Removing Deals4You from Vista

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by miscott57, Apr 9, 2014.

  1. miscott57

    miscott57 Private E-2

    Hey all
    I am in some serious need of removing a hijacker malware from my Vista Home Premium, I have a 64bit Toshiba Sattellite.
    The program in question is called deals4u :mad
    I saw another thread for removing it from windows7, but I don't know if it's the same procedure for vista home premium.
    I've tried uninstalling it using the uninstall exe from the deals4u website, didn't work after repeated attempts. Wrote to their customer support and they say they will uninstall it for me, but i have to let them have remote access to my computer? Would you do that? My computer has been having alot of problems since this program/infection was installed, mainly freezing up for minutes at a time. Quite often I have to restart it to get it going again.
    My spybot and malwarebytes can't find it either. :cry
    Is it possible to get rid of it with out allowing deals4u remote access to my computer? is there a malware program that will get rid of it?
    I'm not a computer geek by any stretch of the imagination, but I can follow instructions pretty well.
    Any help you can provide will be greatly appreciated.
    Mike
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. miscott57

    miscott57 Private E-2

    Thanks, I'll check it out this evening, and get back here if I have any questions.
    Thank You!
    Mike
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     
  5. miscott57

    miscott57 Private E-2

    Good Morning Kestrel13!
    Sorry it took so long. Sometines working nights really bites.
    Followed all the instructions to a T.
    Got everything downloaded. Ran the programs and saved the logs per instructions.
    After everything was finished, I went to ebay to see if those darn Deals4U pop-up windows were still there. Yep, Still there!
    Pretty sure I accidently let it install when I was installing a you tube downloader. Unfortunately, after running the 5 programs, it's still there.
    Hope you can help so I don't have to give them remote access to my computer so "they" can uninstall it. Don't know who "they" are, and don't trust them. Their uninstall exe doesn't, then they want you to let them into your computer? Don't think so. I'd rather do a complete system re-install, and that's a real pain
    I'm going to re-enable my user controls and re-hide the folders that are supposed to be, untill I hear back.
    Thanks so much for your help. Can't tell you how much I appreciate you giving your time and effort.
    Thank You!
    Michael
     

    Attached Files:

    Last edited: Apr 20, 2014
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Re run Hitman and have it remove everything EXCEPT for:

    • C:\Windows\System32\Future_City_3D_Screensaver.scr
    Which browser please?
     
  7. miscott57

    miscott57 Private E-2

    I use Firefox 99.999% of the time. IE is only there as emergency backup.
    When I re-run Hitman, I should have the hidden files and folders 'showing' again?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    They should be showing anyway. Yes have Hitman remove all those and then do this:

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except we will use Revo Uninstaller to uninstall it) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bookmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    ============

    Any better?
     
  9. miscott57

    miscott57 Private E-2

    Kestrel13!
    That got rid of it!! Thank you so much! Can't hardly believe those darn pop-ups are finally gone! Your a life saver!
    Do have a couple questions. I haven't used that you tube downloader since we started this process. It was a free trial that worked well enough that I got the paid version. If I use it now, do you think that the pop-ups will return, with the paid version? Just wondering. I'm gonna keep the HitMan and the RevoUninstaller to use if I ever need them again. It never occured to me that the bug was intertwined into my Firefox! Not only got rid of the bug, but the newer version of Firefox is pretty cool!
    Also, can/should I now remove the MGTools from my C:/ drive?
    Thanks for all your time and help!
    Greatly Appreciated!!
    Michael
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi! :)

    I am glad that did the trick for you.

    Final steps to come below at the end...

    For a youtube to mps software discussion thread see here.

    Alot of programs are advertising supported so you just have to be very careful during the installation process that no unwanted extra's make it thru.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds