Ndo.coreopti.net Removal Guide

Threat Level:
7/10
Rate this Article:
Comments (0)
Article Views: 4562
Category: Adware

If you see a window with an ndo.coreopti.net URL pop up on your screen, then you definitely have an adware application installed on your computer. This domain is used by adware programs to generate commercial advertisements and it is generally not related to adware applications directly, but if you want to remove ndo.coreopti.net from your browser and your computer, you definitely need to terminate the program utilizing this domain first. In order to determine which program is making use of ndo.coreopti.net, run a full system scan with SpyHunter free scanner and all the potentially unwanted programs will be detected.

It is very possible that you do not remember having installed any adware application recently. That is so, because adware applications often arrive bundled with freeware and they get installed on computer silently. Once adware application is installed, you are bombarded with a wide range of commercial pop-up ads when you browse the Internet.

The ads displayed via ndo.coreopti.net are generated by third parties and for the most part you will probably be urged to download a new video codec or to update your video player so that you would be able to watch all of your videos in HD. It is important that you stay away from such advertisements, especially if they are distributed through ndo.coreopti.net.

Chances are that by clicking the ads you would not download a video player installer – rather than that, you most probably would end up installing yet another adware application on your computer or even worse – that could be part of malware distribution network as well.

Since you cannot trust ndo.coreopti.net and anything related to it, you need to remove the domain and the program that keeps on displaying pop-ups on your computer right now. As we have mentioned above, it is important to determine which program might be responsible for commercial pop-ups. While you are at it, remove ALL the potentially unwanted applications from your computer. It is very likely that you have installed ndo.coreopti.net application along with other freeware apps, so most probably the installation date indicated on the list of installed programs on Control Panel will coincide.

After manual removal, be sure to scan your PC with licensed antimalware tool once again, just to make sure that you have removed all the potentially unwanted and dangerous files for good. Invest in a computer security application if need be, and do not hesitate to leave us a comment below if you have any further questions.

How to remove ndo.coreopti.net adware

Windows 8

  1. Slide mouse cursor to the bottom right of your desktop.
  2. When Charm bar appears click Settings and go to Control Panel.
  3. Open Uninstall a program and remove unwanted applications.

Windows Vista & Windows 7

  1. Click Start menu button and go to Control Panel.
  2. Open Uninstall a program and remove undesirable applications.

Windows XP

  1. Open Start menu and go to Control Panel.
  2. Select Add or remove programs and uninstall unwanted applications.
Download Remover for Ndo.coreopti.net *
*SpyHunter scanner, published on this site, is intended to be used only as a detection tool. To use the removal functionality, you will need to purchase the full version of SpyHunter.

Ndo.coreopti.net Screenshots:

Ndo.coreopti.net

Ndo.coreopti.net technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1haokanbar2.dll1196544 bytesMD5: f9b16220b4fef4929fcbef70f796ee1d
2loader.dll1952224 bytesMD5: 37bd04088bdce15df2233a0bbb30b581
3SRRest.exe195584 bytesMD5: 7c0866231c693ee4fb849db98c116958
4Browsafe.dll4370944 bytesMD5: 352321754d7ddd2c0ff78a6192820b8b
5ProtectExtension.exe65024 bytesMD5: a3ef1e191ecc5c9119cb8b240e661d1b
6mngr.exe2402840 bytesMD5: 83de1aba61074da70f5011d28610b18d
7score.exe4795904 bytesMD5: f67364e6c49a4a35135122c7fa4981e3
8PCProtect.dll293984 bytesMD5: f03faec422b8e51280c6643b95325a36
9datamgr.exe168264 bytesMD5: dfb1b3b2f47d4ae0c6924dcbb9316be1
10eBP.dll506944 bytesMD5: c96ffd1c7e1a3251e572af247fa5b4b9
11killvirus.exe1867776 bytesMD5: 2bde55f0caa615234dbed270e297916d
12srapw.exe1045360 bytesMD5: 9ada4434d23c772e26532ab2a308e162
13googleupd.exe210432 bytesMD5: 455f041fa885dc6bea2b8e1a679c2d4e
14%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph
15Coupons64.dll720232 bytesMD5: 3af9efc3adbf93bd355359267d13a1cc
16assistant.dll1224192 bytesMD5: 54040c2d87bf93f29b8b5b435fdbdb68
17uninstaller.exe1114624 bytesMD5: 8c7fb9078a63b7e5e899e7a2dbb0db53
18AlcwDrv.sys20608 bytesMD5: 67f07aff287a8ab86bbd5f46b96c5d0f
19%ALLUSERSPROFILE%\Application Data\BrowserProtect
20sv.exe390464 bytesMD5: 933c9ab95b4699976247182edc573ba7
21FunSpace.Update.Process.exe479848 bytesMD5: ff9d7fc12e622ed63a2214319bff1bfd
22Bind.exe503808 bytesMD5: 5004e1d136deaa741edf41310ac07f54
23GoogleUpdate.exe68608 bytesMD5: d858ba2ee718b1db1ced20646e641d08
24Coupons.dll605544 bytesMD5: adc6038fc7ef8d6b6b92169dde4b9a46
25browsemngr.exe2561488 bytesMD5: b98ef68b1e3dc5ac79a432900947ea2d
26WSSvc.dll183632 bytesMD5: f95b0bd988772a273579d5daee15410a
27%AppData%\Microsoft\Windows\Start Menu\Programs\BrowserProtect
28SmdmFService.exe3572240 bytesMD5: 7e773e6043dbd576e3af32c853030405
29smdmfu.exe3587088 bytesMD5: e1e7f05223d6ab75b6a0884b19ddc682
30%ALLUSERSPROFILE%\Application Data\Anti-phishing Domain Advisor
31UninstallManager.exe656384 bytesMD5: 23fd41f5fd6f3add8f38e1becfdc53d8
32mngr.dll 2147352 bytesMD5: a5c86cabe266de5f9e4d37beeb0415fb
33%ALLUSERSPROFILE%\Application Data\Browser Manager
34browse~1.dll 2162280 bytesMD5: 08b95f5a221bc1f184d2ac9223a6dddf
35haokanbar.dll976384 bytesMD5: a880b9123376746bb297d0bff3ca4612
36contentagent.exe108032 bytesMD5: 802aff4c0ccd0cbe2c9d8ca84b7c5ec9
37Assistant_x64.dll2759168 bytesMD5: 7464ba51bdf2a44ce54dc0d7940d5cc9
38%ALLUSERSPROFILE%\Anti-phishing Domain Advisor
39wprotectmanager.exe499856 bytesMD5: e9986e9adb8d65b6ca30d80103f1f53c
40chrome-links.exe16152 bytesMD5: 0150918679d3501aa7c1275d500311f1
41flashEnhancer.dll177664 bytesMD5: 2f0599bdc6448a822bf88a0d575a7dfc
42gp_upd.exe806912 bytesMD5: 4a055ebdfc81410df990ae4bd3c76d41
43BManager.exe888832 bytesMD5: 5111c89efe59998baa0b3664688bf0ac
44CLTMNG.EXE1199944 bytesMD5: b2660e264e3391be190937a0345c4a49
45Supporter.dll4378112 bytesMD5: 1443cdced9b103fb98313228125158bb
46MAJTuto.exe3015168 bytesMD5: 8d6c1e70004efc97710697aa9450130a
47updater_task.dll1573888 bytesMD5: 2a575c4ff38bf28524adba45a817342b
48webdev.exe368448 bytesMD5: 2989aad5de387817e115ff82b1b83bee
49WebstatsAgent.exe35934 bytesMD5: 1747817dd26e365b3827a14fc130b299
50%AppData%\Mozilla\Firefox\Profiles\????????????????
51consoleguard.exe327168 bytesMD5: b2e3f929a5cb350908fd06f086e90bff
52lmservice.exe293400 bytesMD5: 9aee86334f8b21d23b467fff36e93db9
53GSSvc.dll180048 bytesMD5: 8852a4872bfaf269369631e99e54e8f2
54DFService.exe141312 bytesMD5: f884ade2532330098dd3076cb46d0f2e
55unwrapped.exe2244608 bytesMD5: 151afdad85df956bbc7c1586688c7b30
56FrameworkBHO64.dll325160 bytesMD5: e04114c2f0b55d330a96b420d5a56231
57dnkt.exe730928 bytesMD5: 64f276f23c20dc0902cca1d071a10949
58monitorsvc.exe34244 bytesMD5: 8717fa628a749175a7ef127df2c012fc
59webmakerplus.exe4153344 bytesMD5: e482ec510e409ed43fd2a1b33ab1beee
60netupdsrv.exe161792 bytesMD5: 70120e886d9bdece4b4063c8f921bc3c
61winclient32.exe639488 bytesMD5: 10b2a4f40e30705469ceabaf5acc3e7b
62ntvmon32.exe1716224 bytesMD5: d0d6d4a67a62983e874a9dc5219e716e
63WS_x64.Booster4210176 bytesMD5: 14fc568bcaf731bc998041a56af09ff9
64simple_new_tab.dll213504 bytesMD5: 9d43dc984217b861a35cd38e2b4e0503
65SupporterSvc.dll179536 bytesMD5: 53ec43fafb51ec1f337ab342884e9833
66sprotector.dll323584 bytesMD5: 1a8b01302741f5e6b33de2918e06e4b7
67BrowserProtect.exe2469992 bytesMD5: 4c260de6b554a670546578426bb0c604
68BitGuard.exe2845152 bytesMD5: 2d89abac9d439abad1e427a467f0687d
69srvhelper32.exe640512 bytesMD5: 9d3cfe474a377a8ad643d99c1825aeea
70iexplorer_monitor.exe74075 bytesMD5: cb72687b0f0b6ea1b8c102d35cab377a
71%USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default
72%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph
73VideoUsage.exe1290384 bytesMD5: d722cd14f93275a5a831a7ed42a3d6fb
74monitor.exe487518 bytesMD5: d93ad5cdaf2536ae400ee789c1fd0951
75PCProtect.exe1265608 bytesMD5: c231bea86e6ec4c6510c99de9dd6d6fa
76keepmysettingsx.exe973384 bytesMD5: b1fd4d3b3fb3676171fdd3320a6c3b57
77SoftUpdate.exe18432 bytesMD5: ace56e0e47a2d7987a8c48cdc187ee2d
78DS.EXE19456 bytesMD5: faae0ffb4277ee0d73cd15b4281163de
79%ALLUSERSPROFILE%\Browser Manager
80iexplore_monitor.exe81378 bytesMD5: 8568b48a5bcba9fd6965527bd3ec7798
81BrowserDefender.exe2827728 bytesMD5: 013a330f16b1cecbde5cb6f921689523
82install_helper.exe912896 bytesMD5: bd23a611a8a2c22a6944f92825164ffa
83ScriptHost.dll244736 bytesMD5: 31504cff43d737434df748c19acb5b78
84Updater.exe286208 bytesMD5: 0e664de3e36998a10d5e6e21d4d65b4d
85ws_updater.exe48402 bytesMD5: 1712022d23818ab21f2d94e04b533788
86FrameworkBHO.dll258088 bytesMD5: 20e21d49831f726fdac5b25d25085190
87%LOCALAPPDATA%\Google\Chrome\User Data\Default
88regmon32.exe147784 bytesMD5: 9870700d00213d18f5978fe906a2fdb6
89DProtectSvc.exe343104 bytesMD5: c2fcb2597859fc777b0d712bf863e6bf
90AssistantSvc.dll146768 bytesMD5: d8397319f25cbd0deabfe00fadb6ce5f
91onekit.exe547208 bytesMD5: 3e1f5e3366a9c06a5b95bad869fe2590
92RazaWebHook64.dll56320 bytesMD5: d9c6a2cf9c2ead81faf15da71bad7f98
93smdmfmgrc2.cfg41872 bytesMD5: d20ac17bb5877055856f39beec7bc5a2
94UpdateTask.exe94208 bytesMD5: ec63f649f7090f885ebd4770ffb92fcb
95ProtectWindowsManager.exe528384 bytesMD5: 357a3a310bc75b9b57a7292847896015
96ExtensionUpdaterService.exe188760 bytesMD5: 2af0e02a92bee89e84ef1000f695aa7e
97AmiBho.dll178176 bytesMD5: e31b02008af00d3b9e0fe7ec06c74bf9
98dsrlte.exe535472 bytesMD5: ba73d8dc5dd1cf3e558c2152c3d969ad
99SPVC64~1.DLL 202560 bytesMD5: 5abdcfd360ed6678379f3b34a4ed8731
100biclient.exe230480 bytesMD5: 92c732231b7909edeff180174c6ef499
101SOSvc.dll174928 bytesMD5: e6e495e524b06440a480a80dda8551ea
102%ALLUSERSPROFILE%\BrowserProtect
103dlprotect.exe12800 bytesMD5: 405086033107e126371536fb5e558b50
104SWSvc.dll174928 bytesMD5: 5b7fb006f463e40c835b8b269b239fad
105GS.Enabler4105728 bytesMD5: 181c6deb7ee5b3d582b9a1643aeae1e7
106dsrsetup.exe334696 bytesMD5: f69f826c0323da0c32e70f73d952f0ca
107sgnahzzzax.dll74752 bytesMD5: f9556a7884e44b15acc1c3a4a4e72001
108SNSvc.dll174928 bytesMD5: 8f9454e2b5b5793167400570929e87e2
109NCdownloader.exe270848 bytesMD5: ece8676d382dd3d96367144f867c292e
110ytai_ytareg_setup.exe785296 bytesMD5: c560bc055e26d58835605327e10e9b13
111Autoload.exe48128 bytesMD5: 09de3cb9af1bddcc60f986440efe98f1
112SafeUpdater.exe3015168 bytesMD5: 1f2880e2ee5aa1c3f4fa680a68b3837f

Files in the following directories were modified:

  • %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions
  • %ALLUSERSPROFILE%\Application Data
  • %AppData%\Microsoft\Windows\Start Menu\Programs
  • %ALLUSERSPROFILE%
  • %AppData%\Mozilla\Firefox\Profiles
  • %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data
  • %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions
  • %LOCALAPPDATA%\Google\Chrome\User Data

Memory Processes Created:

# Process Name Process Filename Main module size
1SRRest.exeSRRest.exe195584 bytes
2ProtectExtension.exeProtectExtension.exe65024 bytes
3mngr.exemngr.exe2402840 bytes
4score.exescore.exe4795904 bytes
5datamgr.exedatamgr.exe168264 bytes
6killvirus.exekillvirus.exe1867776 bytes
7srapw.exesrapw.exe1045360 bytes
8googleupd.exegoogleupd.exe210432 bytes
9uninstaller.exeuninstaller.exe1114624 bytes
10sv.exesv.exe390464 bytes
11FunSpace.Update.Process.exeFunSpace.Update.Process.exe479848 bytes
12Bind.exeBind.exe503808 bytes
13GoogleUpdate.exeGoogleUpdate.exe68608 bytes
14browsemngr.exebrowsemngr.exe2561488 bytes
15SmdmFService.exeSmdmFService.exe3572240 bytes
16smdmfu.exesmdmfu.exe3587088 bytes
17UninstallManager.exeUninstallManager.exe656384 bytes
18contentagent.execontentagent.exe108032 bytes
19wprotectmanager.exewprotectmanager.exe499856 bytes
20chrome-links.exechrome-links.exe16152 bytes
21gp_upd.exegp_upd.exe806912 bytes
22BManager.exeBManager.exe888832 bytes
23MAJTuto.exeMAJTuto.exe3015168 bytes
24webdev.exewebdev.exe368448 bytes
25WebstatsAgent.exeWebstatsAgent.exe35934 bytes
26consoleguard.execonsoleguard.exe327168 bytes
27lmservice.exelmservice.exe293400 bytes
28DFService.exeDFService.exe141312 bytes
29unwrapped.exeunwrapped.exe2244608 bytes
30dnkt.exednkt.exe730928 bytes
31monitorsvc.exemonitorsvc.exe34244 bytes
32webmakerplus.exewebmakerplus.exe4153344 bytes
33netupdsrv.exenetupdsrv.exe161792 bytes
34winclient32.exewinclient32.exe639488 bytes
35ntvmon32.exentvmon32.exe1716224 bytes
36BrowserProtect.exeBrowserProtect.exe2469992 bytes
37BitGuard.exeBitGuard.exe2845152 bytes
38srvhelper32.exesrvhelper32.exe640512 bytes
39iexplorer_monitor.exeiexplorer_monitor.exe74075 bytes
40VideoUsage.exeVideoUsage.exe1290384 bytes
41monitor.exemonitor.exe487518 bytes
42PCProtect.exePCProtect.exe1265608 bytes
43keepmysettingsx.exekeepmysettingsx.exe973384 bytes
44SoftUpdate.exeSoftUpdate.exe18432 bytes
45iexplore_monitor.exeiexplore_monitor.exe81378 bytes
46BrowserDefender.exeBrowserDefender.exe2827728 bytes
47install_helper.exeinstall_helper.exe912896 bytes
48Updater.exeUpdater.exe286208 bytes
49ws_updater.exews_updater.exe48402 bytes
50regmon32.exeregmon32.exe147784 bytes
51DProtectSvc.exeDProtectSvc.exe343104 bytes
52onekit.exeonekit.exe547208 bytes
53UpdateTask.exeUpdateTask.exe94208 bytes
54ProtectWindowsManager.exeProtectWindowsManager.exe528384 bytes
55ExtensionUpdaterService.exeExtensionUpdaterService.exe188760 bytes
56dsrlte.exedsrlte.exe535472 bytes
57biclient.exebiclient.exe230480 bytes
58dlprotect.exedlprotect.exe12800 bytes
59dsrsetup.exedsrsetup.exe334696 bytes
60NCdownloader.exeNCdownloader.exe270848 bytes
61ytai_ytareg_setup.exeytai_ytareg_setup.exe785296 bytes
62Autoload.exeAutoload.exe48128 bytes
63SafeUpdater.exeSafeUpdater.exe3015168 bytes

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *