Author Topic: Found Proc.RunPE, [PUP.Gen0], [PUM.StartMenu] and more! Help me?  (Read 7274 times)

0 Members and 1 Guest are viewing this topic.

July 08, 2018, 12:44:01 PM

dieselpots

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
hello. what should i do about this ? i will attach files. (json and txt)
also i think my network is strange i am using TCPView if anyone is experienced with networking and wants to help with that.

thanks for great software and support!   :D :D




Reply #1July 08, 2018, 03:47:58 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: Found Proc.RunPE, [PUP.Gen0], [PUM.StartMenu] and more! Help me?
« Reply #1 on: July 08, 2018, 03:47:58 PM »
Hi Haned,

Welcome to Adlice.com Forum.
What do you mean by strange ? Did you install netcut on your own ?

Please select the following entry for deletion :
Quote
[PUP.Gen0] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}

PUM stands for Potentially Unwanted Modification. In your case, thoses entries are perfectly legit and necessary to access Internet.
For more information, please read RogueKiller Documentation.

We need to retrieve more information, for the [Run.PE] detection.
Please follow the following process :
  • Download Process Explorer (x64) and save it to your desktop.
  • Click on the setup file (procexp64.exe) and select Run as Administrator to start the tool.
  • Locate the process named RtkNGUI64.exe, do a right click on it and select Create Dump > Create Full Dump...
  • Save the dump on your desktop and compress it.
  • Upload it to Dropbox, Google Drive or similar services and share the link in your next reply.
Regards.

Reply #2July 08, 2018, 04:02:58 PM

dieselpots

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
Re: Found Proc.RunPE, [PUP.Gen0], [PUM.StartMenu] and more! Help me?
« Reply #2 on: July 08, 2018, 04:02:58 PM »
Hi Haned,

Welcome to Adlice.com Forum.
What do you mean by strange ? Did you install netcut on your own ?

Please select the following entry for deletion :
Quote
[PUP.Gen0] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}

PUM stands for Potentially Unwanted Modification. In your case, thoses entries are perfectly legit and necessary to access Internet.
For more information, please read RogueKiller Documentation.

We need to retrieve more information, for the [Run.PE] detection.
Please follow the following process :
  • Download Process Explorer (x64) and save it to your desktop.
  • Click on the setup file (procexp64.exe) and select Run as Administrator to start the tool.
  • Locate the process named RtkNGUI64.exe, do a right click on it and select Create Dump > Create Full Dump...
  • Save the dump on your desktop and compress it.
  • Upload it to Dropbox, Google Drive or similar services and share the link in your next reply.
Regards.

Thank you for your quick reply and help I really appreciate it. I installed (then uninstalled) netcut yes.
I deleted what you told me to delete, and here is the dump: https://ufile.io/dq5ej

Thank you again!  :)

I guess I suspect that I have something infected.. I am not that experienced when it comes to these things.. I'll say it again lol I appreciate all the help!
« Last Edit: July 14, 2018, 12:12:21 AM by dieselpots »

Reply #3July 11, 2018, 03:15:43 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: Found Proc.RunPE, [PUP.Gen0], [PUM.StartMenu] and more! Help me?
« Reply #3 on: July 11, 2018, 03:15:43 PM »
Hi Haned,

The analysis of the dump concluded to a false positive.
Could you please attach the file RtkNGUI64.exe itself in your next message to help us fix this ?

Could you please also attach the log of the tool that detected malware in the "steam" folder ? It may be a false positive, since no malware should be able to survive a fresh install of Windows 10.

Regards.

Reply #4July 12, 2018, 10:14:57 AM

dieselpots

  • Newbie

  • Offline
  • *

  • 3
  • Reputation:
    0
    • View Profile
Re: Found Proc.RunPE, [PUP.Gen0], [PUM.StartMenu] and more! Help me?
« Reply #4 on: July 12, 2018, 10:14:57 AM »
Hi Haned,

The analysis of the dump concluded to a false positive.
Could you please attach the file RtkNGUI64.exe itself in your next message to help us fix this ?

Could you please also attach the log of the tool that detected malware in the "steam" folder ? It may be a false positive, since no malware should be able to survive a fresh install of Windows 10.

Regards.

Hi okay that sounds good but I am still almost certain something is wrong.. I don't have any logs left for the detected malware on my previous OS. Sorry!
Here is the RtkNGUI64.exe and related files in the same folder: https://ufile.io/ejrah

Thank you!!

Reply #5July 13, 2018, 08:18:50 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: Found Proc.RunPE, [PUP.Gen0], [PUM.StartMenu] and more! Help me?
« Reply #5 on: July 13, 2018, 08:18:50 PM »
Hi dieselpots,

Thanks.
We will do an analysis and get back to you as soon as possible.

Regards.