Jump to content

Can someone help me out with this virus? How do I destroy it?

Go to solution Solved by maxib7,

I had a similar problem when conduit hijacked my search engine on all my browsers. My anti virus would pick it up and I had to go into my settings in my browsers and manually remove it from my defaults then find its file in my computer. It ended up being hidden in my program files. The first step I would recommend would be to look for the name associated with this adware. it looks from the picture to be offerswizard and google and see what other people have done. I'll look it up and post any finding

I think I found an article that may be your solution http://www.fixyourbrowser.com/removal-instructions/remove-ads-offerswizard-popup-virus/ 

Does anyone know what virus is causing this and which program I can use to remove it? As you can see in the included picture I am running adblock on purpose to see if it will do anything, but it doesn't. The things circled in red shouldn't exist and open a popup ad if clicked. Sometimes I even get a simulated bing searchbard that opens an ad as well. I scanned my computer with both avg and malwarebytes, no result. Please help me out, it's driving me crazy!

 

post-42239-0-95019400-1403197903_thumb.p

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

probably a google extension.... if not go to programs and features and remove a program that is like search protect or something like that :) 

Its all looks these days

Link to comment
Share on other sites

Link to post
Share on other sites

lc-smith-shotgun_flat.jpg

It won't even see it coming...

 

 

Seriously though, try disabling all your extensions and reinstall Chrome if that doesn't work. 

.

Link to comment
Share on other sites

Link to post
Share on other sites

Here is how to get rid of it,

Step 1: MalwareBytes scan

Step 2: Antivirus scan

Step 3: Download and use ADWCleaner

Step 4: Restart PC

Step 5: Check extensions in browser

Step 6: be happy

My current build - Ever Changing.

Number 1 On LTT LGA 1150 CPU Cinebench R15

http://hwbot.org/users/TheGamingBarrel

Link to comment
Share on other sites

Link to post
Share on other sites

probably a google extension.... if not go to programs and features and remove a program that is like search protect or something like that :)

 

I tried and found nothing, that's the first thing I did :( it doesn't even show any suspect addon in the extension page on chrome

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

Some extensions try to insert stuff like that, go and check the settings for all your chrome addons.

 

Spoiler

Case Bitfenix Ghost, Mobo Asus Maximus VIII Ranger, CPU i7 6700K @4.2 Ghz cooled by Arctic cooling Freezer i30, (barely). GPU Nvidia GTX 970 Gigabyte G1 @1519Mhz core, RAM 16Gb Crucial Ballistix CL16 @2400Mhz. SSD 128GB Sandisk Ultra Plus as my OS drive. HDD's  1TB  Seagate ST31000524AS its OEM, 3TB Seagate Barracuda, 2x 500GB WDC Blue (RAID 0)

If it isn't working absolutely perfectly, according to all your assumptions, it is broken.

Link to comment
Share on other sites

Link to post
Share on other sites

I know I ranted about the uselessness of avast!'s additional features yesterday, but the browser cleanup tool might help you out.

QUOTE ME OR I PROBABLY WON'T SEE YOUR RESPONSE 

My Setup:

 

Desktop

Spoiler

CPU: Ryzen 9 3900X  CPU Cooler: Noctua NH-D15  Motherboard: Asus Prime X370-PRO  RAM: 32GB Corsair Vengeance LPX DDR4 @3200MHz  GPU: EVGA RTX 2080 FTW3 ULTRA (+50 core +400 memory)  Storage: 1050GB Crucial MX300, 1TB Crucial MX500  PSU: EVGA Supernova 750 P2  Chassis: NZXT Noctis 450 White/Blue OS: Windows 10 Professional  Displays: Asus MG279Q FreeSync OC, LG 27GL850-B

 

Main Laptop:

Spoiler

Laptop: Sager NP 8678-S  CPU: Intel Core i7 6820HK @ 2.7GHz  RAM: 32GB DDR4 @ 2133MHz  GPU: GTX 980m 8GB  Storage: 250GB Samsung 850 EVO M.2 + 1TB Samsung 850 Pro + 1TB 7200RPM HGST HDD  OS: Windows 10 Pro  Chassis: Clevo P670RG  Audio: HyperX Cloud II Gunmetal, Audio Technica ATH-M50s, JBL Creature II

 

Thinkpad T420:

Spoiler

CPU: i5 2520M  RAM: 8GB DDR3  Storage: 275GB Crucial MX30

 

Link to comment
Share on other sites

Link to post
Share on other sites

Step n1: show all your processes in windows task manager. There is an option ''show process of all users''

There are 104 processes (written in bottom) show them all.

 

Legit check each of them, then bring the Matrix God Hammer.

CPU: Ryzen 2600 GPU: RX 6800 RAM: ddr4 3000Mhz 4x8GB  MOBO: MSI B450-A PRO Display: 4k120hz with freesync premium.

Link to comment
Share on other sites

Link to post
Share on other sites

ok this is what you do, boot Hirens Boot CD off a usb/cd Scan your HDD/SSD with the included programs, mainly clamwin_logo.png

No Problem,

 

and stop using chrome for christ sake, use Firefox(32) Waterfox(64) with add-on Adblock Plus

I say this because, I had a very bad Gypsie attack...they stole my wife, plow... and they touch my horse in a very bad way... he got very depressed.

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone know what virus is causing this and which program I can use to remove it? As you can see in the included picture I am running adblock on purpose to see if it will do anything, but it doesn't. The things circled in red shouldn't exist and open a popup ad if clicked. Sometimes I even get a simulated bing searchbard that opens an ad as well. I scanned my computer with both avg and malwarebytes, no result. Please help me out, it's driving me crazy!

 

attachicon.gifvirushighlights.png

I Had this a few days ago. 

 

Ran malwareBytes anti virus and it destroys it

[spoiler= Dream machine (There is also a buildlog)]

Case: Phanteks Enthoo Luxe - CPU: I7 5820k @4.4 ghz 1.225vcore - GPU: 2x Asus GTX 970 Strix edition - Mainboard: Asus X99-S - RAM: HyperX predator 4x4 2133 mhz - HDD: Seagate barracuda 2 TB 7200 rpm - SSD: Samsung 850 EVO 500 GB SSD - PSU: Corsair HX1000i - Case fans: 3x Noctua PPC 140mm - Radiator fans: 3x Noctua PPC 120 mm - CPU cooler: Fractal design Kelvin S36 together with Noctua PPCs - Keyboard: Corsair K70 RGB Cherry gaming keyboard - mouse: Steelseries sensei raw - Headset: Kingston HyperX Cloud Build Log

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone know what virus is causing this and which program I can use to remove it? As you can see in the included picture I am running adblock on purpose to see if it will do anything, but it doesn't. The things circled in red shouldn't exist and open a popup ad if clicked. Sometimes I even get a simulated bing searchbard that opens an ad as well. I scanned my computer with both avg and malwarebytes, no result. Please help me out, it's driving me crazy!

 

attachicon.gifvirushighlights.png

Go look at your programs hit date added and delete the most recent one thats not a windows program game or a legit program you know is safe.... just did that the other day and it got rid of it :)

Its all looks these days

Link to comment
Share on other sites

Link to post
Share on other sites

Step n1: show all your processes in windows task manager. There is an option ''show process of all users''

There are 104 processes (written in bottom) show them all.

 

Legit check each of them, then bring the Matrix God Hammer.

done that but anyway there was no other user logged in

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

Here is how to get rid of it,

Step 1: MalwareBytes scan

Step 2: Antivirus scan

Step 3: Download and use ADWCleaner

Step 4: Restart PC

Step 5: Check extensions in browser

Step 6: be happy

 

I had done everything you said already except using ADWcleaner that solved it :D thanks to everyone who answered!

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

done that but anyway there was no other user logged in

The system processes wont show otherwise. that list you shown aint 104 processes.

Because knowing this means prevention from coming here for weird cpu&ram usage discrepancies

CPU: Ryzen 2600 GPU: RX 6800 RAM: ddr4 3000Mhz 4x8GB  MOBO: MSI B450-A PRO Display: 4k120hz with freesync premium.

Link to comment
Share on other sites

Link to post
Share on other sites

I used to have that too, check your chrome extensions

Song Of The Day: Nujabes - Battlecry

Link to comment
Share on other sites

Link to post
Share on other sites

The system processes wont show otherwise. that list you shown aint 104 processes.

Because knowing this means prevention from coming here for weird cpu&ram usage discrepancies

 

I thought I had solved it but i was wrong D: it happens in opera too now! so it wasn't a chrome extension!

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

Im telling you man Clamwin has yet to fail me...

I say this because, I had a very bad Gypsie attack...they stole my wife, plow... and they touch my horse in a very bad way... he got very depressed.

Link to comment
Share on other sites

Link to post
Share on other sites

I thought I had solved it but i was wrong D: it happens in opera too now! so it wasn't a chrome extension!

I had a similar problem when conduit hijacked my search engine on all my browsers. My anti virus would pick it up and I had to go into my settings in my browsers and manually remove it from my defaults then find its file in my computer. It ended up being hidden in my program files. The first step I would recommend would be to look for the name associated with this adware. it looks from the picture to be offerswizard and google and see what other people have done. I'll look it up and post any finding

No... I'm not ready for my thread to die, not yet.... nooooo......

Link to comment
Share on other sites

Link to post
Share on other sites

I had a similar problem when conduit hijacked my search engine on all my browsers. My anti virus would pick it up and I had to go into my settings in my browsers and manually remove it from my defaults then find its file in my computer. It ended up being hidden in my program files. The first step I would recommend would be to look for the name associated with this adware. it looks from the picture to be offerswizard and google and see what other people have done. I'll look it up and post any finding

I think I found an article that may be your solution http://www.fixyourbrowser.com/removal-instructions/remove-ads-offerswizard-popup-virus/ 

No... I'm not ready for my thread to die, not yet.... nooooo......

Link to comment
Share on other sites

Link to post
Share on other sites

Im telling you man Clamwin has yet to fail me...

 

 

I'm in the process of trying both, I'll let you know how it went.

 

p.s. I actually temporarily solved the issue by cutting a suspicious process in task manager, but I was unable to trace it as it wouldn't let me open the source folder. It hasn't shown up again for now but I have the feeling that at the first reboot it will spring out again.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

 

I identified what it is, it's "system network driver", the process I had killed. I uninstalled it manually and am running adwcleaner and malwarebytes to see if I can find any trace left, then I'll reboot and try clamwin.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

 

Apparently it's gone now, even after reboot it didn't show up and it doesn't appear in task manager nor control panel. Thanks to everyone!

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×