Melpik Posted September 25, 2022 ID:1535346 Share Posted September 25, 2022 I keep getting notification of a dimessing-parker.com trojan. How do I remove? Link to post Share on other sites More sharing options...
Maurice Naggar Posted September 25, 2022 ID:1535348 Share Posted September 25, 2022 Hello First question: Is this about a "Block notice" from Malwarebytes about some specific link address or IP address ? Was there a browser in use at that moment? If so, which one ? I will guide you along on looking for potential malware. Lets keep these principles as we go along. Removing malware can be unpredictable Please don't run any other scans, download, install or uninstall any programs while I'm working with you. Only run the tools I guide you to. Do not run online games while case is on-going. Do not do any free-wheeling web-surfing. The removal of malware isn't instantaneous, please be patient. Cracked or or hacked or pirated programs are not only illegal, but also will make a computer a malware victim. Having such programs installed, is the easiest way to get infected. It is the leading cause of ransomware encryptions. It is at times also big source of current trojan infections. Please uninstall them now, if any are here, before we start the cleaning procedure. Please stick with me until I give you the "all clear". If your system is running Discord, please be sure to Exit out of it while this case is on-going. I would like a report set for review. This is a report only. Please download MALWAREBYTES MBST Support Tool Once you start it, click Advanced >>> then Gather Logs Have patience till the run has finished. Upload an archive once it is done. Attach the mbst-grab-results.zip from the Desktop Please attach mbst-grab-results.zip to your reply The IP block actions by Malwarebytes are keeping the machine safe from potential threats. Link to post Share on other sites More sharing options...
Melpik Posted September 25, 2022 Author ID:1535352 Share Posted September 25, 2022 Thanks for the quick response. Received while using Google Chrome. mbst-grab-results.zip Link to post Share on other sites More sharing options...
Solution Maurice Naggar Posted September 25, 2022 Solution ID:1535362 Share Posted September 25, 2022 What are being blocked are Outbound connections to a specific IP address "34.196.146.107" /// link address dimessing-parker[.]com The threat is external of your machine. It is out in the internet. The Malwarebytes web protection is keeping this system safe from potential harm at a external location.{ step 1 } Here are next first steps: Please set File Explorer to SHOW ALL folders, all files, including Hidden ones. Use OPTION ONE or TWO of this article Please use this Guide { step 2 } Start Malwarebytes. Click Settings ( gear ) icon. Next, lets make real sure that Malwarebytes does NOT register with Windows Security Center Click the Security Tab. Scroll down to "Windows Security Center" Click the selection to the left for the line "Always register Malwarebytes in the Windows Security Center". { We want that to be set as Off .... be sure that line's radio-button selection is all the way to the Left. thanks. } This will not affect any real-time protection of the Malwarebytes for Windows 😃. Close Malwarebytes. >{ step 3 } Using just the Chrome browser, signin to your Google account ( if not signed in already) https://chrome.google.com/ Then go to https://chrome.google.com/sync? Scroll down the page, press the "CLEAR DATA" button, to clear the Chrome data from your Google account. [ 4 ] for Chrome, while Chrome is running: Press & hold SHIFT+CTRL+Del keys on keyboard to get menu for clearing browsing data: Check mark the line "Browsing history" Check mark the line "Download history" Check mark the lined "Cached images and files" and press Clear Data button ( in blue ) [ 5 ] After that, make real sure that Chrome is "NOT" set to reload the pages from the last session Go into the settings menu of Chrome by first clicking the control icon of Chrome on upper right of the adress bar Then look deeper in SETTINGS Make real sure it is "NOT" set to "continue where you left off" . [ 6 ] See this article on our Malwarebytes Bloghttps://blog.malwarebytes.com/security-world/technology/2019/01/browser-push-notifications-feature-asking-abused/ You want to disable the ability of each web browser on this machine from being able to allow "push ads". That means Chrome, Firefox, or Edge browser (on Windows 10), or on Opera. Scroll down to the tips section "How do I disable them". [ 7 ] I suggest you install the Malwarebytes Browser guard for Chrome. To get & install the Malwarebytes Browser Guard extension for Chrome, Open this link in your Chrome browser: https://chrome.google.com/webstore/detail/malwarebytes/ihcjicgdanjaechkgeegckofjjedodee Then proceed with the setup. IF after that there are still Block notices when using Chrome browser, then EXIT the Chrome browser & for the meantime, use the EDGE browser. Link to post Share on other sites More sharing options...
Maurice Naggar Posted September 26, 2022 ID:1535453 Share Posted September 26, 2022 Good morning. Do let me know if you have completed the suggestions. Let me know whether the Block notices have ceased. Link to post Share on other sites More sharing options...
Melpik Posted September 27, 2022 Author ID:1535529 Share Posted September 27, 2022 I think it did! Thanks Link to post Share on other sites More sharing options...
Maurice Naggar Posted September 27, 2022 ID:1535633 Share Posted September 27, 2022 Good morning. Alright, that is good to know. I would recommend getting a readout report as to update status of some key apps. Download SecurityCheck by glax24 from here https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe and save the tool on the desktop. If Windows's SmartScreen block that with a message-window, then Click on the MORE INFO spot and over-ride that and allow it to proceed. This tool is safe. Smartscreen is overly sensitive. Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow to run & go forward Wait for the scan to finish. It will open in a text file named SecurityType.txt. Close the file. Attach it with your next reply. You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 5, 2022 ID:1536620 Share Posted October 5, 2022 This system is good-to-go. This here is for tools cleanup. Please download KpRm by kernel-panik and save it to your desktop. right-click kprm_(version).exe and select Run as Administrator. Read and accept the disclaimer. When the tool opens, ensure all boxes under Actions are checked. Under Delete Quarantines select Delete Now, then click Run. Once complete, click OK. A log may open in Notepad titled kprm-(date).txt. I do not need it. Just close Notepad if it shows up. Delete mb-support-1.8.7.918.exe Delete mbst-grab-results.zip on the Desktop Consider using PatchMyPC, keep all your software up-to-date - https://patchmypc.com/home-updater#download Keep your system and programs up to date. Several programs release security updates on a regular basis to patch vulnerabilities. Keeping your software patched up prevents attackers from being able to exploit them to drop malware. I am marking this case for closure. I wish you all the best. Stay safe. Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 5, 2022 ID:1536621 Share Posted October 5, 2022 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Please review the following to help you better protect your computer and privacy Tips to help protect from infection Thank you Link to post Share on other sites More sharing options...
Recommended Posts