angelkr Posted August 20, 2016 ID:1057467 Share Posted August 20, 2016 Hello there I too have been struck from the zodiac-game russian pop-up. it appears whenever i open a browser window after booting the pc. i uninstalled chrome, then it poped up on IE. reinstalled chrome, same thing happened. i am following instructions hoping we can solve this without having to make a clean installation of windows. thank you in advance for your precious time! FRST.txt Addition.txt Link to post Share on other sites More sharing options...
kevinf80 Posted August 20, 2016 ID:1057502 Share Posted August 20, 2016 Hello and welcome to Malwarebytes, My screen name is kevinf80, i`m here to help clean up your system. Make sure to run all scans from accounts with Administrator status, continue as follows please: Anyone other than the original starter of this thread please DO NOT follow the instructions and advice posted as replies here, my help and advice is NOT related to your system and will probably cause more harm than good... Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into. NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work. Run FRST and press the Fix button just once and wait. The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply. Next, Please open Malwarebytes Anti-Malware. On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits". Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button. A Threat Scan will begin. When the Scan is complete Apply Actions to any found entries. Wait for the prompt to restart the computer to appear (if applicable), then click on Yes. After the restart once you are back at your desktop, open MBAM once more. To get the log from Malwarebytes do the following: Click on the History tab > Application Logs. Double click on the Scan log which shows the Date and time of the scan just performed. Click Export > From export you have three options:Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your replyText file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to replyXML file (*.xml) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply… Next, Download AdwCleaner by Xplode onto your Desktop. Double click on Adwcleaner.exe to run the tool. Click on the Scan in the Actions box Please wait fot the scan to finish.. When "Waiting for action.Please uncheck elements you want to keep" shows in top line.. Click on the Cleaning box. Next click OK on the "Closing Programs" pop up box. Click OK on the Information box & again OK to allow the necessary reboot After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed... Next, Download Sophos Free Virus Removal Tool and save it to your desktop. Double click the icon and select Run Click Next Select I accept the terms in this license agreement, then click Next twice Click Install Click Finish to launch the program Once the virus database has been updated click Start Scanning If any threats are found click Details, then View log file... (bottom left hand corner) Copy and paste the results in your reply Close the Notepad document, close the Threat Details screen, then click Start cleanup Click Exit to close the program If no threats were found please confirm that result.... Let me see those logs, also give an update on any remaining issues or concerns... Thank you, Kevin.. Fixlist.txt Link to post Share on other sites More sharing options...
angelkr Posted August 21, 2016 Author ID:1057546 Share Posted August 21, 2016 Hey Kevin, thank you for the swift reply! i followed your instructions to the letter, it seems that the problem has been solved, i haven't got any more pop-ups from that page and all the scans have come out clean. i am attaching all the log files you requested and below is the export from malwarebytes and below that, the log from adw, even though it came with 0 as well. Sophos is taking its sweet time with it, but so far 0 threats detected. I will post a reply if anything comes up! Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 21-Aug-16 Scan Time: 10:10 Logfile: Administrator: Yes Version: 2.2.1.1043 Malware Database: v2016.08.20.06 Rootkit Database: v2016.08.15.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 10 CPU: x64 File System: NTFS User: Angel Scan Type: Threat Scan Result: Completed Objects Scanned: 359801 Time Elapsed: 12 min, 39 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) ADW log. # AdwCleaner v6.000 - Logfile created 21/08/2016 at 10:29:18 # Updated on 12/08/2016 by ToolsLib # Database : 2016-08-21.1 [Server] # Operating System : Windows 10 Pro (X64) # Username : Angel - ARKHANGELSK # Running from : C:\Users\Angel\Downloads\AdwCleaner.exe # Mode: Clean # Support : https://toolslib.net/forum ***** [ Services ] ***** ***** [ Folders ] ***** ***** [ Files ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** ***** [ Web browsers ] ***** ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [3251 Bytes] - [20/08/2016 16:16:50] C:\AdwCleaner\AdwCleaner[C2].txt - [807 Bytes] - [21/08/2016 10:29:18] C:\AdwCleaner\AdwCleaner[S0].txt - [3181 Bytes] - [20/08/2016 16:15:55] C:\AdwCleaner\AdwCleaner[S1].txt - [1272 Bytes] - [21/08/2016 10:27:55] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1025 Bytes] ########## Fixlog.txt Link to post Share on other sites More sharing options...
kevinf80 Posted August 21, 2016 ID:1057552 Share Posted August 21, 2016 Thanks for those logs, yes Sophos is a very thorough tool so the scan make take a couple of hours. Let me see the log when Sophos completes. Thank you, Kevin Link to post Share on other sites More sharing options...
angelkr Posted August 22, 2016 Author ID:1057777 Share Posted August 22, 2016 Hello again! the sophos scan came through with 0 threats and a clean computer and that makes me a happy camper. thanks you very much for your time and effort Kevin, much appreciated Link to post Share on other sites More sharing options...
kevinf80 Posted August 22, 2016 ID:1057783 Share Posted August 22, 2016 Hello angelkr, If you have no remaining issues or concerns run the following to clean up: Download "Delfix by Xplode" and save it to your desktop. Or use the following if first link is down:"Delfix link mirror" If your security program alerts to Delfix either, accept the alert or turn your security off. Double Click to start the program. If you are using Vista or higher, please right-click and choose run as administrator Make Sure the following items are checked: Remove disinfection tools <----- this will remove tools we have used. Purge System Restore <--- this will remove all previous and possibly exploited restore points, a new point relative to system status at present will be created. Reset system settings <--- this will reset any system settings back to default that were changed either by us during cleansing or malware/infection Now click on "Run" and wait patiently until the tool has completed. The tool will create a log when it has completed. We don't need you to post this. Any remnant files/logs from tools we have used can be deleted… Next, Read the following links to fully understand PC Security and Best Practices, you may find them useful....Answers to Common Security Questions and best PracticesDo I need a Registry Cleaner? Take care and surf safe Kevin... Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted August 23, 2016 Root Admin ID:1057862 Share Posted August 23, 2016 Glad we could help. :)If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts