results.
Upon completion of the cleaning you may remove HerdProtect if you wish so. To do it just delete its directory (chosen by you when installing the tool).

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,

Should I remove malicious software that Hitman Pro has discovered?  The scan has completed and is asking me to activate their product which i can do with a 30 day free  license.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Yes, go ahead with that. However, only herdProtect you should not remove anything right now, please. Smile...

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi.
 I have run Hit man Pro. The log is attached. 
 I have run Sophos Virus removal Tool. The Scan found 1 threat which i removed. It showed an error message when i clicked Details,then View Log File.I Could not retrieve a log.
 I have run herdProtect as requested and have left the scan open on the desktop after completion. The log is attached. I have not attempted anything further with herdProtect. I have split this log into 5 individuals files due to the size of the initial log. I will send part 5 separately.
 I await your response.
  thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please find attached part 5

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks for letting me know the progress, the system is still heavily infected...

Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.Running it on another one may cause damage and render the system unstable.

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart of your computer, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.




RogueKiller Scan


  • Download RogueKiller from the following link and save it on your desktop:
    TechSpot
    Official Site (alternative)
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan

[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 RGKRScan


  • Wait for the end of the scan.
  • The report has been created on the desktop.
  • Click on the Delete button.

[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 RGKRDelete


  • The report has been created on the desktop.


  • Next click on the ShortcutsFix

    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 RGKRShortcutsFix
  • The report has been created on the desktop.

Please post:

All RKreport.txt text files located on your desktop.




CKScanner

Please download CKScanner by askey127 from here
Save it to your desktop.

  • Doubleclick CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify that the file is saved.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
I have followed your instructions regarding the Farbar Recovery Scan Tool. The Fixlog.txt is attached to this message.
I have run RogueKiller and after the completion  I opened the report and copied it to the desktop. I have attached same here.
The version of RogueKiller I used was 12.9.7.0 and the layout is different to the one you supplied. It is still open on my desktop. Should i check each item before i select the 'Remove Selected' button.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Yes, please do remove those items.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I will send you the CKFiles log shortly when it completes
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Okay. I'll be online for quite a while longer. Smile...

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have tried to send the CKFile log as a txt and it will not accept it as a 267kb single text document and it won't accept 3 individual smaller text documents.
 It shows 'Could not upload file : exceeded user allowed storage. (Free space : 0) .
Do you have a solution?
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please upload it to www.mediafire.com and post the download link here. Smile...

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks,
Here is the link - http://www.mediafire.com/file/rds7uzt1wv9lcs7/ckfiles.zip

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
You're welcome and thanks for the upload. I got the info just fine. Smile...

To free up space on your attachments account here on the forums, press the Profile button in the navigation bar near the top of the page: [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 Profil12, then hit the Attachments tab.

You should see a page like this: [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 Attach10

You are free to checkmark and delete any of your attachments in there, as they have already been reviewed by me or the staff, so they are no longer necessary. If you would rather not do this, then feel free to continue to use a free file upload site.




As far as the deletions go, any kind of potentially illegal software and other possibly infected resources will be deleted.

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.




After that, please run CKScanner again and post a new log, as well as the following please (don't worry we'll delete all these tools afterward) - Re-run Junkware Removal Tool and AdwCleaner and post fresh logs from those tools! Right On!

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Thanks for the advice on removing previous messages. 

I have carried out fresh scans using  Farbar Recovery Scan Tool and I have attached the fixlog.

I have run CKScanner again and the log is attached.

I have run Junkware Removal Tool and that log is attached.

Finally,I have just run Adw Cleaner and that log is attached. 

I look forward to your reply.

 thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Looks like we're wrapping things up...  Awesome (sparkly)

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.




Remove the Adware

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner_xxxx.exe to run the tool.
  • Press Scan, wait for it to finish.
  • Ensure to only check the following items (uncheck all others):
    Chrome pref Found:  [C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Web data] - uk.ask.com
    Chrome pref Found:  [C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - hxxp://uk.search.yahoo.com?type=512435&fr=spigot-yhp-ch.
  • Then hit the Clean button.
  • Your computer will be rebooted automatically. If it does not, please reboot the computer manually.
  • Re-run AdwCleaner as before and post a new log please.





Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

  • Once it is restarted and you're back in Windows, double-click adwcleaner_xxxx.exe, hit "Logfile." On the Cleaning tab, double-click the latest logfile, copy the contents, and paste it into your next reply.
  • You can find the logfile at C:\AdwCleaner[Sx].txt as well.





