NewSaver malware re-enabling itself after uninstallation and deletion of files.

swedishswede

Estimable
Jul 15, 2014
1
0
4,510
Yesterday, 12 December, 2014, NewSaver was somehow downloaded onto my computer. I turned on my laptop, and the second I went onto Chrome I saw Ads and pop-ups. I looked in my Control Panel and saw that it had been installed this day, even though I haven't installed anything in the last week. I followed my routine and disabled the extension, uninstalled the malware from Control Panel, and deleted the files from Programs. But everytime I launch Chrome the adware has re-enabled itself. I am going to run a full hardware scan, but any help would be appreciated.
 
Solution
I think you will need to do more than just deleting the files of the adware/malware.
First boot into safemode without networking and run roguekiller this will freeze the edits in registry and will also disable any services that are allowing it to comeback
second run the super anti spyware removal tool in normal mode
run malwarbytes anti malware if it doesn't find anything try bit defender
fourth run CCleaner.

After each of these finishes up reboot your computer

Just to polish everything off run http://www.bleepingcomputer.com/download/adwcleaner/

This should clean your system. Remember to run Ccleaner twice for registry, one time normally isn't enough.

Just make sure you also have all restore points removed also. Even if the...

lfkfkfkffs

Estimable
Apr 2, 2014
37
0
4,610
I think you will need to do more than just deleting the files of the adware/malware.
First boot into safemode without networking and run roguekiller this will freeze the edits in registry and will also disable any services that are allowing it to comeback
second run the super anti spyware removal tool in normal mode
run malwarbytes anti malware if it doesn't find anything try bit defender
fourth run CCleaner.

After each of these finishes up reboot your computer

Just to polish everything off run http://www.bleepingcomputer.com/download/adwcleaner/

This should clean your system. Remember to run Ccleaner twice for registry, one time normally isn't enough.

Just make sure you also have all restore points removed also. Even if the first two steps fixes your problem I would still run these other tools and steps. You can manually delete the .exe and adware but thanks to the registry it can resurrect itself once you delete it since it uses the buddy system.
 
Solution