Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google keeps redirecting, Computer gets slow sometimes


  • This topic is locked This topic is locked
50 replies to this topic

#46 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,372 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:16 AM

Posted 16 May 2018 - 05:37 PM

No problem, thanks for letting me know.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

BC AdBot (Login to Remove)

 


#47 eckvanet

eckvanet
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:02:16 PM

Posted 18 May 2018 - 03:19 PM

Computer seems like it's running better. One thing to note, I personally deleted weimthxsrv.exe from my computer beforehand.

 

C:\AdwCleaner\Quarantine\gxIX4a2dRE\RunBoosterService64.exe a variant of Win64/Adware.RunBooster.A application cleaned by deleting
C:\AdwCleaner\Quarantine\oZYFYZ5B6k\uninstallce.exe a variant of Generik.MYRBMVT trojan cleaned by deleting
C:\AdwCleaner\Quarantine\rQF69AzBla\Application\Lavasoft.Utils.dll a variant of MSIL/WebCompanion.D potentially unwanted application cleaned by deleting
C:\AdwCleaner\Quarantine\rQF69AzBla\Application\Lavasoft.WCAssistant.WinService.exe a variant of MSIL/WebCompanion.D potentially unwanted application cleaned by deleting
C:\AdwCleaner\Quarantine\rQF69AzBla\Application\WebCompanion.exe a variant of MSIL/WebCompanion.D potentially unwanted application cleaned by deleting
C:\AdwCleaner\Quarantine\rQF69AzBla\Application\WebCompanionInstaller.exe a variant of MSIL/WebCompanion.C potentially unwanted application cleaned by deleting
C:\AdwCleaner\Quarantine\xrpMCARCr4\3f0cfe79caebe32b72d8bed91b9d4848.exe a variant of Win32/Adware.Zdengo.EC application cleaned by deleting
C:\AdwCleaner\Quarantine\xrpMCARCr4\60bf100430dc182363fd33757c90cbb9.exe a variant of Win32/Adware.Zdengo.EG application cleaned by deleting
C:\AdwCleaner\Quarantine\xrpMCARCr4\6c3d4965a310e338886de7f43847bd1e.exe a variant of Win32/Adware.Zdengo.EC application cleaned by deleting
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Cache\f_000007 JS/Adware.Revizer.A application deleted
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Cache\f_00000b JS/Adware.Revizer.A application deleted
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Cache\f_020038 JS/Adware.AztecMedia.A application cleaned by deleting
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Cache\f_02003d JS/Adware.Revizer.A application deleted
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Cache\f_02005e JS/Adware.AztecMedia.A application cleaned by deleting
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Cache\f_02011b JS/Adware.AztecMedia.A application cleaned by deleting
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Extensions\adfjcahgdmhmnmlodjhhhigkpajpjakn\12.602.11.57241_0\common\js\PartnerId.js JS/Mindspark.G potentially unwanted application cleaned by deleting
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Extensions\adfjcahgdmhmnmlodjhhhigkpajpjakn\12.602.11.57241_0\components\api\background\widget-api-impl.js JS/Mindspark.E potentially unwanted application cleaned by deleting
C:\Users\nith8\AppData\Local\Google\Chrome\User Data Default\Default\Extensions\adfjcahgdmhmnmlodjhhhigkpajpjakn\12.602.11.57241_0\js\scriptInjector.js JS/Mindspark.E potentially unwanted application cleaned by deleting
C:\Users\nith8\AppData\Local\wdaehlx\data645\f_00000a JS/Adware.Revizer.A application deleted
C:\Users\nith8\AppData\Local\wdaehlx\data664\f_0000a3 JS/Adware.Revizer.A application deleted
C:\Users\nith8\Downloads\DriverAssist-Setup.exe a variant of MSIL/UwS.DriverAssist.A application cleaned by deleting
C:\Users\nith8\Downloads\FileZilla_3.30.0_win64-setup_bundled.exe Win32/FusionCore.T potentially unwanted application cleaned by deleting
 
Result of Security Analysis by Rocket Grannie (x86) Updated: 13th May, 2018
Running from:C:\Users\nith8\Desktop (16:23:45 - 05/18/2018)
***---------------------------------------------------------***
Microsoft Windows 10 Home X64
UAC is Enabled
Internet Explorer 11
Default Browser: Google Chrome
***------------Antivirus - Antispyware - Firewall-----------***
Windows Defender (Enabled - up to Date)
Windows Defender (Enabled - up to Date)
Windows Firewall (Enabled)
No other Firewall Installed
***-------Security Programs - Browsers - Miscellaneous------***
Adobe Flash Player NPAPI is not installed
Adobe Acrobat Reader DC (18.011.20038)
Google Chrome (66.0.3359.181)
Java (8.0.1710.11)
Microsoft Silverlight (5.1.20513.0)
 
***----------------Analysis Complete-------------------------***


#48 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,372 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:16 AM

Posted 18 May 2018 - 07:24 PM

Nothing of any real concern in the ESET report. The second report looks good.

Are there any remaining issues?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#49 eckvanet

eckvanet
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:02:16 PM

Posted 19 May 2018 - 07:40 AM

Nothing else really, my computer is working much better than it did before. Thank you so much for your help over this past month, I really do appreciate the good you do for me and others in the same boat. 



#50 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,372 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:16 AM

Posted 19 May 2018 - 08:56 AM

It was my pleasure to work together with you on your computer. I am glad things are better.

Thank you for your kind words, I really do appreciate them. Looks like we are all set.

Now that your computer is running well it is my great pleasure to proclaim to you the Good News!

===================================================

All Clean!

--------------

Your computer is now clean.

Right click on the FRST icon and rename it to Uninstall. Right click on it again, select Run as administrator and FRST will delete itself. You may also delete any other tools or reports created during our efforts.

Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean.

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read:In addition, here are some more links you might find of interest:Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. ohmy_done.gif
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#51 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,372 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:16 AM

Posted 20 May 2018 - 08:48 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users