can't remove DodoIneptus

Status
Not open for further replies.

dsweetay

New Member
Thread author
Dec 29, 2023
3
I'm infected with the DodoIneptus extension in both Chrome and Edge. I've followed the instructions on the MalwareTips blog page, including running ESET. I don't seem to have problems running Chrome Incognito, but the extension is still listed and active in both browsers.

I'm also having difficulty downloading FRST. I'm being denied access by bleepingcomputer.com, error 1008 both in and out of Incognito mode.

I've attached the log from ESET and Rkill and a screenshot of what MalwareBytes removed.

Thanks in advance
 

Attachments

  • esetscanlog.txt
    268 bytes · Views: 2
  • Rkill.txt
    2 KB · Views: 3
  • MalwareBytesDetectionHistory.jpg
    MalwareBytesDetectionHistory.jpg
    55.8 KB · Views: 2

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

In order to give you sound advice I need more information.

Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Ensure that you are in an Administrator Account
Double-click to run it. When the tool opens click Yes to disclaimer.
Check the boxes as seen here:
https://i.imgur.com/L7kNU5y.jpg
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Please attach the logs for my review.
How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
[img=[URL]http://deeprybka.trojaner-board.de/eset/eng/attachlogs.png[/URL]]

Let me know what problems persists.

Wait for further instructions

p.s.
This program is updated often.
If it's identified as suspicious by your Anti-Virus program trust it if Downloaded from the link I provided.
OR, you should restore the program from the Quarantine folder.
====
 

dsweetay

New Member
Thread author
Dec 29, 2023
3
Here are the logs.

another symptom- tried to turn off my McAfee VPN before downloading FRST, since I was blocked from the website yesterday. McAfee would not allow me to turn off the VPN- it said only an administrator can. However since this is my personal computer and I'm the only user I am the admin. checked in Windows settings and I'm still identified as and administrator.
 

Attachments

  • Addition.txt
    39.4 KB · Views: 3
  • FRST.txt
    48.2 KB · Views: 4

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • Fixlist.txt
    2.6 KB · Views: 5

dsweetay

New Member
Thread author
Dec 29, 2023
3
The extension has been removed and everything seems to be working fine.

Thanks so much for your time, especially on a holiday weekend!
 

Attachments

  • Fixlog.txt
    17.5 KB · Views: 2
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top