DownLoadNSave still there

Discussion in 'Malware Help (A Specialist Will Reply)' started by neversatisfied, Nov 5, 2012.

  1. neversatisfied

    neversatisfied Private E-2

    Hello,

    I have followed the directions in the READ/RUN ME thread and still have an issue.

    About 1-2 weeks ago I started seeing random words transformed into hyperlinks to little ad boxes appearing on many websites or some times just a line saying "ads by downloadnsave". I don't really do any risky stuff online so I'm not sure where this came from. There were also lots of stationary ad boxes from downloadnsave appearing on certain pages like youtube but those seem to be gone now.

    here are the logs
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the log from running MGTools.exe -- C:\MGLogs.zip.
     
  3. neversatisfied

    neversatisfied Private E-2

    Is this what you mean?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that's the file specified.

    Just an FYI. You picked this up from porn sites.

    Exit your Firefox browser ( it must be shutdown to do the below ) and use IE to read this:

    Navigate in Windows Explorer to the below file

    C:\Users\CouldBAny1\AppData\Roaming\Mozilla\Firefox\Profiles\y83npvu6.default/prefs.js


    Open this file in notepad and delete only the lines beginning with the below. I had to shorten them because they are very long lines. These should be line number 35, 36, and 37.

    user_pref("extensions.5072606b10d87.epoch", "1352255856");
    user_pref("extensions.5072606b10d87.scode", ..........
    user_pref("extensions.5072606b10d87.url"............

    After deleting only those lines, save the file.

    Then rerun Firefox and see if you still have a problem.
     
    Last edited by a moderator: Nov 7, 2012
  5. neversatisfied

    neversatisfied Private E-2

    Forgive me but I can't seem to figure out how to locate the file specified. There is no AppData folder in user CouldBAny1??? I must be looking in the wrong place. Also the hyperlinks are showing up in IE as well (I never use it so I hadn't noticed). Is this a problem associated only with certain browsers?

    As far as porn goes do you mean any/all porn sites? because (full disclosure) I have had a recurring membership to Videobox for over a year now and never had any problems with it. It's a business/pay site which I assume would be safe and clean. I don't really mess with anything else as far as that goes because I don't need to, and I know it's all poisonous.

    Two things I just recall that may have been mistakes on my part. About 9 months to a year ago I used a couple of youtube2MP3 converter websites that did look kind of sketchy with obnoxious ad banners and links every where but I got nervous about that and stopped using them. Never noticed any problems after that though.

    Also after watching the movie Dread I Did a google Image search for 1 of the actresses and did follow some of the links to the images but it was just the type of stuff you would find on IMDB not nude/porn type sites. And that was about 1-2 months ago and the hyperlink ads only showed up last week. Don't these type of problems show up as soon as you get infected??
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you installed a pop up blocker on your browsers?
     
  7. neversatisfied

    neversatisfied Private E-2

    Update-progress!

    I Did not have a pop up blocker on firefox so I added one, and then I checked the add-ons (should have done this at the start I know) and found DownloadNSave. So I deleted it and found the same add-on in IE but the options were disabled, so I located the file on the main drive and deleted that.

    Afterwards I was able to find and edit the file you said and things seem to good now, although downloadnsave is still listed in the IE add-ons tab under 'not available'. I can't seem to do any thing to it but IE seems clean now as well. Is this a remnant or whats left of the file?

    Anyways thank you very much for your help!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running CCleaner.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain =$149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds