NicabarP
New member
- Local time
- 8:44 AM
- Messages
- 3
I have been finding this on several machines lately using RogueKiller. (Third one today)
¤¤¤ Registry : 4 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B5D00FF2-C635-4597-A707-DEE7ED712F33} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B5D00FF2-C635-4597-A707-DEE7ED712F33} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
The Private address is sometimes different but is always a class A private address.
After rebooting the entries return. Webpages are timing out on multiple browsers and ping returns >50% packet loss.
Suggestions online are to run the standard arsenal: Malewarebytes, AV cleaners, Combofix (Win 7), ESET, ect. None of these are finding the infection.
I have tried all of these and I am still receiving same findings from RogueKiller. It is persistent even when booting to safe mode.
The only solution I have found thus far has been to Refresh the OS.
I am hoping someone finds a less intrusive solution. Any help would be appreciated.
¤¤¤ Registry : 4 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B5D00FF2-C635-4597-A707-DEE7ED712F33} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B5D00FF2-C635-4597-A707-DEE7ED712F33} | DhcpNameServer : 10.0.0.1 [(Private Address) (XX)] -> Found
The Private address is sometimes different but is always a class A private address.
After rebooting the entries return. Webpages are timing out on multiple browsers and ping returns >50% packet loss.
Suggestions online are to run the standard arsenal: Malewarebytes, AV cleaners, Combofix (Win 7), ESET, ect. None of these are finding the infection.
I have tried all of these and I am still receiving same findings from RogueKiller. It is persistent even when booting to safe mode.
The only solution I have found thus far has been to Refresh the OS.
I am hoping someone finds a less intrusive solution. Any help would be appreciated.
My Computer
At a glance
Cross PlatformIntel(R) Core(TM) i7-4700MQ CPU @ 2.4Ghz 2.40...12064 MB DDR3Intel(R) HD Graphics 4600
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- HP
- OS
- Cross Platform
- CPU
- Intel(R) Core(TM) i7-4700MQ CPU @ 2.4Ghz 2.40 Ghz
- Motherboard
- Hewlett-Packard 1962 ENVY 15-J SERIES LAPTOP 720568-501
- Memory
- 12064 MB DDR3
- Graphics Card(s)
- Intel(R) HD Graphics 4600
- Hard Drives
- 1TB HHD 2.5 Sata (Multiple partition formats) HGST HTS541010A9E680
- Antivirus
- Avast (Current Version)
- Browser
- Multiple

