Exterminate It! Antimalware

malpedia

Known threats:699,742 Last Update:October 27, 11:19

Testimonials

exterminate it remove the agent.nbo files without restart. i let it scan again, nothing found! great job!

now i surf since 5 minutes, no popups, it looks like the problem is solved!

big thanks to you and your team, you are the only company that give me response and realy help to remove this bad worm/malware!

i will place now links to our network to your homepage and email my friends and business partners that they know that there is a realy good company with a great tool and good programmers.

thanks.

regards,

m. s.

File: chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage

Location of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage and Associated Malware

Check whether chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage is present in the following locations:

Windows 2000, Windows XP, Windows Server 2003 specific chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage file locations:

  • C:\Documents And Settings\USER_NAME\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage
  • C:\Documents And Settings\USER_NAME\Local Settings\Application Data\Google\Chrome\User Data\ChromeDefaultData\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage
  • C:\Documents And Settings\USER_NAME\Local Settings\Application Data\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage

Windows Vista, Windows Server 2008, Windows 7, Windows 8 specific chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage file locations:

  • C:\Users\USER_NAME\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage
  • C:\Users\USER_NAME\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage
  • C:\Users\USER_NAME\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage

If you find chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage file in any of these locations, your computer is very likely to be infected with the following malware:

IMPORTANT: Malware files can be camouflaged with the same file names as legitimate files. The chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage file is associated with malware only if found in the locations listed above.

Notes:

Different Variations of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage File^

File SizeFile Md5Last Seen
30729C3794BD9F8D98E8E6F49D049E7F9E13Jun 16, 2014
2048090C85D177EC81A7E5B17192C82AFBDA4Jun 16, 2014
174087FD7F2983E7D72D558495ACD92D9DAB0Jun 22, 2014
1433684ABCE4D98CF9D79AE929BF4F3A26C04Jun 24, 2014
14336E6D8024F7ABA888ACAA091D2BE72BE27Jun 24, 2014
378886741F6C00B1AE1F26155784CB6DCD120Jun 25, 2014
174084F56561FF4A901010850D03FB4DB1BE9Jun 26, 2014
18432F2AF4D0D727064B4ACB8D7AD67B8BEF5Jun 27, 2014
14336E1DE3CD4081C65A99B4F9EDC961DF2EBJun 27, 2014
9216E1C7762CB0E4E68E428A3A64A1987A81Jun 29, 2014
37888BCBCEC74D037B38373759323B6D2EC90Jun 29, 2014
1536074B3BFDF412623F73C87C7D07812103FJun 30, 2014
17408A80F394C5C0438C95191FE60C6969FC4Jun 30, 2014
3072D59DEC6B6705A8E4B8259E24422C1D98Jun 30, 2014
15360CC05BEA64ACC4369ACF9347E8B888BB7Jul 2, 2014
307200704560494CFDD29FE73CFBBA325D0DJul 2, 2014
25600584EA05D0A813346182BD86EE056ABBFJul 5, 2014
30724A716EEDAB21980ABDA9D000BC668DF4Jul 6, 2014
14336FF28C3104B797BADDD99F58764B66BC7Jul 6, 2014
9216677BE16AF96BA59149E029C864B4A4E5Jul 6, 2014
24576916F34722B2F3A45AA78E28C4F2E395FJul 8, 2014
14336FCA5F65F96431E12A946FC1E3D61DA03Jul 8, 2014
30728B27A0F825F956403C2FCE8541CFB798Jul 8, 2014
14336259EB03141CB7CFE8CAB217085E560D4Jul 8, 2014
30727D056F57EA7BD56FEAEF6CE06F885BFCJul 9, 2014
3072BBF3E55DEBE5C40137E23610CF725BE8Jul 11, 2014
194566EEFA359B61636AF0C5121EEFAD62416Jul 11, 2014
1740852F6685333DF43AD289CAF9684170DE3Jul 11, 2014
368647473EF4CE78BBCF1F38864BA21811FBBJul 12, 2014
3072FC5F6FF09322E42CE5F5AE152E7AE1D6Jul 12, 2014
1740882D93EEBDB9A2142A5AC0D62407FA456Jul 13, 2014
15360260420F839DF5DB6C2C92568B5A229E5Jul 26, 2014
3072D8A1FE0CD4A6A195C5C544BDAA27B053Jul 26, 2014
3072F82A99CF8EBB920049910D5DDFAA8EB3Jul 26, 2014
3072BAF0912715D58E0A38E41C56854A257EJul 28, 2014
30722D5954458D052CF13BB36790EC40C1F9Jul 29, 2014
1331239FF0030BF1818C0ECD06F03B741B5F9Jul 29, 2014
1433682E01BEE57B0726D81BDA7C573C62358Jul 29, 2014
1331274D2D5266B839FF4DC335A55256FACB7Jul 31, 2014
14336D11B69A1ECBAF5152A587D30FDE7FD28Aug 4, 2014
3072CB239FA14B3D22867F99827E7D4FEE3EAug 4, 2014
15360B04B2C31533431962B8C06F3EEBD0C7DAug 4, 2014
2252825CFF107546191E89EBEEA9DA657F8ADAug 4, 2014
1331205B190F8110187BD3D82202F4677518FAug 5, 2014
3072D24626E71A4BD37E7592E18A9A98C70EAug 6, 2014
30722404B8648C364D0438F8F9EBD8ECF23DAug 6, 2014
15360341AF59F81D65CC208CB6F1A085D0E7AAug 6, 2014
184327C049FC86C4611FC1E942DDE63B725E9Aug 7, 2014
30725E70C005EF225E133BDFE5F381B5EF2FAug 7, 2014
38912A3D5B4422B70BBEC175C2009661112C3Aug 7, 2014
256007979E4BFFD11D4C0947CD9910E9796B8Aug 9, 2014
3072A75EC0F44186E10ED31416A67C1B4355Aug 10, 2014
1433663C22698D2FA1C68012F70A258842102Aug 11, 2014
225284F1C6B5AEB8C9E32BA92FB834B4CF44BAug 12, 2014
3072050E9F0CDBA76E0646480D45211A6910Aug 12, 2014
30726EE522B323B056A2F223D7DBE0C80999Aug 13, 2014
3072BFF378EADD0CB592EE93EF306B14C70AAug 17, 2014
143365F28E1B9414FD6A32656F91E977703EDAug 18, 2014
30726D02DC03F08FA9461A3BA19A7D93363EAug 18, 2014
30722FB8E5B92E7D1336C44877D8DBCC1D98Aug 19, 2014
1536096F3EDAAAF0FEB65605EF9EE82449446Aug 26, 2014
30720CA9043AF29EB3CB8F0ED3B7A44F2F23Aug 26, 2014
1331202C6431B0B8190230E06B32EA5A84223Aug 26, 2014
12288301E97ECD7072C4C4B2912874837053DAug 27, 2014
307205F4A981AE50E02B266E186DB913CAC3Aug 27, 2014
552968F48F315FDFA626F98FEDFDB29F0BFA7Aug 27, 2014
39936DCAFDF0047454F563E3D254B4FF190AFAug 30, 2014
15360150B2BA8204123C882804BEBB58A2D1FAug 31, 2014
30724FF6F32674612A87A9C17866170279BDSep 2, 2014
399362B60A94BAA49A3A22CEE94F32E92177ESep 3, 2014
30723B590B7CAF9B9FFD4607396411638570Sep 8, 2014
143366CC6506D73A75DB7CB6B2FA22A9FDDCFSep 9, 2014
696325D47B79FF3AFDE337172078AF5431E32Sep 15, 2014
307225CF21AFA1C95C2E0BF7CF2741F15445Sep 16, 2014
3072B15EC90DEF7A3B53EF33AE8A2A0CF2D0Sep 18, 2014
133126E7ED7BF8586B7202CFC59D2F7E6DBD2Sep 18, 2014
542725B23C917D2CD7A75AE70C047D510EED4Sep 18, 2014
38912D648051A83B656C77C2B270DEBC77509Sep 19, 2014
14336CCA9F578116E67892C4ACACF993729B1Sep 19, 2014
64512ABBED49EB7CEEFF418F2556210AECC62Sep 19, 2014
3072FE0A4BEF3FA9D60430B0C64D716D7F3ESep 22, 2014
624649BB4CC57B7ED55DA5947D091141AD1B4Sep 23, 2014
3072BDCAD31971972D73D3018D8322D42037Sep 23, 2014
78848863784B218307597F97E1A0EE6C31F0BSep 23, 2014
3072EA15F83B4292D6C0A764B81CD2A313B7Oct 16, 2014
337920E391CF4F6FBE0DAB6984875AACF7124Oct 21, 2014
3072F053981D3557FE47B11C06135AAF1F6FOct 26, 2014
143360EF5EB700DDC7ED24BF36B8849529FE9Oct 27, 2014
614407EC50B7AC29E76F6D430EE556F79DBE4Oct 27, 2014
5836867F46A8A5B373DAB82EB5C9FB1B4CAC1Oct 28, 2014
1433688E600608043ECE514C8445B0C66467EOct 29, 2014
47104005FA22621BB45CD1344471C984D221AOct 29, 2014
38912F47816680565634CB0CB4F83C7ADF94BNov 1, 2014
3072CD73195D86F254C522EFD9E36D9757DBNov 2, 2014
15360DF7CCA4572C20E9848C2A80A775EA375Nov 2, 2014
143366B1023C4458C0DD942DD774A5A2CD1FBNov 2, 2014
3072F70D9ED535355267EA601C89776ADC5BNov 5, 2014
15360097EC6A79439BE458DC1F22CFC677F28Nov 5, 2014
60416C03185A6E887D418CE76E656CB6EA386Nov 6, 2014
307254C5EAEAD141274A82DD2EE192DC3505Nov 10, 2014
378884A7DD876B7E7C342A8CB1F921DF14B1ENov 10, 2014
4710421975234E86F0B9B0E207C407A0B4E3ENov 10, 2014
19456E4AA6C5C980269331BF1D8A8CDA9C5F5Nov 12, 2014
3072E536F97AE76662EE1B9ED5190A6EEE09Nov 13, 2014
3072DEA7A2AD457CD6C7FF908874D1688857Nov 14, 2014
35840C0574D63B8F0F7E6BC3B57071B4D5F90Dec 5, 2014
14336B0037A346387BA507EE0A9E271FF7F29Dec 22, 2014
9216F48D55D374A2BE137E81347D355F0C50Dec 27, 2014
737285CBF2A8C87374ACB32552691522655FDDec 27, 2014
14336BF901692AC29BAE271B1F6CF0F0798A7Dec 27, 2014
3072650A205031A0B86A6A706518AF4C0B91Dec 30, 2014
61440FFF377B462F9A238719A1632D031D8F4Jan 6, 2015
14336120E510257494007834F55E9661CC2A4Jan 30, 2015
30729ECDC6E4A589D79DC1D8CB874F9A1977Feb 3, 2015
4710408B17D6C5D83EB4841839AE04311DEF5Feb 6, 2015
14336740BEC4A82ECE383A32B08322CF1281CFeb 22, 2015
460801BECE6FBACE3BFF20630C1DBAB11A058Feb 22, 2015
593923B1AC37F5C6BAF600B7FC051DDACA413Mar 13, 2015
22528C569115721CE2030458F0D9FA0A55E1CMar 29, 2015
512003DFF56F0448C3AB4AE6F5160278E5DA9Mar 31, 2015
1536042AD19573DDD370F28B6447482245167Apr 22, 2015
20480602868031AF91E83BB45B230EFEAF2EAApr 28, 2015
2048087AB1C675D675018CCE431FC7F79B1ACMay 11, 2015
2048025102CC7876691088B0795777A33E194May 20, 2015
389121D9E651A90CB5D52CAFA13F719C5E32CMay 26, 2015
36864AFE3E758A272B386616E764C7E5662D1Jun 23, 2015
460808DB3AB2C3C7E81AD800085813FCF1370Jul 14, 2015
378882CC7E3856463C8298E5DFFF6CF5EF214Aug 3, 2015
44032B086ED02CCA74B2BD70975F3601AE58AAug 17, 2015
143364E72D671168AF0424DCD74BC00205313Aug 19, 2015
501767698E60BFA1C93477BB36808BA492CFFAug 25, 2015
36864F807F4061870A78219AC1C863A6B0357Aug 30, 2015
143365B3FBBE4AB6F7DAAB62979C964DA0B58Sep 21, 2015
15360BE5696A725461BE256D79E4FC2A156AEOct 1, 2015
143364EBCFBF469AF4E28C875FB125801A8A7Oct 14, 2015
35840B7CAEADEB4C75967C832F8530E91D895Oct 18, 2015
3072642DBFECEA2660A371C0C086DCFDC907Oct 22, 2015
15360F6E65022F490BF5E83357AC6AD0F1C51Nov 6, 2015
45056E83C6DC298BD425440D28AB793F1CEC5Nov 15, 2015
20480D7AB10070F021F7ED9F7B85382BC3663Dec 7, 2015
21504954403589F760E45AE6E1A3560B1FF9FDec 18, 2015
45056738FC99823307377C7B8FEE6B3D6F6FEDec 26, 2015
22528CB34350F721D39043880E7C4A822C7D7Dec 28, 2015
17408920E59F09FA03419F73DADAF8DB15632Jan 16, 2016
194564E15D0B1D355818899FF752D9D191353Jan 28, 2016
389125E09A524B0452463BE0131126BE7783DFeb 4, 2016
14336366AFA69EE3D1A637B9E8BFB2FC3E643Feb 5, 2016
30729AA63364AB059CFA7165EE89547E8CAEFeb 13, 2016
15360E484FC37EB8A2720082EE893C13BB985Mar 9, 2016
45056A7417CFE5EB1EA86E47F33BD3F0A4106Apr 2, 2016
3993676643628D2B053D162927A4BD3F5E130Apr 21, 2016
471045176F066415E6466C21CB93BE3A0BFB7Apr 23, 2016
16384017C60555E0DA900A313650C7DFC4895Apr 24, 2016
51200EE94990C4FA24DA4B9B090AB314A0CCDMay 5, 2016
52224B18E20E651E103AB938DA6E7A8176045May 11, 2016
15360DEC599D889B5D497ECF555CC77F3D657May 17, 2016
3072A6BF326564CF0D9AA9AB02744A493B14May 25, 2016
327689E911848BAE71DCEDD03FE78DADD699FMay 27, 2016
49152F181933812D552BC94B6CF4027A1A575Jun 21, 2016
47104699F123D8BAAD2FAEB8D3B8461F40C82Jun 26, 2016
99328BA4E32B524FC58C2B7FBDB026CB390F5Jun 27, 2016
4300812562107FBD6167A3A20426996E8FD21Jun 29, 2016
13312E5E1BE1E23E8FBB9DAA94C2A0AE09161Jul 10, 2016
7475255EF9EFCA34880B2B18047DACD4AA162Jul 16, 2016
2355263DD24AEF3959739FF594259D2AF9007Jul 28, 2016
153607120B540EEBD292822DFABDC1ACB93A9Aug 15, 2016
30728B1A8E2C966806677550FF4D2427A112Sep 18, 2016
225285936C05CA3BF7E3E20163C1951AC740BSep 26, 2016
47104316EDF626BFB07F055968A8C358C4062Sep 29, 2016
14336E65A5C3A940471BE65DE5C96DDF69BEBNov 10, 2016
30723F84558DF12C57DCF0A414A7C8B488F0Nov 13, 2016
4300896BD3B3EAA01D0BAF753741C67BFB822Nov 20, 2016
30726D892F390314C0F8CEE7DE9171B2E03EDec 1, 2016
45056028EB50F58FBFEEDDD0F2F685421A049Dec 6, 2016
4096065F7B3D1AA2B3C32B6D703402258D4B1Dec 8, 2016
30722B6B6FEAC2456FE5209041F5267B75E4Dec 12, 2016
593929C6FAA8BA62CEE1ABD735861D02D7186Dec 15, 2016
153609E02631EC7B15BEC8B40AC6D531BE222Dec 17, 2016
491528FEA00CE00ABAD2106D27E46F97458BCJan 4, 2017
2355239C31C012ADC992155CC1AA888471DFDJan 8, 2017
143360D3C097B85260CF38242E58DC9E23D66Jan 21, 2017
256004B2F31FC4039E51DA466E11D3F2D93CCFeb 5, 2017
655365423E1ABFEE20FD13FF8200FF003656EFeb 8, 2017
3891246DFE729375148FB7979FFAA145EA27BFeb 9, 2017
30722BDBB4A63ABC6B5F9C30D32E0591507EMar 12, 2017
53248D2D635762EB1FE1B2A9C6B7557827AB8Mar 15, 2017
18432FB9DD79DE67E9BE2569AEFDD76A070E4Mar 30, 2017
143367E13BF93B303E08652E04D14B2A4CC37Apr 8, 2017
3072A0476193ECE4756DB312A3FCB62EDB04May 12, 2017
307258B1BCA234591654933F2391BFA94103May 12, 2017
24576BC45058D8A57BA1D8A2B66B06ED0EF42May 21, 2017
675845767B3BDA587D28B5B389F378FE36B97May 30, 2017
450565FD73A8BCBFA9744C7048BEC7BDB1869May 30, 2017
5017663C0F6E9E404669EE1A03FCC66CFE213May 30, 2017
286722F36CEE87FCD9EEB961CB62D8C1B1539Aug 28, 2018
14336A502A829478360A55BD19E1D90739B3ASep 17, 2018

Why Is It Important to Remove Malware Files?^

It is imperative that you delete malware-associated files as soon as possible because they can be used - or are already being used - to inflict serious damage on your PC, including:

  • Disrupting the normal functioning of the operating system or rendering it completely useless.
  • Hijacking valuable private information (credit card numbers, passwords, PIN codes, etc.)
  • Directing all your Web searches to the same unwanted or malicious sites.
  • Dramatically slowing down your computer.
  • Gaining total control of your PC to spread viruses and trojans and send out spam.

How to Remove chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage^

  1. To enable deleting the chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage file, terminate the associated process in the Task Manager as follows:
    • Right-click in the Windows taskbar (a bar that appears along the bottom of the Windows screen) and select Task Manager on the menu.
    • In the Tasks Manager window, click the Processes tab.
    • On the Processes tab, select chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage and click End Process.
  2. Using your file explorer, browse to the file using the paths listed in Location of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage and Associated Malware.
  3. Select the file and press SHIFT+Delete on the keyboard.
  4. Click Yes in the confirm deletion dialog box.
  5. Repeat steps 2-4 for each location listed in Location of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage and Associated Malware.
  6. Notes:

    • The deletion of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage will fail if it is locked; that is, it is in use by some application (Windows will display a corresponding message). For instructions on deleting locked files, see Deleting Locked Files.
    • The deletion of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage will fail if your Windows uses the NT File System (NTFS) and you have no write rights for the file. Request your system administrator to grant you write rights for the file.

Deleting Locked Files^

You can delete locked files with the RemoveOnReboot utility. You can install the RemoveOnReboot utility from here.

After you delete a locked file, you need to delete all the references to the file in Windows registry.

To delete a locked file:

  1. Right-click on the file and select Send To -> Remove on Next Reboot on the menu.
  2. Restart your computer.

The file will be deleted on restart.

Note: In the case of complex viruses that can replicate themselves, malware files can reappear in the same locations even after you have deleted those files and restarted your computer. Exterminate It! Antimalware can effectively eradicate such viruses from your computer.

To remove all registry references to a chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage malware file:

  1. On the Windows Start menu, click Run.
  2. In the Open box, type regedit and click OK. The Registry Editor window opens.
  3. On the Edit menu, select Find.
  4. In the Find dialog box, type chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage. The name of the first found registry value referencing chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage is highlighted in the right pane of the Registry Editor window.
  5. Right-click the registry value name and select Delete on the menu.
  6. Click Yes in the Confirm Value Delete dialog box.
  7. To delete all other references to chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage, repeat steps 4-6.
IMPORTANT: Malware files can masquerade as legitimate files by using the same file names. To avoid deleting a harmless file, ensure that the Value column for the registry value displays exactly one of the paths listed in Location of chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage and Associated Malware.