need to remove some add-ons

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by igrushka7, Sep 18, 2014.

  1. igrushka7

    igrushka7 Private E-2

    Hi All.
    I'we got several add-ons which clog up the screens with adds I really don't want.
    It has been a while, but getting worse & affects GOOGLE only. The IE11 is OK.
    The add-ons in question are:

    50CoupOens, DealExpreSs, Downloadd keeper, NettoCoupon, saavE neT, TTubeeAdbiloecoker, YoutubeAdblocker, YoutubeAdblocker.
    Trying to "disable" them doesn't help as the "enable & disable" for these files are grayed out.
    After running the READ & RUN ME FIRST. Malware Removal Guide, nothing changed, so here I am.
    Thanks, Boris
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. igrushka7

    igrushka7 Private E-2

    Hi Tim.
    Yes, it did fix the problem, thank you very much.

    One more thing though. The add-ons are still there.
    When in IE11 I go TOOLS/Manage add-ons/Toolbars & Extensions ..- all those nasty add-ons are there and enabled. Is there a way to remove them?
    Thanks again.
    Boris.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. igrushka7

    igrushka7 Private E-2

    Hi again Tim.
    Thanks for your patients.
    I have done everything you suggested above, but the mentioned add-ons are still there. The computer works OK though.
    Regards, :confused
    Boris.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm going to pop in because I'm seeing a fair bit to do that could help. Resetting browsers will not help. Let's be more thorough here, begin with the below:

    For a start, Malware Bytes log shows you took no action on what it found. Please do so now!

    Reimage Protector
    <<< Uninstall this junk

    What is inside of this folder?

    C:\ProgramData\350cd8d5514346dc




    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Tasks tab and locate these detections:

    • [Suspicious.Path] Digital Sites.job -- C:\Users\Boris\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] \\Digital Sites -- C:\Users\Boris\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE (/Check) -> FOUND
    • [Suspicious.Path] \\IHUninstallTrackingTASK -- CMD (/C DEL C:\Users\Boris\AppData\Local\Temp\IHUD000.tmp.exe) -> FOUND

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.




    Now re run Hitman Pro and have it remove all it finds.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: NettoCoupon - {0D6EA1A8-8016-2BBA-BC71-9791A70A2C4C} - C:\ProgramData\NettoCoupon\O1983iHI.dll (file missing)
    • O2 - BHO: DealExpreSs - {6FE679CA-8DD4-C03A-6B8C-C55BD3B8AC16} - C:\ProgramData\DealExpreSs\XiA97GF1.dll (file missing)
    After clicking Fix exit HJT.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\nlpiajdbfnmcooenladkpoddemchpplo
    C:\ProgramData\Reimage Protector
    C:\ProgramData\SaverExtEnssioon
    C:\Users\Boris\AppData\Roaming\DIGITA~1
    C:\Users\Boris\AppData\Local\Temp\IHUD000.tmp.exe
    C:\Program Files (x86)\ReimageExpress.com
    C:\Windows\tasks\APSnotifierPP1.job
    C:\Windows\tasks\APSnotifierPP2.job
    C:\Windows\tasks\APSnotifierPP3.job
    C:\Windows\tasks\Digital Sites.job
    C:\ProgramData\NettoCoupon\O1983iHI.dll
    C:\ProgramData\DealExpreSs\XiA97GF1.dll
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Don't forget to let me know about that folder.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    If you still have problems, we'll dig even deeper. :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  8. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13!
    Thanks a lot for your time.
    I have done what you suggested. Unfortunately the bad Add-ons are still there, see attached snapshot "Add-ons.jpg".
    The reset of Google Chrome set the Explorer for "no add-ons" mode. That, I think, why the flood of adds stopped, but the bad add-ons are still there, unfortunately.
    The "Reimage Protector " did not uninstall, the computer suggested that it probably was removed earlier, but the listing in "Control Panel" still remained ??? I just removed the Name as advised.
    I attach the requested files.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall Google Chrome. Reboot the machine and then reinstall. That *should* clear it all. Let me know.
     
  10. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13!
    No, unfortunately it did not. I uninstalled Google Chrome, rebooted, and the add-ons are still there. Not that they do anything, just sitting there. Of course I would like to get them out. So, what the next thing I can do now?
    Thanks,
    Boris
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry. I should have suggested removing it using Revo Uninstaller. Try that and let me know how you get on, if the add ons are still there.
     
  12. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13!
    Bad news. The bastards are still there. Google Chrome is uninstalled again with Revo Uninstaller, but no change.
    By the way, why in IE11 SEARCH is "powered by Google", when Google is uninstalled?
    Thanks,
    Boris.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to be clear... this did not work?

    To turn off add-ons

    • Open the desktop, then tap or click the Internet Explorer icon on the taskbar.
    • Tap or click the Tools button, then tap or click Manage add-ons.
    • Under Show, tap or click All add-ons, then select the add-on you want to turn off.
    • Tap or click Disable, then tap or click Close.
     
  14. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13!
    This was the first thing I tried .
    Now, see attachment, the highlighted are the troublemakers. Check out the red sign on "Toolbars & Extensions" and also the grayouted "Enable & Disable" buttons in the bottom right corner.
    The same story is when dealing with individual ones.
    They all have addresses, see attachment, but none of them could not be found. "Hidden files and..." has been ticked.
    Best regards,
    Boris
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\ProgramData\50CoupOens\1G.x64.dll
    C:\ProgramData\TTubeeAdbiloecoker\vkjJbVyDu1.x64.dll
    C:\Program Files (x86)\Downloadd keeper\wdajCHJ.x64.dll
    C:\Program Files (x86)\YoutubeAdblocker\ReRQ7DaE.x64.dll
    C:\Program Files (x86)\saavE neT\GS5Sqcn.x64.dll
    C:\ProgramData\50CoupOens
    C:\ProgramData\TTubeeAdbiloecoker
    C:\Program Files (x86)\Downloadd keeper
    C:\Program Files (x86)\YoutubeAdblocker
    C:\Program Files (x86)\saavE neT
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Any better?
     
  16. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13!
    No, it did not work. Those files are so well hidden, even OTM can't find them nor could SEARCH.
    Anything else you could suggest?
    Thanks,
    Boris.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is stubborn! Once a full/proper uninstall has been done with Google Chrome, all add ons/extensions should be cleared completely...

    Try this please:

    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    and this..... Avast! Browser Cleanup

    Description:

    Let me know how you get on.
     
  18. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13!
    Done it all. The "untouchables" are still there.
    Yesterday I was playing with ...\Tools\Internet Options\....and somehow managed to make them "Incompatible" instead of being "Enabled". Then by a silly move I've reset the IE11 and the files are back to "Enabled". Now I can't repeat it again. I think it had something to do with security, but can't do it again.
    Well, Kestrel13! don't you hate me yet? By my estimation it is about time.
    Best regards,
    Boris.
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oooh it's a frustrating one that's for sure. I am asking colleagues if they can assist me. Hang in there...
     
  20. igrushka7

    igrushka7 Private E-2

    Thanks Kestrel13!
    Boris
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, let's have you remove Google Chrome again using Revo Uninstaller. DO NOT reinstall Chrome until I say so. Once it's been removed using Revo, do this:


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also, I want you to get rid of any old installation files for Google Chrome. When the time comes to reinstall, I will have you download fresh from our website.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To fully cleanup Chrome, you need to make sure both of the below are uninstalled:

    Google Chrome
    Google Update Helper

    Then you need to make sure that the folders from Chrome are deleted!!! I suggest that the below be deleted ( if they still exist ) and this must be done before ever reinstalling Chrome:

    C:\Users\Boris\AppData\Local\Google
    C:\Program Files (x86)\Google
     
    Last edited: Oct 1, 2014
  24. igrushka7

    igrushka7 Private E-2

    Hi Kestrel13! & chaslang.
    Thanks for your time.
    Just done everything suggested by you both.
    Let's hope for the best.
    Best regards
    Boris.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So do you still have any problems?
     
  26. igrushka7

    igrushka7 Private E-2

    Yes,
    the add-ons are still there. There are no traces of Chrome in the PC left ( I hope !).
    Where do the add-ons hide? Doesn't look like, does it?
    Best regards.
    Boris.
     
  27. igrushka7

    igrushka7 Private E-2

    Hi chaslang.
    Look what my grandson just found ! (Unfortunately, he only visiting here).
    Do you think I should create a restore point and delete the files, they are all there at the bottom of the screenshot ?
    Or what do you think ?
    They all attached to that " No Explorer " thing.
    See attached.
    Best regards,
    Boris.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BHO's are not all bad. There are thousands of them. Some good, some bad and some are somewhere in between and a matter of user preference.

    I noticed a few in your MGtools logs that no one had removed yet so let's just remove them. They are from 50CoupOens, TTubeeAdbiloecoker, Downloadd keeper, and saavE neT


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it, you must shutdown all browsers including this one you are reading in. After shutting down all browsers, double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now see what still appears in Internet Explorer. Also tell me are you running the 32 bit version or 64 bit version of IE?
     
  29. igrushka7

    igrushka7 Private E-2

    Hi chaslang.
    Yes, those four add-ons have gone. Thanks a lot.
    Only one have remained: it's the YoutubeAdbloker.
    Otherwise looks as the job is done.
    Could you send me another fixme.reg for this one, please.
    Thanks again.
    Boris.
    PS: My system is win7x64 pro, so I assume the IE11 is also 64 bits.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below should remove YoutubeAdblocker.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  31. igrushka7

    igrushka7 Private E-2

    Hi chaslang.

    Well you got them out.
    Thanks a looooot!
    And , yes I received a success message .
    Everything is OK now.
    Also, thank you Kestrel13! You really tried.
    Best regards.
    Boris.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  33. igrushka7

    igrushka7 Private E-2

    Hi chaslang.
    More thanks to you.
    Done it all.
    So far, so good.
    Best regards,
    Boris.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds