Facebook page that opens by itself
Solved
romain5911000
Posted messages
17
Registration date
Status
Member
Last intervention
-
Malekal_morte- Posted messages 178136 Registration date Status Moderator, Security Contributor Last intervention -
Malekal_morte- Posted messages 178136 Registration date Status Moderator, Security Contributor Last intervention -
Hello
my girlfriend was on Facebook and a new browser popped up on its own, and now I have pages that open by themselves. I tried Malwarebytes, AdwCleaner, but nothing works. I ran ZphDiag and it tells me I have adware.suspect pub.optional.crossrider pub.optional.browserair.
my girlfriend was on Facebook and a new browser popped up on its own, and now I have pages that open by themselves. I tried Malwarebytes, AdwCleaner, but nothing works. I ran ZphDiag and it tells me I have adware.suspect pub.optional.crossrider pub.optional.browserair.
7 answers
Hi,
Windows has been infected by adware and potentially unwanted programs. These unwanted software are known to cause advertisements to pop up and can lead to serious slowdowns on your web browsers.
Here are the steps to follow:
1°)
Follow Xplode's AdwCleaner tutorial
If copying/pasting doesn't work, use the site http://pjjoint.malekal.com/ to host your report, provide the report link in a new message.
Note: The report is also saved as C:\AdwCleaner[S1].txt
2°) FRST
Follow the FRST tutorial. ( take your time to read carefully - everything is well explained ).
Download and run the FRST scan, 3 FRST reports will be generated:
Send these 3 reports to the site http://pjjoint.malekal.com/ and return the 3 pjjoint links that lead to the reports here in a new reply so that we can review them.
--
Please press any key to continue the disinfection...
Windows has been infected by adware and potentially unwanted programs. These unwanted software are known to cause advertisements to pop up and can lead to serious slowdowns on your web browsers.
Here are the steps to follow:
1°)
Follow Xplode's AdwCleaner tutorial
- Download it to your Desktop or Downloads folder,
- Launch "AdwCleaner" and click on [Scan],
- The scan will take several minutes, please be patient,
- Once the scan is complete, do not uncheck anything, click on [Clean],
- After the cleaning is finished, a report will open,
- Copy/paste the report content into your next reply.
If copying/pasting doesn't work, use the site http://pjjoint.malekal.com/ to host your report, provide the report link in a new message.
Note: The report is also saved as C:\AdwCleaner[S1].txt
2°) FRST
Follow the FRST tutorial. ( take your time to read carefully - everything is well explained ).
Download and run the FRST scan, 3 FRST reports will be generated:
- FRST.txt
- Shortcut.txt
- Additional.txt
Send these 3 reports to the site http://pjjoint.malekal.com/ and return the 3 pjjoint links that lead to the reports here in a new reply so that we can review them.
--
Please press any key to continue the disinfection...
Here is the correction to be made with FRST. You can refer to this explanatory note with screenshots.
Open Notepad: Windows Key + R,
In the "Run" field, type notepad and click OK.
Copy/Paste the following into it:
Once the text is pasted into Notepad,
Menu "File" then "Save As",
On the left, go to the Desktop,
In the bottom field, file name enter: fixlist.txt
Click on "Save", this will create fixlist.txt on the Desktop.
Restart FRST and click on the "Fix" button
A restart may be necessary ( not mandatory )
A text file appears, copy/paste the content here in a new message.
Restart the computer.
2°)
Reset/Repair Web browsers:
--
Please press any key to continue the disinfection...
Open Notepad: Windows Key + R,
In the "Run" field, type notepad and click OK.
Copy/Paste the following into it:
CreateRestorePoint:
CloseProcesses:
Task: {CECABA10-1B2E-4E3E-878B-27492714BEE4} - System32\Tasks\6c7610ca07fac4eceb94111ee23064f1 => Rundll32.exe "C:\Program Files (x86)\Reference Assemblies\p7oxnd.dll",e62dc6c6547f46bda862da2d05af6862 <==== ATTENTION
ShellExecuteHooks: No name - {3C12FAA6-AA96-11E6-AE69-64006A5CFC23} - C:\Users\romain\AppData\Roaming\Merpupy\Stoqeshgrerigh.dll -> No file
R2 Ghorersearuqis; C:\Program Files (x86)\Cluberspmercerk\Zcnrnw.dll [139264 2017-01-18] () [Unsigned file]
2017-01-18 20:48 - 2017-01-18 20:48 - 00006106 _____ C:\WINDOWS\System32\Tasks\Finshgrijock System
2017-01-18 20:47 - 2017-01-19 08:40 - 00000228 _____ C:\WINDOWS\web.bat
2017-01-18 20:47 - 2017-01-18 21:47 - 00000000 ____D C:\Program Files (x86)\Cluberspmercerk
2017-01-18 20:47 - 2017-01-18 20:57 - 00000000 ____D C:\Users\romain\AppData\Roaming\Chwodomanozak
2017-01-18 20:47 - 2017-01-18 20:48 - 00000000 ____D C:\Users\romain\AppData\Local\Ckahuterrety
2017-01-18 20:47 - 2017-01-18 20:47 - 00720033 _____ C:\WINDOWS\unins000.exe
2017-01-18 20:47 - 2017-01-18 20:47 - 00033985 _____ C:\WINDOWS\unins000.dat
2017-01-18 20:47 - 2017-01-16 17:06 - 00385510 _____ ( ) C:\WINDOWS\window.exe
2017-01-18 20:47 - 2017-01-05 11:10 - 00000059 _____ C:\WINDOWS\window.bat
2017-01-17 17:47 - 2017-01-17 17:47 - 03095223 _____ C:\WINDOWS\442749b19edcbea6a6297f02f3cad418.exe
Hosts:
EmptyTemp:
RemoveProxy:
Reboot:
Once the text is pasted into Notepad,
Menu "File" then "Save As",
On the left, go to the Desktop,
In the bottom field, file name enter: fixlist.txt
Click on "Save", this will create fixlist.txt on the Desktop.
Restart FRST and click on the "Fix" button
A restart may be necessary ( not mandatory )
A text file appears, copy/paste the content here in a new message.
Restart the computer.
2°)
Reset/Repair Web browsers:
- Repair Mozilla Firefox (first paragraph)
- Repair Google Chrome (just the first paragraph).
- Reset and repair Internet Explorer
--
Please press any key to continue the disinfection...
for the first
https://pjjoint.malekal.com/files.php?id=FRST_20170119_r13s9w6p15j14
246231 file(s) in the database - 84019 lines referenced
86572 comments - 103.04% lines commented -
https://pjjoint.malekal.com/files.php?id=FRST_20170119_r13s9w6p15j14
246231 file(s) in the database - 84019 lines referenced
86572 comments - 103.04% lines commented -
It's all good =)
End with a cleanup using Malwarebytes - Malwarebytes Anti-Malware free version tutorial
A few tips:
To avoid getting caught again.
Read - Unwanted Programs / PUPs: Adware/PUPs File: unwanted and parasitic programs
(Especially enable LPI detections to spot parasitic and advertising programs)
--
Please press a key to continue the disinfection...
End with a cleanup using Malwarebytes - Malwarebytes Anti-Malware free version tutorial
A few tips:
To avoid getting caught again.
Read - Unwanted Programs / PUPs: Adware/PUPs File: unwanted and parasitic programs
(Especially enable LPI detections to spot parasitic and advertising programs)
--
Please press a key to continue the disinfection...
On the other hand, I just redid zphdiag https://pjjoint.malekal.com/files.php?id=20170119_b8j11j9b13l6
# Updated on 01/06/2017 by Malwarebytes
# Database: 2017-01-18.1 [Locale]
# Operating System: Windows 10 Pro (X64)
# Username: romain - ROMAIN-PC
# Executed from: H:\download\adwcleaner_6.042.exe
# Mode: Scan
# Support: https://www.malwarebytes.com/support/
No malicious service found.
No malicious folder found.
No malicious file found.
No patched DLL found.
No malicious key found.
No infected shortcut found.
No malicious task found.
No malicious item found in the registry.
No malicious Firefox preference found.
No malicious Chromium preference found.
C:\AdwCleaner\AdwCleaner[C0].txt - [5302 bytes] - [01/18/2017 21:04:12]
C:\AdwCleaner\AdwCleaner[C2].txt - [1445 bytes] - [01/19/2017 00:34:57]
C:\AdwCleaner\AdwCleaner[C3].txt - [5782 bytes] - [01/19/2017 01:43:57]
C:\AdwCleaner\AdwCleaner[C4].txt - [1737 bytes] - [01/19/2017 08:39:36]
C:\AdwCleaner\AdwCleaner[R0].txt - [5112 bytes] - [10/03/2015 17:32:08]
C:\AdwCleaner\AdwCleaner[S0].txt - [5153 bytes] - [01/18/2017 21:03:43]
C:\AdwCleaner\AdwCleaner[S1].txt - [1642 bytes] - [01/19/2017 00:34:35]
C:\AdwCleaner\AdwCleaner[S2].txt - [1629 bytes] - [01/19/2017 00:38:44]
C:\AdwCleaner\AdwCleaner[S3].txt - [6193 bytes] - [01/19/2017 01:43:23]
C:\AdwCleaner\AdwCleaner[S4].txt - [1924 bytes] - [01/19/2017 07:21:59]
C:\AdwCleaner\AdwCleaner[S5].txt - [1845 bytes] - [01/19/2017 09:20:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [1919 bytes] ##########