logo elektroda
logo elektroda
X
logo elektroda

Russian website (virus) - After logging in, the browser with the Russian website

bizon1993 3033 5
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16470090
    bizon1993
    Level 15  
    Hello.

    I have had a problem with Windows 10 PRO x64 for several hours. Namely, the point is that today I downloaded some drivers for a friend and unfortunately I had to use the "downloader" although I never do that, which downloaded the surprisingly working drivers but it blew my computer. He installed some strange applications for me, which I removed and it was ok ... Until restart ... After logging in to my account, the browser on the "normami.ru" page starts automatically (I only have Microsoft explorer left, because I deleted other with Edge and the same).

    I scanned the computer with programs such as: Eset online scanner, Avast Browser Cleanup, CCleaner, ADWcleaner and something else, but I don't remember the name, and then after starting it is the same. I looked for suspicious processes, tried some way with registry keys and nothing.

    I know that the easiest way would be to reinstall the system but I don't want to do it because a month ago I added an m.2 disk to my computer, on which I have the system and some larger games (e.g. Forza horizon 3, about 54GB for download and I have limited internet: /)

    So the best solution for me would be to save this system, but if ultimately nothing can be done, I will put the elevator up again.

    Anyone have any idea? :D

    Thank you in advance for your help and best regards ;)
  • ADVERTISEMENT
  • Helpful post
    #2 16470096
    Kolobos
    IT specialist
    You wrote in the wrong section. You did not include the required FRST logs in the attachment.
  • ADVERTISEMENT
  • ADVERTISEMENT
  • #4 16470197
    bizon1993
    Level 15  
    in the FRST file I found this line:
    HKU \ S-1-5-21-1707937235-4055251897-2623388274-1001 \ ... \ Run: [wsjgkhaayh] => explorer "hxxp: //normami.ru/? Utm_source = uoua03 & utm_content = 9827b388ec781688cce813f51c253m2 = DB22m2E2C702 & utd229mce813f51c253m2 & utm_source
  • ADVERTISEMENT
  • Helpful post
    #5 16470238
    Kolobos
    IT specialist
    Next to frst.exe, create a Fixlist.txt file with the contents:
    Task: {9925973E-58A2-4DF9-96E9-CC73C484F792} - System32 \ Tasks \ MSI => C: \ Users \ bizek! \ AppData \ Roaming \ Microsoft \ msi.exe
    Task: {D93FF539-7695-48E1-B852-BDE89D862906} - System32 \ Tasks \ StartMenuCache => C: \ Windows \ explorer.exe hxxp: //asnopo.ru
    Task: {E843CE16-3B05-4E87-A57B-118A70318896} - System32 \ Tasks \ {9584D211-A4A6-41CA-A996-1F05A09402E2} => pcalua.exe -a C: \ Users \ bizek! \ Downloads \ Nestopia140bin \ nestopia. exe -d C: \ Users \ bizek! \ Downloads \ Nestopia140bin
    HKU \ S-1-5-21-1707937235-4055251897-2623388274-1001 \ ... \ Run: [Vuze Leap] => C: \ Users \ bizek! \ AppData \ Roaming \ Vuze Leap \ VuzeLeap.exe [3247376 2016-10-03] (Azureus Software, Inc.)
    HKU \ S-1-5-21-1707937235-4055251897-2623388274-1001 \ ... \ Run: [wsjgkhaayh] => explorer "hxxp: //normami.ru/? Utm_source = uoua03 & utm_content = 9827b388ec781688cce813f51c253m2 = DB22m2E2C702 & utd229mce813f51c253m2 & utm_source
  • #6 16470288
    bizon1993
    Level 15  
    I did according to the instructions you provided and everything works as before ;) Now I just need to get Edge back into my system ;)

    Thank you for your quick help and best regards Mateusz ;)
ADVERTISEMENT