TubeAudBlockker? PLEASE HELP!

Suddenly i began to get those small grenn boxes with a little arrow at the top on some speciel words… everytime i pointed on one a little ad popped up. then i went to Browser Cleaning and cleaned it and it says it was a succes… but it dosent look like it. It just keeps coming back, and its also an extension in my Chrome but cant remove with ANYTHING at all :frowning: ive tryed everything but nothing works. ive read that this is gonna do some baaad stuff to my pc but whatever i do with avast or anything else it just wont get removed. Please help me here, i really need the help.

Edit: also others call it stuff like TubeAdBlockeR and stuff like that. Also says The Configuration of your Google Chrome browser is damaged now…

can you attach a screenshot…

Sorry but how do i take a screenshot of it and how do i upload it?

g2g now but try and search it up… found some stuff about it on google.

search google for how to and/or youtube for how to do it video

then click Attachments and other options below the txt box you write in here

Everytime i try to remove it it says this… also looks like i removed the ads but the virus is still there.

And this in Chrome… Sorry but im Danish but in the right box i made it says: Installed by enterprise policy.

Ok now its getting scary :frowning: i went into programs and i uninstalled some stuff that had not been there a moment ago and one of them was called VIP acces SDK i think and when i uninstalled it it shut down my whole PC, so i just pressed the Shut down button on the my PC really fast so if it was the virus it couldnt do anything to my PC (I hope). Also the program had taken the picture of another program i had.

Hi there lets have a look

Download OTL to your Desktop
Secondary link

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif

[*]Select All Users
[]Select LOP and Purity
[
]Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT

[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

Heres the logs…

Let me know if this kills it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:Commands
[CREATERESTOREPOINT]

:OTL
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=141113&systemid=426&sr=0&q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=nv1&ir=nv1&cd=2XzuyEtN2Y1L1Qzu0EzztAzytAyDyEzz0EtA0FyE0DyBtB0AtN0D0Tzu0CtAyCtBtN1L2XzutBtFtBtFtCtFyEtDyB&cr=67230348
IE - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=nv1&ir=nv1&cd=2XzuyEtN2Y1L1Qzu0EzztAzytAyDyEzz0EtA0FyE0DyBtB0AtN0D0Tzu0CtAyCtBtN1L2XzutBtFtBtFtCtFyEtDyB&cr=67230348
IE - HKU\S-1-5-21-3179294234-38059543-2529484439-1000\..\URLSearchHook: {77f8c945-4b74-4bd6-a073-e0d1997edce8} - No CLSID value found
IE - HKU\S-1-5-21-3179294234-38059543-2529484439-1000\..\URLSearchHook: {cdf97ee2-ded0-4369-835e-99dd08225fa5} - No CLSID value found
IE - HKU\S-1-5-21-3179294234-38059543-2529484439-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=HitachiXHDS723015BLA642_MN1140F106K1ED06K1EDX&ts=1356707194
IE - HKU\S-1-5-21-3179294234-38059543-2529484439-1000\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=nv1&ir=nv1&cd=2XzuyEtN2Y1L1Qzu0EzztAzytAyDyEzz0EtA0FyE0DyBtB0AtN0D0Tzu0CtAyCtBtN1L2XzutBtFtBtFtCtFyEtDyB&cr=67230348
FF - prefs.js..CT2795622.browser.search.defaultthis.engineName: "true"
FF - prefs.js..CT3227975.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultthis.engineName: "midicair Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2795622&SearchSource=3&q={searchTerms}&CUI=UN42197556192094385"
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.580.182\{d1538445-ebd9-4c43-882a-854eff8d928c}\FirefoxExtension
[2013/02/12 14:59:13 | 000,002,325 | ---- | M] () -- C:\Users\Aske\AppData\Roaming\mozilla\firefox\profiles\gzfeddtd.default\searchplugins\Funmoods.xml
[2012/12/28 16:06:34 | 000,000,736 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml
O2:64bit: - BHO: (DiscountExxtensi) - {47200394-21B1-4D4E-B5F3-A44079747E27} - C:\ProgramData\DiscountExxtensi\zAdqxG.x64.dll ()
O2:64bit: - BHO: (TubeAudblockker) - {FC469B14-A9D9-FFF0-1153-D124381894A6} - C:\ProgramData\TubeAudblockker\fjLl5A_sJ.x64.dll ()
O2 - BHO: (no name) - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {af6ac4f2-9825-4fb6-a600-92bc5361f209} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O20 - AppInit_DLLs: (xxc:\progra~3\browse~1\22580~1.182\{d1538~1\brwmngr.dll) - File not found
[2014/03/07 19:53:28 | 000,000,000 | ---D | C] -- C:\ProgramData\DiscountExxtensi
[2014/03/13 17:09:30 | 000,034,358 | ---- | M] () -- C:\END
[2013/08/12 16:41:17 | 000,000,000 | ---D | M] -- C:\Users\Aske\AppData\Roaming\Awesomium
[2013/10/15 15:10:38 | 000,000,000 | ---D | M] -- C:\Users\Aske\AppData\Roaming\Babylon
[2012/12/28 11:42:34 | 000,000,000 | ---D | M] -- C:\Users\Aske\AppData\Roaming\Funmoods

:Files
C:\Program Files (x86)\VideoScavenger_1e
C:\ProgramData\Browser Manager
C:\ProgramData\TubeAudblockker

:Commands
[resethosts]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

By reboot do you mean restart?

Yes restart :slight_smile:

Suddenly it came with an error saying that it could not create some weird file in Mozilla Firefox folder called something really weird… after that the fix just froze and havent done anything since that.

Edit: Remember that the next replys is on next page :wink: just a reminder.

Was that OTL ? If so reboot please and run AdwCleaner

will do

Ok i rebooted and when it started OTL asked for Permissions to start. i clicked yes and it created this file straight away…

OK it did not get it all but Adwcleaner will :slight_smile:

Ok i runned AdwCleaner and it made this file after reboot…

How is the computer behaving now ? Any problems