In your next reply, please include these logs:


  1. Fixlog.txt from FRST
  2. Fresh AdwCleaner log
  3. Fresh FRST scan log
  4. Also, let me know how your device is doing. Thanks for your patience also, this has been a challenge worth my youth!


Last edited by Dr Jay on 11th February 2017, 10:02 pm; edited 1 time in total

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
 I cannot see any attachment for fixlog.txt with your last message, or am i to use a previous one?
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Sorry, I just fixed the download hub system, as we added new functions to the forums...

This should work or click on the attachment above I just created: http://www.geekpolice.net/download.forum?id=533

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello Again,
I have carried out the FRST scan and I have attached the Fixlog.txt

I have also run adwcleaner,scanned the pc and followed your instructions relating to only checking those 2 items. My problem was that i could not see those two items in the scan. The scan found 5 items, as below.
Under Services it found NetUtils2016.
 Files It found C:\WINDOWS\SysNative\NetUtils2016.dll
 Files it found C:\WINDOWS\SysNative\drivers\NetUtils2016.sys
 Registry it found HKLM64\SOFTWARE\HDWallpaper
 Chrome it found C;\Users\paull\AppData\Local\Google\Chrome\User Data\Default
I made the assumption that the last item was the one you referred to and have checked it  and  hit the clean button.
I have attached the adwcleaner log also.

I have re-run FRST again and have attached the log as well

I have found my pc to be still having problems with Google Chrome,it freezes which causes me to use Task Manager to close it, and i am finding Chrome not opening after clicking on the desktop icon.

I have installed Opera which appears to be running better.

With reference to NetUtils, it seems to be the cause of problems using Chrome as i am finding it opening pages as well as getting 'reimage plus' opening regularly.

I have found Avast notifying me of potential malware that they have stopped when i have been carrying out adwclweaner scans too.

I hope i make sense with all this info.

I look forward to your reply
Thank you so much.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please download and run the Google Chrome Software Cleaner.



CCleaner Temporary Files Cleaning

NOTE: If you already have this installed, you don't have to reinstall it.

Please download CCleaner

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.


  • Double-click the CCleaner shortcut on the desktop to start the program.
  • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
  • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
  • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).


Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

SystemLook
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:


    :filefind
    *netutils*


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have run CC Cleaner as requested 
I have also run System Look and that log is attached.
thank you.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Well, I'm now made well aware that the infection on your PC is simply a rare one. I am going to change the name of your topic slightly, as it will make it useful for visitors to find helpful information. You see, one file that was missed in the fixes by me kept reinstalling the other malicious system file, which made the machine reinfect. It may be the cause of it reappearing. Smile...

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply. Also, please run SystemLook as we did above, and let's see a new log. Right On!

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have carried out the FRST as you instructed and the fixlog is attached
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please do this part now:
Also, please run SystemLook as we did above, and let's see a new log.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Please find a fresh scan of SystemLook attached
thank you

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Persistent lot, isn't it?
Look at this: C:\Windows\System32\drivers\NetUtils2016.sys    --a---- 909944 bytes    [19:00 13/02/2017]    [19:00 13/02/2017] 9EE21F7D46BD2B0F128E0907BABC7D28




Let's target it a bit more... We need a different approach... Bear with me here. Smile...

Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply. Also, attach MBRDUMP.txt to your next reply, which will be located within the same area of FRST.




Avast Browser Cleanup Tool


  1. Please download this free tool and save it to your desktop.
  2. Install the program by double-clicking on avast-browser-cleanup-sfx.exe.
  3. This cleanup tool will search and list if unwanted entries were found. If found, it will display a button ‘Remove all add-ons listed below and cleanup browser.’ You may remove all or delete one entry at a time.
  4. Avast Browser Cleanup will confirm before it permanently deletes the add-on. Please click Yes to proceed with removal of bad add-ons on the affected browser.





Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




In your next reply, please include the following:

  • Fixlog.txt for FRST fix
  • MBRDUMP.txt
  • FRST.txt and Addition.txt for the re-run of FRST.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Please find attached the logs as you requested,
The MBRDUMP log is empty and as such I have been unable to send it.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Couple of questions... Did you make these restrictions on the OS:

GroupPolicy: Restriction - Chrome <======= ATTENTION
HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2138326613-2610238322-1334748225-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION


Second question... Did you install or want these Google Chrome extensions:
CHR Extension: (Google Translate) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-02-09]
CHR Extension: (Nimbus Screenshot App) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\aecjogkncpbkjfobfnoaiepipllcadhe [2017-02-09]
CHR Extension: (File Converter) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\alblmaecejifbilchdofkdanifpmnmfk [2017-02-09]
CHR Extension: (BeFunky Photo Editor) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2017-02-09]
CHR Extension: (TV) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2017-02-09]
CHR Extension: (Nimbus Screenshot and Screencast) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2017-02-09]
CHR Extension: (Replace New Tab Page) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkhddihkmmiiclaipbaaelfojkmlkja [2017-02-09]
CHR Extension: (Pixlr-o-matic) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2017-02-09]
CHR Extension: (Tetriz Challenge) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\emidddocikgklceeeifefomdnbkldhng [2017-02-09]
CHR Extension: (AudioRecorder) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\enhfkjkjfhhdibpgjmiamdcdgmcjpplk [2017-02-09]
CHR Extension: (Audio Downloader Prime) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\flainkeonkoanoijnkojmiiihnfdhipd [2017-02-09]
CHR Extension: (Trevx - Music Downloader) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpmaepaboafhefdejcbiciklgjogoghf [2017-02-09]
CHR Extension: (AdBlock) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-09]
CHR Extension: (A Journey through Middle-earth) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2017-02-09]
CHR Extension: (Where Am I? - VPN Checker) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbgdaefcalonegdjkhfaeabgodpahimo [2017-02-09]
CHR Extension: (Blocky Minecraft Sniper 3D) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgbbaloijjnkpigapgmocdpoblnlec [2017-02-09]
CHR Extension: (Tate Art Slideshow) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgfbniacchiboaeoaoaejhggfepbbmkj [2017-02-09]
CHR Extension: (New Tab Redirect) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna [2017-02-11]
CHR Extension: (The Weather Channel for Chrome) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop [2017-02-09]
CHR Extension: (90`s Games) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2017-02-09]
CHR Extension: (iPiccy Photo Editor) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\imokeandodnlammaoenbgcnbhigjbpjh [2017-02-09]
CHR Extension: (Pixect) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgdeoagndhabdnoenpdcagbkkmjeibmh [2017-02-09]
CHR Extension: (Webcam Toy) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2017-02-09]
CHR Extension: (Google Maps) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-02-09]
CHR Extension: (Screencastify (Screen Video Recorder)) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2017-02-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-07]
CHR Extension: (New Tab Changer) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\occbjkhimchkolibngmcefpjlbknggfh [2017-02-09]
CHR Extension: (SetupVPN - Lifetime Free VPN) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofgbpoabipfcfjapgnbbjjaenockbdp [2017-02-08]
CHR Extension: (Rollip - Photo Effects) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooikhmcdpofogemaldinihdhidaokcmp [2017-02-09]
CHR Extension: (Pop Art Studio Online) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\oompiimecpnflklhlnmdpddcjdmiibkf [2017-02-09]
CHR Extension: (Chrome Media Router) - C:\Users\paull\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]



With that aside, we're going to have to take a bit more extreme measures, because with all that fix, the malware came right back.

Let's do the following first please...

GMER

Note about this tool:

  • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
  • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
  • No matter what is in the log, please post all the information/contents of the log.
  • These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT"


Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
Thanks again for your help.
In answer to your first question: No, I haven't made any restrictions or changes to the OS.  My knowledge of pc's is basic and I wouldn't know where to start.
In answer to what seems to be a large amount of extensions in Google Chrome, I have installed some of those from the Google Chrome Store,like  Adblock,Google Translate,Nimbus, Where am i VPN Checker, SetUp VPN and New tab redirect.  There seems to be an awful lot that I have no knowledge of having acquired however there are a few i may have had and removed from the Chrome page. The ones I mentioned, I regularly use but I am happy to remove the remainder.
Please find attached,the results of the GMER.txt
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
You're welcome. Please do not give up... I know we will have this soon... Just many of these tools have inabilities that we cannot help, so we are trying to find the best solution.

Please feel free to remove any Chrome addons that you do not want anymore, since it is difficult for me to decide what to remove, as many to most of them are safe. In case you need to know, hit the menu button   and select Settings > Extensions > Press the trash can button on each extension you do not wish to keep.

Let us continue with FRST, but please disable your Antivirus and IObit software before proceeding with this next fix...




Fix with Farbar Recovery Scan Tool

Note to outside visitors: This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable.


Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.


Please post it to your reply.



