RemoivETheAdAppp 3.5 - The most stubborn virus I know!

Hi,

Have had a problem for probably close to 3 weeks with stuttering (especially music on itunes and videos on the net) thought it was my virtual memory so increased it but the stuttering returned.

Then I realised every time I tried to log into a legitimate website, I was getting redirected to malicious sites wanting me to participate in surveys and it twigged the computer was infected howerver, my AVAST software had not detected or reacted to the virus.

I have since run several full scans using my paid AVAST subscription to no avail. I have also run 3 anti-malware programs recommended by friends and on other malware websites including adwcleaner (about 3 times), ad-aware (once) and most recently, malware bytes (twice)… Again, they pick up suspect files and quarantine them but this virus remains unaffected and continues to reek it’s havoc on my browsing and internet usage.

I can see an extension in Google Chrome which I am sure is linked to t his virus but I cannot remove it and none of the antivirus software I have used have been able to remove it either.

The Malware Bytes software I am currently running is however, picking up and blocking the redirections when they occur (which is more than AVAST was doing!!).

I really just want to clear my PC of this malicious infection as soon as possible! It’s very stubborn and there isn’t much about it on the internet at large and it’s obviously quite new as there aren’t very many effective fixes out there as of yet!

Can someone help with this?

I’ve attached a copy of my extensions list in Google Chrome so you can see what I see in terms of the extension…

Intel operating system with 4.00GB ram
64 bit
Running Windows 7 Professional, service pack 1.

I have found some further info which may or may not be useful.

In desperation, I uninstalled Google Chrome and reverted to Internet Explorer as the default web browser, I then clicked on the settings to explore add-ons within Explorer and found I could access more info on the 2 unwanted programs… (Yes, I found another one when checking my installed programs list).

I’ve included screenshots of what Explorer had identified regarding these programs, see below.

In Explorer, I was able to disable the RemoivETheAdAppp add-on but not the allcheapprice add-on.
In Chrome I was able to delete the AllcheApPricE extension early on but not the RemoivETheAdAppp extension…

Also, AllCheApPricE appears as a program in my programs list but when I click to uninstall, it says it has been uninstalled or no longer exists. When I search for the related files etc, none exist except in the form of notes saying the program has been quarantined… If it’s quarantined, why is it still enabled in explorer? And why is it still appearing in my programs list???

In regards to the RemoiveTheAdAppp files, I managed to locate them manually and send them to recycling but whether this means I have eliminated the problem is anyone’s guess… I can’t imagine with all the difficulty I’ve had that it would be as easy as that!

The RemoivETheAdAppp extension has gone from Google Chrome since uninstalling it but is still present in the Internet Exlorer add-ons list.

I could really use some assistance :frowning:

Hi,

Please download zoek.zip or zoek.rar by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers
[*]Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool .
Please wait for the tool to start…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

createsrpoint;
gpt.ini;z 
C:\Windows\System32\GroupPolicy;v
C:\Windows\SysWOW64\GroupPolicy;v 
StandardSearch; 
emptyfolderscheck; 
installer-list; 
installedprogs; 
uninstall-list;

[*]Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

Here it is.

Re-run Zoek once more with this script:

C:\Windows\System32\GroupPolicy\gpt.ini;f
C:\Windows\SysWOW64\GroupPolicy\gpt.ini;f
C:\Windows\System32\GroupPolicy\Machine;fs
C:\Windows\System32\GroupPolicy\User;fs
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r
"AppInit_DLLs"="c:\\progra~2\\citrix\\icacli~1\\rshook.dll";r
c:\\progra~2\\gssupp~1\\assist~1.dll;f
omcgihjdbnmggijdfijcpkmdbecmcido;chr
bffmoknhemiciipapimmlcmmndonoekg;chr
midocgecopimdncocioehdpokjphdjdp;chr
emptyfolderscheck;delete
ipconfig /flushdns;b
autoclean;
emptyalltemp;
emptyclsid;

Sorry for the delay! Here are the next lot of results…

How is the situation now?