Author Topic: Topwebclub.com invasion  (Read 5500 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Topwebclub.com invasion
« on: April 16, 2016, 07:56:32 AM »
Hello,

my homepage on Micosoft Edge changed to Topwebclub.com or one of its other guises.
I also use chrome but that does not seem affected.

Can someone please guide my through the process of malware removal.

Thanks

Adam

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Topwebclub.com invasion
« Reply #1 on: April 16, 2016, 08:02:52 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #2 on: April 16, 2016, 09:03:09 AM »
MBAM log...


REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #3 on: April 16, 2016, 09:10:44 AM »
Farbar logs...

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #4 on: April 16, 2016, 09:17:27 AM »
aswMBR log...


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Topwebclub.com invasion
« Reply #5 on: April 16, 2016, 09:26:03 AM »
OK, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #6 on: April 16, 2016, 09:36:57 AM »
Okay, thank you.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Topwebclub.com invasion
« Reply #7 on: April 16, 2016, 12:24:51 PM »
Let me know if this works

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk [2015-11-10]
ShortcutTarget: $McRebootA5E6DEAA56$.lnk ->  (No File)
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #8 on: April 17, 2016, 02:44:11 AM »
FRST fix log...

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #9 on: April 17, 2016, 03:11:37 AM »
AdwCleaner.exe log...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Topwebclub.com invasion
« Reply #10 on: April 17, 2016, 07:06:27 PM »
How is the computer now ?

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #11 on: April 18, 2016, 01:58:53 AM »
Hiya,

still there I'm afraid.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Topwebclub.com invasion
« Reply #12 on: April 18, 2016, 04:22:48 PM »
OK lets now reset Edge


CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
C:\Users\Adam\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix

THEN


To Launch PowerShell, Type “Power Shell” in Windows search.
Right Click powershell.exe and Run as Administrator 
Copy and paste the following command into the blue box :

Get-AppXPackage -AllUsers -Name Microsoft.MicrosoftEdge | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register "$($_.InstallLocation)\AppXManifest.xml" -Verbose}

Press enter and reboot once completed
Now try Edge

REDACTED

  • Guest
Re: Topwebclub.com invasion
« Reply #13 on: April 19, 2016, 08:20:17 AM »
Tried this but it started on en.4yendex.com

Tried again but it started on Topwebclub.com again.

The normal homepage is MSN.




Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Topwebclub.com invasion
« Reply #14 on: April 19, 2016, 04:02:07 PM »
Hmm that is intriguing as what we did was totally re-install edge

Could you go to edge settings > advanced settings and let me know if you can change the home page