Nasty Adware - difficult to remove after many attempts

3eer4e345

New member
Local time
4:39 PM
Messages
3
Hello everyone, first post here.

I'm usually savvy enough to get rid of most viruses, but this bugger has been deeply embedded somewhere I can't find it. Essentially this adware does two things: whenever starting on the google homepage, a "secure" search will automatically pop up, redirecting my search through bing or secure-search, and at random intervals (once every 3-5 minutes) a new tab opens up to a site called "weevah.[...]" or some site where I can chat with Emily. I also use Google Chrome.

So far I've uninstalled and reinstalled all plugins (I only use Adblock Plus and now Ublock Origin which prevents these pop-ups). I've ran Panda Security on full search, and used ESET Online Scanner, Junkware Removal Tool, TDSS Killer, and Adware Removal. During those searches I removed a trojan.

I'm open to going back through and doing these steps again, but just looking to see if you've guys got suggestions as to removing it. If anyone believes running these through Safe Mode will provide better results, I'll likely begin that.

EDIT: Don't know if this is much help, but after checking the uBlock logger, it appears a blocked domain on the google page is from "https://us.adloads.net/post"
 

My Computer My Computer

At a glance

asdf
Computer type
Tablet
OS
asdf
Antivirus
Panda
Browser
Chrome

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Went through the second link you posted, and have already done many of the things mentioned.

Nothing sketchy in the task manager. Nothing strange in the RegEdit
CurrentUser->CurrentVersion->Run: Default
LocalMachine->Currentversion->Run: Default, Apoint, HotKeysCmds, IgfxTray, Itunes Helper, SysTrayApp //All system32 or dell/apple stuff
LocalMachine->Wow6432: Default, PSUAMain (Panda Security), SunJavaUpdateSchedule

No unwanted IP Addresses in the hosts file in System32.

Deleted my current user from Chrome -> Adware still here. When I signed back in, it also said that an extension was automatically installed by another program, so its still here.

IP4/IP6 network connections set to automatic.

Chrome Shortcut does not lead to bad .exe file.
 

My Computer My Computer

At a glance

asdf
Computer type
Tablet
OS
asdf
Antivirus
Panda
Browser
Chrome

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Tried that - didn't work. Virus even runs in safe mode.

EDIT: Deleted useless info
 
Last edited:

My Computer My Computer

At a glance

asdf
Computer type
Tablet
OS
asdf
Antivirus
Panda
Browser
Chrome
Back
Top