Solo3.biz?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bravus, May 25, 2020.

  1. Bravus

    Bravus Private E-2

    My wife's Windows 7 computer at work (a Lenovo ThinkCentre) has started throwing up fake Norton expiration ad popups (no Norton products are installed) on the desktop that can't be dismissed, as shown in the attached screenshot.

    It says 'solo3.biz' in the popup itself, and that's a malware thing, but it might be misdirection, since none of the typical things described in the online descriptions of how to remove solo3.biz show up.

    Preliminary checks with Malwarebytes and Bitdefender found nothing.

    I've run the checks as instructed. I did forget to reboot after the (newly installed on top of the existing installation) Malwarebytes finished scanning (it found nothing) but did reboot after Roguekiller. Sorry. Also neglected to turn off UAC until after Roguekiller finished, because I assumed she had Windows 10 but it's Windows 7. Please let me know if I need to repeat any steps due to these mistakes on my part.

    All the logs are attached, except that the MGTools log is in a reply message below because I couldn't attach 6 logs to the first message. Nothing was detected by any of the scans.

    Thanks so much for your help and support.
     

    Attached Files:

  2. Bravus

    Bravus Private E-2

    MGTools log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't let MGTools complete the scan.

    Is this a company computer? Would she have permission to make changes on it?
     
  4. Bravus

    Bravus Private E-2

    It's a company computer but she basically *is* the company and we own the computer: we have full admin permissions to make changes.

    We're at home now but I'll probably head in to her office early tomorrow morning and run MGTools again for the full scan and send the log.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What browser does she use predominately?
     
  6. Bravus

    Bravus Private E-2

    Mostly Vivaldi (offshoot of Opera), although Chrome is also on the machine. We checked for .exe hijacks for both but they looked OK.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This nasty usually comes from a rogue download.


    1. Open Google Chrome.
    2. In the top-right corner, expand the Chrome menu.
    3. In the Google Chrome menu, open Settings.
    4. At the Privacy and Security section, click Site settings.
    5. Open the Notifications settings.
    6. Remove Solo3.biz by clicking the three dots on the right next to the Solo3.biz URL and click Remove.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I checked with Vivaldi.....click the far left V and click on settings - under tools. Then click on Web pages. Scroll down to default permissions and see if the notifications is set to ask / allow or block. I suggest you set it to block.
     
  9. Bravus

    Bravus Private E-2

    Thanks, Tim. We needed to update her Vivaldi from 2.5 to 3.0 for those instructions to work and then it worked, but the popups came back after a little while.

    What's next? (It might be a matter of bringing her computer home so I'm not trying to work on it around office hours and my work and her work, 20 minutes drive from home.)

    Thanks very much.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need you to re-run the MGTools to get a full set of logs. What happened when you ran it the first time?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds