[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Tried loads of shit and can't get rid of adware

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 48
Thread images: 9

File: 1449800517480.gif (2MB, 336x178px) Image search: [Google]
1449800517480.gif
2MB, 336x178px
I've ran rkill, malwarebytes, adwcleaner, hitman pro and tried them in safe mode as well, deleted all history, cache etc. for all browsers, reinstalled opera and this fuckin adware still won't go away.
None of the cleaners even pick up anything.
When I click anywhere on a page with any button it will open new tabs with ads, usually from cpmofferconvert but I think I've seen other things, it'll highlight random words on a page and if I click on them it searches them in yahoo and it redirects my google searches to yahoo.
It does this randomly and doesn't happen every time but it's incredibly frustrating.
>>
File: 2017-08-12 22-01-38-912.jpg (52KB, 1586x88px) Image search: [Google]
2017-08-12 22-01-38-912.jpg
52KB, 1586x88px
Wow look at this fucking shit
The ones highlighted in red will take me to securesurf.biz then it'll google search them when I click on them
>>
Let me see your process in task manager . use alt+ctrl+del then click process tab so we're gonna remove the software who do that.

But Before that check your extension on your browser first if there's a plugin
>>
>>363158
Step 1 – Remove cpmofferconvert.com pop-up with AdwCleaner
Step 2 – Remove cpmofferconvert.com malicious files with MalwareBytes Anti-Malware
Step 3 – Remove cpmofferconvert.com Browser Extension with Avast Browser Cleanup
Step 4 – Optional: Reset browser settings
>>
Anon again don't use Opera m8 use chrome or Mozilla instead and get a ublock origin extension
>>
>>363166
When is the last time you've used opera
>>
>>363163
Checked plugins and didn't notice anything unusual
Do you want me to take pictures of every part of task manager?

>>363164
I've already seen sites like that and already said I've used some of those
>>
>>363166
The adware affects other browsers too though
>>
>>363169
Please post more process it's running currently right now.

Also you found any malicious software that installed ? Check add or remove programs.
>>363167
Never used it
>>
It's time for a windows reinstall Anon
>>
>>363173
Opera gets a bad rap because I think older versions were really shit but it's good now
>>
>>363173
I've checked that but I didn't notice anything unusual, I'll check again
Gonna dump processes

>>363175
I would really prefer to not do that :(
>>
>>
>>
File: 1502450820479.png (85KB, 492x280px) Image search: [Google]
1502450820479.png
85KB, 492x280px
>>363175
>>363178
Odd nothing any malicious process found

>>363181

Better Untick those since applications are safe.
>>
When was the last thing you did before this happens anyway?
>>
>>363190
What do you mean untick

>>363194
I think it started when I tried to download an album
It wasn't mp3s it was just a picture of a disc
I scanned it with an antivirus software and it said it was fine so I clicked on it but nothing was happening, when I tried to delete it it said it was being used or something
I think I had to disable it from devices and drivers and then I was able to delete it
>>
>>363196
Use your common sense man if you download a PDF and the file extension is .exe don't click it, that's why I never use antivirus anymore since I can tell if it's a virus or not.

>>363196
The meme arrow > like this services
Click that
>>
>>363200
Yeah I know it was stupid since I wasn't really sure what it was
>>
https://www.techsupportall.com/how-to-remove-secure-surf-com-homepage-removal-help/


Do this
>>
>>363200
>why I never use antivirus anymore since I can tell if it's a virus or not.
>>363201
What I've started to do when downloading files I'm not sure of is looking at them with a he editor. The beginning of the file has a certain hexadecimal that is unique to that particular extension. This way you can tell if it's actually that extension and s extra one that's been embedded in the file. I also search the file for the word "program". Because if an exe is embedded in the file, there should be a text string that says something like "this program can't run in dos".

Tedious to do to a lot if files, but worth the time imo.
>>
File: 2017-08-12 23-35-31-656.jpg (18KB, 456x158px) Image search: [Google]
2017-08-12 23-35-31-656.jpg
18KB, 456x158px
>>363207
Trying the program on that page now

>>363209
I'll try that because I'm not usually downloading sketchy shit
Could doing pic related work even if I keep all my files?
>>
>>363209
Yes I have adblock to block pop ups and malware ads I am safe for now
>>
>>363207
>>363212
Okay I the program finished and it said it found some adware from chrome
Everything looks okay so far but I've had other programs say they found shit but it'll still be fucked up
>>
>>363224
Alright it's still fucked
>>
>>363228
when you ran mbam, did you do a full scan of all drives and search for rootkits or just a quickscan?
>>
>>363235
malwarebytes didn't have rootkit scan on by default for some reason, turned it on and still didn't say it found anything
I don't think I'm doing quickscans, how do I make sure these are scanning all drives?
>>
File: mbam.png (58KB, 892x613px) Image search: [Google]
mbam.png
58KB, 892x613px
>>363239
Scan -> Custom Scan -> check the fuck out of everything
>>
>>363242
holy shit I am so retarded
it's been scanning for a really long time now but I have a feeling I'm gonna get something
>>
>>363253
You're not you are just tech illiterate .
>>
>>363268
I'm usually pretty decent at my computer with other things
It's been scanning for 55 mins and has identified 2 threats
>>
>>363269

5 hours later ... is it still scanning?
>>
>>363363
full scans usually take a long time (like, overnight)

also, OP, make sure you immediately restart your computer when the scan finishes
>>
if you still have it run
rogue killer 64bit portable
tdsskiller
junkware removal tool (jrt)
rkill

rogue killer being the most inportant, failing these i'd use maybe geek uninstaller and uninstall ya browsers with it to nuke every file

here's a rar of the said progs, i couldn't get rogue killer portable like i usually use but the install one is the same

http://www17.zippyshare.com/v/qJJ92eDF/file.html
>>
>>363363
ok it was scanning for a really long time and then it crashed or whatever, my hdd wasn't accessible until I restarted my computer
fucking stupid thing was in my steam folders for 2 hours
scanner over a million files and found 12 viruses/pups from what it had done
I think the one that's doing it might be rootboot64.exe
idk if it actually quarantined or deleted any of them so I guess I'll run it again
>>
>>363439
*scanned over a million

>>363395
I'll try them after I work out what malwarebytes did
>>
>>363158
Back up your data

Nuke your hard drive

Reinstall Windows.

Believe me, you'll actually save time compared to trying to remove every little bit of malware manually.
>>
>>363461
dont worry my niggy I think mbam is gettin what needs to be got
also I think something changed because I'm not getting popups anymore it's just that I get the text highlights sometimes like in >>363159
>>
>>363376
>full scans usually take a long time (like, overnight)

Well, yeah. But we don't know how big OP's HDD is, so...

Also, it was a stealth bump, thanks for blowing my cover, Anon.
>>
>>363476
It's 1.8 tb and I've only filled up about a third of it but it's still pretty slow
Running it again cuz it didn't finish properly last time
>>
>>363461
Okay I might have to roll out some big boy stuff now
Something always fucks up before the scan gets finished, idk why
Windows will just stop responding a bit after I start it up but other programs will keep running
>>
>>363540
what version of mbam are you using? maybe try a fresh install
>>
>>363541
I'm pretty sure it was the newest one
I just did the reset pc thing but it's going to keep my files
>>
>>363541
>>363544
And this is going to be the second time I have to set all my shit up again this year and it's really fucking annoying
>>
>>363549

Once it's all set up again and you're happy that you are infection free, and all your browsers have all the plug ins and shit ... make a backup of a clean system. That way, next time you are forced to start again it's just a case of restoring your backup and everything is ready to go.
>>
Get hirens boot CD, make the damn CD and use it.
>>
>>363158
Stop being a scrub and reinstall Windows already.
>>
>>363702
I did
I have goldfish memory so I forgot some of the programs I had
I think I lost the shit in my bandicam folder and I don't back up itunes frequently enough so I lost some albums
Thread posts: 48
Thread images: 9


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.