Nasty Adware - difficult to remove after many attempts


  1. Posts : 3
    asdf
       #1

    Nasty Adware - difficult to remove after many attempts


    Hello everyone, first post here.

    I'm usually savvy enough to get rid of most viruses, but this bugger has been deeply embedded somewhere I can't find it. Essentially this adware does two things: whenever starting on the google homepage, a "secure" search will automatically pop up, redirecting my search through bing or secure-search, and at random intervals (once every 3-5 minutes) a new tab opens up to a site called "weevah.[...]" or some site where I can chat with Emily. I also use Google Chrome.

    So far I've uninstalled and reinstalled all plugins (I only use Adblock Plus and now Ublock Origin which prevents these pop-ups). I've ran Panda Security on full search, and used ESET Online Scanner, Junkware Removal Tool, TDSS Killer, and Adware Removal. During those searches I removed a trojan.

    I'm open to going back through and doing these steps again, but just looking to see if you've guys got suggestions as to removing it. If anyone believes running these through Safe Mode will provide better results, I'll likely begin that.

    EDIT: Don't know if this is much help, but after checking the uBlock logger, it appears a blocked domain on the google page is from "https://us.adloads.net/post"
      My Computer


  2. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #2

    Welcome to our forum.

    I'm no infection removal expert.

    Do you have this installed?

    Weeva - Amazing Books - Delightfully Easy


    Take a read through this and see if it might help. Do at your own risk.

    How to Remove Weevah2.top Hijacker Virus | Updated

    Jack
      My Computer


  3. Posts : 3
    asdf
    Thread Starter
       #3

    Went through the second link you posted, and have already done many of the things mentioned.

    Nothing sketchy in the task manager. Nothing strange in the RegEdit
    CurrentUser->CurrentVersion->Run: Default
    LocalMachine->Currentversion->Run: Default, Apoint, HotKeysCmds, IgfxTray, Itunes Helper, SysTrayApp //All system32 or dell/apple stuff
    LocalMachine->Wow6432: Default, PSUAMain (Panda Security), SunJavaUpdateSchedule

    No unwanted IP Addresses in the hosts file in System32.

    Deleted my current user from Chrome -> Adware still here. When I signed back in, it also said that an extension was automatically installed by another program, so its still here.

    IP4/IP6 network connections set to automatic.

    Chrome Shortcut does not lead to bad .exe file.
      My Computer


  4. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #4

    It could be a program you have installed.

    You could use this tutorial by Brink to isolate it.

    Troubleshoot Application Conflicts by Performing a Clean Startup


    Jack
      My Computer


  5. Posts : 3
    asdf
    Thread Starter
       #5

    Tried that - didn't work. Virus even runs in safe mode.

    EDIT: Deleted useless info
    Last edited by 3eer4e345; 14 Feb 2017 at 17:59.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:20.
Find Us