NOTE: ONLY DO THE FOLLOWING AFTER THE SYSTEM HAS REBOOTED FIRST!
Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have followed your advice and run the FRST scans as you stated.
Please find the relevant logs attached.
I have removed all but 6 of the extensions by following your instructions. I did not  see the majority of the ones that were in your previous message,like 90's games, Pixect  Rollip,etc. The only ones that remain are extensions that i use.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
And yet it is back. What a drag...

Let's do the following please:

Reboot your computer, and when the first screen appears, immediately tap F8 to bring up the Startup Options. Use the keys to select Safe Mode with Networking.

Then please do the following:

Please launch Malwarebytes scanner which you have installed on your computer.

  • On the Dashboard, select Settings.
  • Click on Protection.
  • Ensure that Scan for rootkits is checked. If not, check it.
  • If you are notified the Database is out of date, click Update Now.
  • Click Scan now.
  • When completed, click the down arrow on Export Log and select Text file (*.txt).
  • Save the file to your desktop as MBAM.txt.
  • Click Apply Actions, then restart your computer, if requested.
  • Please copy and paste the contents of MBAM.txt into your next reply. Also, indicate if it was successful.




Emsisoft Emergency Kit

  • Please download Emsisoft Emergency Kit and save it to your desktop.

    Double click on Emsisoft Emergency Kit file on your desktop.  [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 687474703a2f2f6936382e70686f746f6275636b65742e636f6d2f616c62756d732f6933352f6361726e33732f656d7369736f6674253230335f7a70736f6f783675786d6a2e706e67

    When the installation starts you see a image like the one below, click on Install.

    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 687474703a2f2f6936382e70686f746f6275636b65742e636f6d2f616c62756d732f6933352f6361726e33732f456d7369736f6674253230375f7a70736d62756f6c6b39722e706e67

    The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.

    When the update is complete, click on MALWARE SCAN under Scan.  When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes.

    [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 687474703a2f2f6936382e70686f746f6275636b65742e636f6d2f616c62756d732f6933352f6361726e33732f456d7369736f66742532307363616e5f7a7073696671796f7a68662e706e67

    Emsisoft Emergency Kit will start scanning.

    When the scan is completed click on Quarantine.

    When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.  Copy the log and paste it in your topic.

    Please save the log in Notepad on your desktop, and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I have run Malwarebytes Scanner in Safe mode,however it stuck again in Heuristics Analysis and didn't move for 2 hours,at that point i ended the scan.

  It did find 7 problems and i got a screen grab of those problems. As the program wouldn't end, I was unable to remove them or provide you with a log.

The screen grab that i generated  is available here http://www.mediafire.com/file/n9hb5sn661k3vkj/screenshot-newtab-2017-02-15-10-36-04.zip

 I have run   Emsisoft Emergency Kit and on completion I could see from the lists that Netutils is still there.

At the completion of the Emsisoft scan,  a window automatically opens and access to any other part of Emsisoft is not possible as the program wants to restart the system.

I have quarenteened those items

 At the restart i was able to see that 2 NetUtils items had been removed at the restart,but they appear to be back again. I have run 2 scans and the results are attached.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks for the information...

Apologies for the brevity here, but please reboot into just Safe Mode (no networking or command prompt). Open Malwarebytes, press the Scan tab on the left, choose Custom Scan, press "Configure Scan," and only select these checkboxes (deselect others): Scan Memory Objects, Scan Startup and Registry Settings, and C: checked on right as well. Also, under Potentially Unwanted Program, choose the drop down and select "Treat Detections as Malware." Do the same for underneath Potentially Unwanted Modification.

Once that is complete, save the log as you usually would, and access it when you reboot back to Normal Mode, and then post it in your next reply. If that does not function again, you may send a screenshot.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
I have run Malwarebytes again as requested and once again it stuck in Heuristics ananlysis for just over 6 hours.
I have come out of safe mode and have attached the screen grab here, http://www.mediafire.com/file/9ruzpu1xdmrwhf3/screenshot-newtab-2017-02-16-01-05-01.jpg.
thank you once more.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
I'm going to do some investigation closer.

I will be back after several hours with the next instructions... For now, please do the following, which will help me decide what to do later:

First, Re-run Junkware Removal Tool and AdwCleaner as before and post logs from them.




Re-running FRST to search for any leftovers:

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST icon and select Run as Administrator to start the tool.
  • Make sure that every checkbox has a checkmark beside it! <<< NEW INSTRUCTIONS
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.




Re-run SystemLook

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:

    :filefind
    *Avg*
    *McAfee*
    *NetUtils*
    *NetUtils2016*
    *dot4*
    *smw*
    *smp*
    *startgo123*

    :folderfind
    *Avg*
    *McAfee*
    *NetUtils*
    *NetUtils2016*
    *sstmp*
    *dot4*
    *smw*
    *smp*
    *startgo123*

    :Regfind
    NetUtils
    NetUtils2016
    startgo123


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt




WVCheck
Please download WVCheck from Latest EXE Download.

  • Double click WVCheck.exe. (If you downloaded the zipped version you will need to extract it.)
  • As indicated by the prompt, This program can take a while depending on your hard drive space.
  • Once the program is done, copy the contents of the notepad file and send me a private message with the information. This is important since much of the information is unique to you as an individual.





OTHER NOTES:
Confirm with me whether you ran the Chrome Browser Cleanup Tool early on and Avast Browser Cleanup. If this was not done, then this has caused the reinfection.

If you have accounts on Mozilla for Firefox, and Google for Chrome and other accounts, then you can easily sync your data, and completely reinstall the profiles for each browser, which may or may not help this process. I can help you do this of course, but I want to ensure you do not lose browser settings, bookmarks, list of addons, etc., which would easily be "sync-able".

Lastly, did you create the folders on the desktop named "AAA - *" (where * is the suffix, like personal files, video, etc.)?

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
 I have run FRST as requested with the new instructions and it stuck on 'Scanning Edge' for approx 5 hours with no sign of ending. I started it at 09.33and at 13.22 it is still running.
At that point I ended the scan. The FRST log is attached. The Additions log is not available as the scan did not complete.
I then ran SystemLook and the results are attached here.
WV check has run and I have sent a pm with the info.
In answer to your questions, I can confirm that I ran Avast Browser Cleanup, but i can't recall running Chrome Browser Cleanup tool unless you asked me to,in which case I have followed all of your directions.
I have synced my bookmarks for Chrome and Opera. 
The folders on my desktop named AAA are mine  and contain all kinds of personal items.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Okay, let's get on the offensive here toward the infection... Since the bookmarks and other things are synced, we would need to work out the following... In order of course:

Please download and run RKill.

Download mirror 1 - Download mirror 2 - Download mirror 3


  • Save it to your Desktop.
  • Double click the RKill desktop icon.
  • It will quickly run and launch a log. If it does not launch a log, try another download link until it does.
  • Please post its log in your next reply.
  • After it has run successfully, delete RKill.

Note: This tool only kills the active infection, the actual infection will not be gone. Once you reboot the infection will be active again! Please do not reboot until instructed further to do so.



Please download ZHPcleaner to your desktop.

  • Double click on ZHPCleaner to run the tool.
  • If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
  • Please click [INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 687474703a2f2f69313231342e70686f746f6275636b65742e636f6d2f616c62756d732f63633439372f6f6c67756e35322f417368616d706f6f5f536e61705f32303134303831395f31336830396d3530735f3030315f5f7a707339366435383637382e706e67
  • Then press ''Repair'' button.
  • Browsers will automatically shut down.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.





Scan with Shortcut Cleaner:

Please download Shortcut Cleaner to your Desktop.

Right-click on sc-cleaner.exe and select Run as Administrator >> follow the prompts and post the contents of sc-cleaner.txt in your next reply.

Note: The log can also be located at C: >> sc-cleaner.txt

Next
When completed the above, please post back the following in the order asked for:

  • Shortcut Cleaner Log.





Re-run of Malwarebytes scanner
!!NEW INSTRUCTIONS: IF Malwarebytes does not work, re-run RKILL above, and try again until it does so, please.

Please re-open Malwarebytes, and press Scan. If there is an update, allow it to do so.

  • When the scan is complete, if there have been detections, click Quarantines Selected button to allow the program to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

How to get logs: (Export log to save as txt)

  • After the restart once you are back at your desktop, open Malwarebytes once more.
  • Click on the Reports tab > Scan Report. (if you have done more than one scan in the past, select the most recent that shows the Date and time of the scan just performed. Press View Report button.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Find the log on your Desktop and Attach that saved log to your next reply.

(Copy to clipboard for pasting into forum replies or tickets)

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hi,
 I have carried out your requests and have run RKill,that log is attached  
 I have run ZHP cleaner and that log is attached
 I have run shortcut cleaner and that log is attached
 Malwarebytes is currently running and i will post the log when it has finished.
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Still no luck with malwarebytes. I have watched it reach Heuristics Analysis and stay searching for updates for an hour. It found 13 threats but i was unable to get any further. I ran RKill again,saved that log, deleted RKill, but then malwarebytes won't open on the desktop. I have tried to open it as administrator and also left clicking. I figure the only way to open it would be to reboot my pc but  wouldn't that just reinfect it? 
thanks

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Heuristics analysis can take a very long time. 5 hours is unbelievable, yes; however, this is ridiculous.

Let's try a different approach. What we used earlier, ZHPCleaner found an object from the infection and a couple of other unrelated things; however, no luck so far. These are two different tools, to which are a seriously complete analysis... (Keep in mind that our privacy policy prevents me from ever sharing any personal information, so if you like, I can remove the link you post to me for the second tool, once I have accessed the results. No identifiable information about you will be on the tool; however, information concerning personal files and other "business" will be there, which can be a problem for some users to allow other people to see. I rarely take this method, but this is ridiculous how complicating the process is...)

This different approach is going to be an removal tool scan, which normally takes up to a few hours, but very effective (I don't like quitting):




Please click here to download Kaspersky Virus Removal Tool.


  1. Double click on the file you just downloaded and let it install.
  2. It will install to your desktop.
  3. After that leave what is selected and put a check next to My Computer.
  4. Click on the option that says Threat Detection and change it to Disinfect,delete if disinfection fails.
  5. Then click on Start Scan.
  6. Before it is done it may prompt for action regardless of the setting so choose delete if prompted.
  7. When the scan is done no log will be produced.
  8. Click on the bottom where it says Report to open the report.
  9. Then highlight of of the items found by using ctrl + a on your keyboard to select all or use your mouse to select all then right click and choose copy.
  10. This will copy the items that it found to the clipboard you can then open notepad (go to start then run then type in notepad) and choose paste to paste the contents into Notepad.
  11. You can save this on the desktop.
  12. Post the contents of the document in your next reply.


Note: This tool will self uninstall when you close it so please save the log before closing it.




Please download the latest version of Kaspersky GetSystemInfo (GSI) from GetSystemInfo.com and save it to your Desktop. (On the website, press the download button in the top bar)

  • Please close all other applications running on your system.
  • Right click GetSystemInfo.zip and hit Extract all. Then double click on getsysteminfo.exe to run the program.
  • Click the Settings button.
  • Set it to Maximum
  • IMPORTANT! Then please click Customize - choose Driver / Ports tab and
  • Uncheck Scan Ports.
  • Click Create Report to run it.
  • It will create a zip folder called GetSystemInfo_XXXXXXXXXXXXXX.zip on your Desktop. Please upload the folder to Kaspersky GSI Parser and click the Submit button.

Please copy and paste the url of the GSI Parser report (not the log) in your next reply.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello again,
I have downloaded and run the latest kaspersky virus removal tool.The version i downloaded differed to your instructions but i did run the scan and It did print a report. However i was  unable to copy it as you requested and so I had to take a screen grab of the finished report. That is available here   https://www.mediafire.com/?1vgd6dgardm3atm
I then ran Kaspersky Get System info. That program also differed from your instructions but i did run it and I uploaded the report to Kaspersky GSI Parser. 
The url is here   http://www.getsysteminfo.com/read.php?file=eec00c693762b46fe85b67eb942d521c
thank you

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Thanks for the updates! Keep in mind that this infection is not detected by very many antivirus/tools, and because of this, we have difficulty.

Go to this site please: https://www.hybrid-analysis.com/

Press choose file... and find c:\windows\system32\drivers\netutils2016.sys

Allow it to scan the file and post the report URL back here when done please. Smile...

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
Hello,
When i try to upload the file you specified by using the page 'Payload security',  I  go 'select file' which i follow using the path you supplied until i reach  \drivers. At that point the drivers folder is open but only a handful of folders & files are visible. When i search normally myself and go my pc > Windows C > system32 > drivers , there are literally dozens of system files including the Netutils2016.sys file. How do i get this file to show when i search through the Payload Security site?
thank you.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
When you're in the folder, press File > Change folder and search options... Press the tab View, and then under Advanced Settings:

-On Hidden Files and Folders, set it to Show hidden files, folders, and drives.
-Uncheck Hide extensions for known file types
-Uncheck Hide protected operating system files

Lastly, hit Apply and OK.

Once that's done, then try to browse for that file again, please, and see if it all works out this time.

description[INACTIVE] NetUtils2016: PC badly affected after installing program - Page 1 EmptyRe: [INACTIVE] NetUtils2016: PC badly affected after installing program

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum