Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Slow browsers and pages like alibaba

  • This topic is locked This topic is locked
2 replies to this topic

#1 Picaro


  • Members
  • 44 posts
  • Local time:02:37 AM

Posted 14 July 2016 - 08:56 PM

hello, my browsers get slow and different pages load at any moment.

It happens to my mozilla,chrome and edge browsers.

Thanks in advance.


Malwarebytes Anti-Malware

Scan Date: 7/14/2016
Scan Time: 8:12 PM
Logfile: malware.txt
Administrator: Yes

Malware Database: v2016.07.14.11
Rootkit Database: v2016.05.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 10
CPU: x64
File System: NTFS
User: Giovanny

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 409802
Time Elapsed: 21 min, 26 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 3
Trojan.ProxyHijacker, HKLM\SOFTWARE\CLASSES\setup.DynamicNS, Quarantined, [698a5bc80e8c64d263474d49b2502bd5],
Trojan.ProxyHijacker, HKLM\SOFTWARE\WOW6432NODE\CLASSES\setup.DynamicNS, Quarantined, [b241a47f1b7f5cda2f7bc8ce986ada26],
Trojan.ProxyHijacker, HKLM\SOFTWARE\CLASSES\WOW6432NODE\setup.DynamicNS, Quarantined, [b241a47f1b7f5cda2f7bc8ce986ada26],

Registry Values: 2
Hijack.AutoConfigURL.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, 0http://stop-block.net/wpad.dat?3fb2543c0acbfed0cb4ae873a5e7854612599693, Quarantined, [d91ad251eab080b6b75e1d91ba4a8f71]
Hijack.AutoConfigURL.PrxySvrRST, HKU\S-1-5-21-3170390870-670902786-56734884-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|AutoConfigURL, http://stop-block.net/wpad.dat?3fb2543c0acbfed0cb4ae873a5e7854612599693, Quarantined, [995aa3805e3cc076869103abf50f2ad6]

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 2
RiskWare.FilePatcher, C:\Users\Giovanny\Downloads\Global.Mapper.v16.0.7.Patch.REPT.rar, No Action By User, [cc271e052872dd5989f7e868c53ca957],
Adware.Agent, C:\ProgramData\InstallMate\{4CED7431-1320-4606-A4ED-5B02970E56C7}\Custom.dll, Quarantined, [2ac9e43ff9a1ea4ce98ac6ef57a954ac],

Physical Sectors: 0
(No malicious items detected)


Attached Files

BC AdBot (Login to Remove)


#2 dbrisendine


  • Malware Response Team
  • 508 posts
  • Gender:Male
  • Location:BC, Canada
  • Local time:07:37 PM

Posted 16 July 2016 - 02:53 AM

Hi Picaro,

Welcome to BleepingComputer. My name is dbrisendine and I'll be helping you with this problem. Before I get into the removal of malware / correction of your problem, I need you to be aware of the following:
  • Please read all of my response through at least once before attempting to follow the procedures described.I would recommend printing them out, if you can, as you can check off each step as you complete it. Also, as some of the cleaning may be done in Safe Mode and there will be no internet connection then, you will find that having the steps printed for reference speeds the cleaning process along. If there's anything you don't understand or isn't totally clear to you, please come back to me for clarification before you start those steps.
  • All of the assistants and staff at BleepingComputer are here on a volunteer basis; please respect our time given to the cause of helping others.If you are going to be away for more than 4 days, please let me know here. (I will do the same for you.) We do realize that 'life happens' and situations arise unexpectedly; we just ask that you keep us up to date.
  • Malware removal is a complex, multiple step process; please stay with me on this thread (don't start another thread) until I declare that your logs are clean and you are good to go. The absence of apparent issues does not mean your system is clean; I will tell you when everything looks good for you to go and help you remove the tools we have used.
  • If any of the security programs on your system should give any warnings about the software tools I ask you to download and use, please do not be alarmed.All of the tools I will have you use are safe to use (as instructed) and malware free.
  • While we strive to disrupt your system as little as possible, things happen.If you can, it would be best to back up your personal files now (if you do not already have a backup). You can store these on a CD/DVD, USB drive or stick, anywhere but on your same system. This will save you from possible anguish later if something unforeseen happens.
  • Please do not run any other tools or scanners than what I ask you to.Some of the openly available software made for malware removal can make changes to your system that interfere with the cleaning of the malware, or even destroy your system. I will use only what the situation calls for and direct you in the proper use of that software.
  • Please do not attach any log files to your replies unless I specifically ask you.Instead please copy and paste so as to include the log in your reply. You can do this in separate posts if it's easier for you.

    - Save ALL Tools to your Desktop-

    All the tools that I will have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.

    Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
    Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
    "Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.
    Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
    and the click the "Select Folder" button. Click OK to get out of the Options menu.
    IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
    select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
    NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.

Let's get started....

Thanks for the logs. I would like for you to run one more search before we begin and I think this will help "knock" out any possible hijacker / wpad abuser at once.

Run a search with FRST.
  • Right click on FRST.exe on your desktop and select "Run as Administrator..." When the tool opens click Yes to disclaimer.
  • Type SearchList into the Search Box.
  • Press the Search Registry button.
  • It will produce a log called search.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
Please attach the log search.txt in your reply.  Thanks.

Please do not ask for Malware help via PM (Private Messages).  Please post in the forum boards instead.  Thanks.

My help is always free but if you would like to help encourage me or show your thanks -----> btn_donate_LG.gif

#3 dbrisendine


  • Malware Response Team
  • 508 posts
  • Gender:Male
  • Location:BC, Canada
  • Local time:07:37 PM

Posted 27 July 2016 - 10:52 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

Please do not ask for Malware help via PM (Private Messages).  Please post in the forum boards instead.  Thanks.

My help is always free but if you would like to help encourage me or show your thanks -----> btn_donate_LG.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users