Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

vGrabber removal


  • Please log in to reply
26 replies to this topic

#1 borlou11

borlou11

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 19 January 2014 - 09:30 PM

Hello,

 

I have a program "vGrabber-software" and I cannot remove it.

I tried to remove it from the Control Panel but cannot find it there.

I tried to remove it through START-PROGRAMS-VIDEO DOWNLOADER (located under vGrabber) - UNISTALL. No change.

I tried through your tutorial "4 simple steps for removing spyware, hijackers, viruses and other malware". Since I have already ESET NOD32, I used online virus scans "Trend Micros's Housecall" and "Dr Web's Cureit". Then I performed scans with "MalwareBytes Anti-Malware" and "SuperAntiSpyware". And I still have "vGrabber-software" under C:\Program Files. I am reluctant to do a direct manuel removal.

My computer is a Windows XP.

Any help would be appreciated.



BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 19 January 2014 - 10:42 PM

And I still have "vGrabber-software" under C:\Program Files

 

If this is the only occurrence of vGrabber you can safely delete that folder.

If it shows up somewhere else as well let me know.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 19 January 2014 - 11:34 PM

I made a search in C: and the following 2 results  came up:

1. Name: vGrabber-software 

    In folder: C:\Program Files

2. Name: Vgrabber_v1.5AutoUpdateHelper

    In folder: Documents and Setting/Owner/Local Settings/Application Data/Conduit/CT3293216

Do I flush them both manually ?


Edited by borlou11, 19 January 2014 - 11:35 PM.


#4 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 19 January 2014 - 11:39 PM

Let's see if couple of garbage cleaners will find those and more....

 

p22002970.gif Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

 

p22002970.gif Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#5 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 20 January 2014 - 12:05 AM

When I clicked on your AdwCleaner, it brougth me to a blank page. So I downloaded through BleepingComputer and here are the results:

 

# AdwCleaner v3.017 - Report created 19/01/2014 at 23:50:09
# Updated 12/01/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Owner - BORIS-9E7B25E3D
# Running from : C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\EWHH0RLS\AdwCleaner[1].exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask
Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\All Users\Application Data\NCH Software
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\NCH Software
Folder Deleted : C:\Program Files\Searchprotect
Folder Deleted : C:\Program Files\TelevisionFanaticEI
Folder Deleted : C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}
Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\NativeMessaging
Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\PackageAware
Folder Deleted : C:\DOCUME~1\Owner\LOCALS~1\Temp\boost_interprocess
Folder Deleted : C:\Documents and Settings\Owner\Application Data\NCH Software
Folder Deleted : C:\Documents and Settings\Owner\Application Data\registry mechanic
Folder Deleted : C:\Documents and Settings\Owner\Start Menu\Programs\Video downloader
File Deleted : C:\DOCUME~1\Owner\LOCALS~1\Temp\Uninstall.exe

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3293216
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\NCH Software
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\Software\NCH Software
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Video downloader
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

-\\ Google Chrome v32.0.1700.76

[ File : C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

*************************

AdwCleaner[R0].txt - [7612 octets] - [19/01/2014 23:48:13]
AdwCleaner[S0].txt - [7715 octets] - [19/01/2014 23:50:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7775 octets] ##########

 

The next assignment will be following tomorrow morning.



#6 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 20 January 2014 - 08:40 AM

Good Morning !

Please find the second assignment  enclosed:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Microsoft Windows XP x86
Ran by Owner on 20/01/2014 at  0:13:27.93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL

 

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"

 

~~~ Files

Successfully deleted: [File] C:\WINDOWS\Tasks\regwork.job
Successfully deleted: [File] C:\WINDOWS\Tasks\rmschedule.job

 

~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\regwork"
Successfully deleted: [Folder] "C:\Documents and Settings\Owner\Local Settings\Application Data\cre"
Successfully deleted: [Folder] "C:\Program Files\regwork"

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20/01/2014 at  0:16:44.14
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

I made a new search on C:\  and found again the two items I mentionned before:

vGrabber-software

Vgrabber_v1.5AutoUpdateHelper

 

What do you suggest to do next ?



#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 20 January 2014 - 03:07 PM

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

64-bit users go HERE

  • Double-click SystemLook.exe to run it.
  • Vista users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following box and paste it into the main textfield:

:filefind
vGrabber*
:folderfind
vGrabber*
:regfind
vGrabber*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#8 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 20 January 2014 - 04:08 PM

I tried SystemLook(1).exe and SystemLook(2).exe and each time I got an error message from Microsoft: "SystemLook(1).exe has encountered a problem and needs to close. We are sorry for the inconvenience"
I made a printscreen of the report, but I cannot find how to post it.

You will find the result of the whatever scan SystemLook did:

 

 

SystemLook 30.07.11 by jpshortstuff
Log created at 15:38 on 20/01/2014 by Owner
Administrator - Elevation successful

========== filefind ==========

Searching for "vGrabber*"
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\38QIEYXO\vgrabber-removal[1].htm --a---- 110315 bytes [20:20 20/01/2014] [20:20 20/01/2014] FFB2A02268F790A8A3894F91C7139C94
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\3MHZ43FO\vgrabber-removal[1].htm --a---- 95964 bytes [05:06 20/01/2014] [05:06 20/01/2014] 08CE47B7ED761200060D1E547ABC4D37

========== folderfind ==========

Searching for "vGrabber*"
C:\Program Files\vGrabber-software d------ [02:26 09/08/2013]

========== regfind ==========

Searching for "vGrabber*"

 



#9 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 20 January 2014 - 05:53 PM

Try to re-run it from safe mode.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#10 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 20 January 2014 - 08:33 PM

As suggested, I went in Safe Mode. Tried SystemLook and got the same message from Microsoft.

Then, I tried SystemLook by type of "find". With "filefind", it went smoothly. With "folderfind", again it was ok. But with "regfind" that is where I crashed  and got another message from Microsoft.

Here is the text from SystemLook log:

 

SystemLook 30.07.11 by jpshortstuff
Log created at 19:59 on 20/01/2014 by Owner
Administrator - Elevation successful

========== filefind ==========

Searching for "vGrabber*"
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\3MHZ43FO\vgrabber-removal[1].htm --a---- 95964 bytes [05:06 20/01/2014] [05:06 20/01/2014] 08CE47B7ED761200060D1E547ABC4D37

-= EOF =-

SystemLook 30.07.11 by jpshortstuff
Log created at 20:04 on 20/01/2014 by Owner
Administrator - Elevation successful

========== folderfind ==========

Searching for "vGrabber*"
C:\Program Files\vGrabber-software d------ [02:26 09/08/2013]

-= EOF =-

SystemLook 30.07.11 by jpshortstuff
Log created at 20:07 on 20/01/2014 by Owner
Administrator - Elevation successful

========== regfind ==========

Searching for "vGrabber*"



#11 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 20 January 2014 - 08:38 PM

OK.

 

Remove following folder manually:

 

C:\Program Files\vGrabber-software

 

You should be good to go.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#12 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 20 January 2014 - 09:35 PM

Done for C:\Program Files\vGrabber-software!

 

What about : "Vgrabber_v1.5AutoUpdateHelper" ?

 

Do I also remove ?

SystemLook and log

JRT log

SuperAntiSpyware



#13 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 20 January 2014 - 09:43 PM

You can delete SystemLook and log.

Keep the others for future use.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#14 borlou11

borlou11
  • Topic Starter

  • Members
  • 54 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, Quebec, Canada
  • Local time:05:21 AM

Posted 20 January 2014 - 09:51 PM

I just made a seach for "Vgrabber_v1.5AutoUpdateHelper"  and it came up again ???



#15 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,679 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:21 AM

Posted 20 January 2014 - 09:54 PM

Where exactly is it located?


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users