Solved 'Sauve, on' extension keeps reappearing on chrome

Marumarsu

New Member
Thread author
Jul 11, 2014
2
I don't know how long the extension has been on the list, but as of yesterday chrome keeps notifying me about developer extensions being on use every time i open the browser. Whether i click on the disable or close button the Sauve, on extension reappears at the top of the list even after i've deleted it before.

This might be nothing, but at the time when i found out about the extension and tried to delete it i got a popup that gave me a 671kb file named download(I didn't run it). It has 10 lines of js, i don't know js syntax but some of the commands sound very suspicious. the entirety of the file ran in notepad++ is:

Code:
<!DOCTYPE html>
<html>
<body onload="window.location.href='[URL='http://omptrendo.s3-website-eu-west-1.amazonaws.com/index2.html?__ipu=1'][COLOR=#ffffff]http://omptrendo.s3-website-eu-west-1.amazonaws.com/index2.html?__ipu=1[/COLOR][/URL]'">
<script type="text/javascript">
    var ua = '';
    if(ua.match(/^UA\-\d{4,10}(\-\d{1,4})?$/))
    {
        var _gaq = _gaq || [];
        _gaq.push(['_setAccount', ua]);
        _gaq.push(['_trackPageview']);


        (function() {
            var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
            ga.src = ('https:' == document.location.protocol ? '[URL='https://ssl'][COLOR=#ffffff]https://ssl[/COLOR][/URL]' : '[URL='http://www'][COLOR=#ffffff]http://www[/COLOR][/URL]') + '.google-analytics.com/ga.js';
            var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
        })();
    }
</script>
</body>
</html>
 

Attachments

  • AdwCleaner[R2].txt
    5.1 KB · Views: 97
  • FRST.txt
    77.2 KB · Views: 170
  • Addition.txt
    64.4 KB · Views: 224
Last edited by a moderator:

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


Before we start please note the following:

icon_arrow.gif
Analysis and research take some time, also sometimes real life gets in the way, please be patient.
icon_arrow.gif
Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
icon_arrow.gif
Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
icon_arrow.gif
Do not paste the logs in your posts, attachments make my work easier. There is a Upload a File button which you can use to attach your reports. Attach all reports.
icon_arrow.gif
Stay with me to the end, the absence of symptoms doesn't mean that your machine is fully operational.
icon_arrow.gif
Note that we may live in totally different time zones, what may cause some delays between answers.

icon_idea.gif
I can't foresee everything, so if anything unexpected happens, please stop and inform me!
icon_idea.gif
There are no silly questions. Never be afraid to ask if in doubt!




FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.





Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • After the scan has finished click on the Clean button.

Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Post logfile will also be saved in the C:\AdwCleaner folder.




51a46ae42d560-malwarebytes_anti_malware.png
Scan with Malwarebytes' Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Install the progam and select update.
  • Once updated, click the Settings tab, in the left panel choose Detctions & protection and tick Scan for rootkits.
  • Click the Scan tab, choose Threat Scan is checked and click Scan Now.
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • At the bottom click Export and choose Text file.
Save the file to your desktop and include its content in your next reply.
 

Attachments

  • fixlist.txt
    4.8 KB · Views: 133
  • Like
Reactions: Oxygen

Marumarsu

New Member
Thread author
Jul 11, 2014
2
Thanks for the reply! The extension doesn't come up any more after i used the adwcleaner and the fixlist. Seems at first i somehow didn't see that there are multiple tabs for other categories in adwcleaner leading me not to run the clean option before, a foolish mistake. I've added the files as an attachments nevertheless for reference or/if you want to take a look at them. (Malwarebytes crashes when trying to export the txt file)

Thank you!
 

Attachments

  • Fixlog.txt
    10 KB · Views: 109
  • AdwCleaner[S0].txt
    5.3 KB · Views: 121

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Good, then we're done here :)


For future protection I can recommend you:
- Adblock --> https://adblockplus.org/en/chrome
- Unchecky --> http://unchecky.com/


Something to read --> Simple and easy ways to keep your computer safe and secure on the Internet



The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
checkmark.png
Remove disinfection tools
checkmark.png
Create registry backup
checkmark.png
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 
  • Like
Reactions: Oxygen

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top