Results 1 to 8 of 8

Thread: Remove GoSavEE 2.0 - GoSave, ads by GoSave and other rubbish spam, malware.

  1. #1
    Gav
    Gav is offline
    Administrator Gav's Avatar
    Join Date
    Jun 2012
    Location
    From Newcastle
    Posts
    8,420
    Blog Entries
    2

    Remove GoSavEE 2.0 - GoSave, ads by GoSave and other rubbish spam, malware.

    First off start with installing the free and wonderful malwarebytes, this software is a great one to help get rid of rubbish software.

    https://www.malwarebytes.org/

    however, this was not enough for me, I kept getting the rubbish plugin every time I started Google Chorme and I went through removing the plugin trying other spamware removal software and the like with no luck. I went through REGEDIT.exe and removed all mentions of the software and other such software that I could find duplicate names for it, restarted, ran more virus removal software and nothing found it.

    Eventually I found it lurking in the Chrome Extensions:

    C:\Users\Administrator\AppData\Local\Google\Chrome \User Data\Default\Extensions\cjdlplnmlladcdfkljjblbjlfl dfengc\2.0

    Also look in:
    C:\Users\USER NAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjdlplnmlladcdfkljjblbjlfl dfengc\2.0

    C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions


    If you use more than one browser make sure you check in

    C:\Users\USER NAME\AppData\Local\
    C:\Users\Administrator\AppData\Local\


    At the time of writing this: I haven't done a restart after removing it yet as I wanted to get this post added with the address of where I found it first with the address on the computer I found it.

    I have also found it in the Torch browser:
    C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\cjdlplnmlladcdfkljjblbjlfl dfengc
    C:\Users\USER NAME\AppData\Local\Torch\User Data\Default\Extensions\

    Comodo Dragon:
    C:\Users\Administrator\AppData\Local\Comodo\Dragon \User Data\Default\Extensions\cjdlplnmlladcdfkljjblbjlfl dfengc

    Chromatic Browser:
    C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions

    Mine folders were all called: cjdlplnmlladcdfkljjblbjlfldfengc if you get a different folder name do let us know, as really is an awful piece of software.



  2. #2
    Gav
    Gav is offline
    Administrator Gav's Avatar
    Join Date
    Jun 2012
    Location
    From Newcastle
    Posts
    8,420
    Blog Entries
    2
    There will be files background.html Which has:

    Code:
    <!doctype html><html><head><title>Background</title><script src="RvpSSY.js"></script><script src="lsdb.js"></script></head><body></body></html>
    Content.js
    lsdb.js
    RvpSSY.js

    and manifest.json searching for text in these may help you get find it hidden in other places.
    Code:
    {  "name": "GoSavEE",
      "version": "2.0",
      "description": "",
      "manifest_version": 2,
      "background": {"page": "background.html"},
      "content_scripts": [
        {
            "all_frames": true,
            "matches": ["http://*/*","https://*/*"],
            "js": ["content.js"],
            "run_at":"document_end"
        }
      ],
      
      "permissions": [
        "http://*/*",
        "https://*/*",
        "tabs",
        "cookies",
        "management",
        "notifications",
        "contextMenus",
        "management",
        "storage"
      ]
    }

  3. #3
    Gav
    Gav is offline
    Administrator Gav's Avatar
    Join Date
    Jun 2012
    Location
    From Newcastle
    Posts
    8,420
    Blog Entries
    2
    This website is a great help for the problem although they're doing it for the virus called YoutubeAdBlocker it can help with GoSave and GoSavEE 2.0 this is for Chrome:

    Remove "Installed by Enterprise Policy" Google Chrome extension

  4. #4
    Gav
    Gav is offline
    Administrator Gav's Avatar
    Join Date
    Jun 2012
    Location
    From Newcastle
    Posts
    8,420
    Blog Entries
    2
    After a restart it's all gone, the browsing speed and computer speed seemed to improved dramatically, I do wonder what data GoSave / GoSavEE 2.0 was gathering as it slowed things right down!

  5. #5
    Senior Member DealDude's Avatar
    Join Date
    Aug 2012
    Location
    Sydney Oz
    Posts
    2,258
    Sounds like a nasty virus Gav, how do you get all these?

  6. #6
    Senior Member DealDude's Avatar
    Join Date
    Aug 2012
    Location
    Sydney Oz
    Posts
    2,258
    Just had a look around about this Virus and might be worth checking your system for it's other names:

    GoSave, GoSaave, YoutubEAdBloCke, GS_Booster and GS_Sustainer

    Hope you've got rid of it all!!

  7. #7
    Administrator fool's Avatar
    Join Date
    Jul 2012
    Location
    Newcastle
    Posts
    17,312
    Wow, that sounds pretty annoying, I haven't had a single problem since going to Windows 8 I only run defender now, I still scan with Spybot but it never finds anything.
    Used to get quite a few viruses with XP.

  8. #8
    Gav
    Gav is offline
    Administrator Gav's Avatar
    Join Date
    Jun 2012
    Location
    From Newcastle
    Posts
    8,420
    Blog Entries
    2
    I haven't had many with Windows 8.1, they've all been bundled in with free ware that i've been testing for friends to see if it's safe for them to use, as I know I'll just end up having to clean their computers if they install it. Very generous!


Similar Threads

  1. Sensor Rubbish Bin - $29.99 at 1-Day
    By fool in forum Homewares
    Replies: 0
    Last Post: 15-06-2014, 10:03 PM
  2. Replies: 0
    Last Post: 21-01-2014, 09:12 AM
  3. Toys R Us Australia email spam.
    By Gav in forum General Chat
    Replies: 2
    Last Post: 17-10-2013, 10:41 PM
  4. Replies: 0
    Last Post: 05-07-2013, 11:14 AM
  5. Replies: 0
    Last Post: 02-09-2012, 09:52 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
share this page


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129