Mal Url oa505txzz.ru

Interesting; the first PowerShell infection I’ve seen.

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

- Right-click on 

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Press the Fix button just once and wait.
- If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
- When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

Also, tell me how your system is running now.

My Internet become slow or Maybe my connection now is just slow at this time
Some of the thumbnails of the picture takes time to load but only once is this normal?
When I refresh in desktop I think there are some delay
So far the malware didn’t show up after 10 mins. Will restart it again just to be sure

Folders icon take time to load too

Your network speed should increase as the system clears the backlog of communications with everything you blocked earlier (some of which should be allowed for security purposes; you can block them when we are finished, if you want to).

FIRST >>>>

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

- Right-click on 

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Press the Fix button just once and wait.
- If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
- When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

SECOND >>>>

AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

- [b]Vista/7/8 users:[/b] Right click the [b]AdwCleaner[/b] icon on the desktop, click [b]Run as administrator[/b] and accept the UAC prompt to run AdwCleaner.

You will see the following console:

http://i1351.photobucket.com/albums/p785/dbreeze2/Scanners%20screens/AdwCleaner_v5016_zpsf8ln0fea.png

- Click the [b]Scan[/b] button and wait for the scan to finish.
- After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: [b]Waiting for action. Please uncheck elements you don't want to remove.[/b]
- Click the [b]Clean[/b] button.
- [b]Everything checked[/b] will be deleted.
- When the program has finished cleaning a report appears.
- Once done it will ask to reboot, allow this

http://1.bp.blogspot.com/-vitKqfMQS4o/UEDylIQ7HJI/AAAAAAAABLc/Hx-IwqKoaxg/s1600/adwcleaner_delete_restart.jpg

- On reboot a log will be produced; please attach that in your next reply. This report is also saved to [b]C:\AdwCleaner\AdwCleaner[C0].txt[/b]

Optional:

NOTE: If you see AVG Secure Search being targeted for deletion, Here’s Why and Here. You can always Reinstall it.

Hi my internet speed is still slow. Not the normal speed and the image is posted become like this (see attachment) Is it really like that?

Did AdwCleaner reboot the system?

Yes. BTW is your image really look like that?

Edit
I attach the image

@dbrisendine: he means the image from the guide looks a little glitched at the top.

@Aco3: just letting you know it looks glitched for me too so its not just you there.

Did the fix force me to use ip filter? And force my sytem to not have proper codecs?

New popup. Search manager

Just a suspicious message > Win32:Evo-gen [Susp] = Suspicious

you may upload and test the file (maca.exe) at virustotal and post link to scan result here

Not sure I understand your questions:
IP filter = Proxy then yes I removed the Proxy setting in FireFox as it was reported as non-specific and could have been hijacked.

The codecs were not changed by the fix directly unless you were using a Proxy service to provide the codecs. Can you provide some details?

Is it possible to return it to normal?
BTW is there need to fix anything after the last fix you posted?

Edit
In chrome sometimes facebook won’t load the url keep changing www.facebook.com then web.facebook.com then www.facebook.com this keep repeating

If you want to return the system to the state it was at before the first Fixlist run, there should be a System Restore point made entitled “Restore Point made by FRST | date and time”. You can run System Restore and choose this point to have you system set back to that state.

As to if there are any more fixes, none at this time.