Jump to content

Trouble getting rid of registry malware


Tl2AV

Recommended Posts

Hello,

I am having an issue where a registry value was created and causes my PC to open chrome browser (my default) and opens a pop-up called sd-steam that redirects to some Russian pop-up page.  This only happens on a fresh boot and only once.  I tracked down the registry edit and attempted to delete it, but it seems to be recreating itself after each reboot.  I even tried to edit the entry but it just reverts back to the original value.  I ran malwarebytes to locate the problem and it found a pup malware.  After attempting to have malwarebytes remove the registry edit, my antivirus (Avira) blocks the edit.  I tried disabling my antivirus and reattempting to delete the edit, but no success. 

Any help at all would be gladly appreciated.

Thank you all for your time.

Link to post
Share on other sites

Hello and :welcome:

 

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button. button.

    x5o4gh.png

  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.

  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Link to post
Share on other sites

This should fix it. Let me know after reboot.

 

FRST.gif Fix with Farbar Recovery Scan Tool

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif


icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.

fixlist.txt

Link to post
Share on other sites

Here is the fixlog. I also had one more question. My computer seems to not want to sleep anymore. Whenever I hit the sleep button on my keyboard or via start menu, the displays turn off, but my computer's LEDs remain on. When I hit a key to turn the displays back on, it is as if the computer didn't even try to go to sleep. Only place I can make it go to sleep is the login screen. This is a recent problem, it was working fine about a week ago. I built the PC in May of this year.

Thank you for your time.

Fixlog.txt

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.