How can I get rid of safesearch malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jassmin, Jul 20, 2015.

  1. Jassmin

    Jassmin Corporal

    Please help !!
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Jassmin

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes, you could use a flash drive too, but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run RogueKiller, Malwarebytes, HitmanPro and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated - our system works the oldest threads FIRST.
     
  3. Jassmin

    Jassmin Corporal

    OK. I will, thank you.
     
  4. Jassmin

    Jassmin Corporal

    Hi, Defogger didn't ask me to reboot pc after disabling ... it remains on screen and didn't move ... I closed application what should I do now? Continue with CCleaner?

    Thank you
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes and then on to Step 6: Windows OS Specific Cleaning Instructions which will generate the 5 logs we use for detection/removal.

    EDIT: Re-boot your machine first, then continue.
     
  6. Jassmin

    Jassmin Corporal

    OK, pc is acting like crazy, hardly can download the tools or type, will continue ... thank you
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See Dr M's first message and Helpful Note #2
     
  8. Jassmin

    Jassmin Corporal

    Sure ...:)
     
  9. Jassmin

    Jassmin Corporal

    Here are the logs but I still have problem with all the pop ups and ads and slow pc....
     

    Attached Files:

  10. Jassmin

    Jassmin Corporal

    Can't find Rogue Killer log, there is only this one:

    RKreport_SCN_07222015_001254.json
     
  11. Jassmin

    Jassmin Corporal

    Hi, sorry for disturbing you, could you please check my logs ?

    The one I couldn't find. Still having problem with pc.

    Thank you.
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Rerun RogueKiller -
    • When the Scan Status reads finished
    • Click on the Report button, a new window opens..
    • At the bottom right corner choose Export TXT, then "Save" the report to your desktop.
    • Attach this report to your next reply
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Next -

    Rerun Hitman Pro, this time activate the 30-day trial so the following can be fixed under these headings:
    Malware
    • C:\Users\Asus\Downloads\DownloadApp_1_8_0_209r_Setup.exe
    • C:\Users\Asus\Downloads\hddh.exe
    Malware remnants
    • ALL
    Potential Unwanted Programs
    • All
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest HitmanPro log.

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Look over the log especially under Files/Folders for any program you want to save.
    • If there's a program you may want to save, just uncheck it from AdwCleaner.
    • If you're not sure, post the log for review. (all items found are either adware/spyware/foistware)
    • If you're ready to clean it all up.....click the Clean button.
    • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
    • Attach that logfile to your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which are created when running the tool.
    How is the pc running now?
     
  14. Jassmin

    Jassmin Corporal

    I went through all steps but still have problem with redirection and all ads on the screen.

    Sending you requested logs.

    Please do you know how can I get rid off all ads?

    Thank you in advance.
     

    Attached Files:

    Last edited by a moderator: Jul 23, 2015
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Questions: With which browser(s) are you getting redirects still? Are you using an ad blocker?
    Is this program still listed as installed and is properly working?
    C:\Program Files\Lavasoft\Web Companion\TcpService

    Run steps 1 & 2 from the following guide ---> Fixing browser and search engine redirection/hijacking problems

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select "Run As Administrator").

    Please attach the updated MGlogs.zip and to your next reply.
     
  16. Jassmin

    Jassmin Corporal

    I use Firefox, not using ad blocker. I've never had these problems before. But I downloaded new Video Player and having problems.
    Will do.
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Which one? Have you noticed any bundleware that came with it?
     
  18. Jassmin

    Jassmin Corporal

    KM Player, yes as I wrote in the beginning ... something like safesearch ... still showing up ads
     
  19. Jassmin

    Jassmin Corporal

    I went through these 2 steps but it continues ... here is LOG
     

    Attached Files:

  20. Jassmin

    Jassmin Corporal


    Sorry what should I do now? Could you let me know?
     
  21. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please be aware that I'm halfway around the globe, volunteering some of my free time to assist infected pc users. Your awareness of that while I work through logs or I wait for less-than-speedy replies is appreciated.

    dr.m
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below software are known to interfere with making desired browser setting changes to correct hijacks.
    Ad-Aware Web Companion
    LavasoftTcpService

    Please use this to uninstall them.
    GeekUninstaller

    NOTE: It may become necessary to also temporarily uninstall Avast AV while we work.

    But let's do this first..

    Reset Firefox to Defaults

    Now clean Firefox's shortcut - refer to the attachment
    • Right-click the Firefox browser shortcut > choose Properties
    • In the Shortcut tab, in the Target field, there should be only the path to browser executable file. *Remove any "http:// argument" found.
    • Close window and reboot your pc.

    Any improvement?
     

    Attached Files:

  23. Jassmin

    Jassmin Corporal

    First uninstall or firefox? I just wanted to know if I can help in some way or just wait ( question before ). I know that is your free time.
     
  24. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please perform those instructions, in the order given.
     
  25. Jassmin

    Jassmin Corporal

    there is not lavasoft among programs and web companion failed uninstall - it can only delete it.

    What now?
     
  26. Jassmin

    Jassmin Corporal


    Uninstaller can't uninsta Web companion, only delete some files from registry. Should I delete them from registry?
     
  27. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, that's the purpose of using that uninstaller - to remove as many leftovers as possible.
     
  28. Jassmin

    Jassmin Corporal

    It looks without having problems now. I finished last steps.

    What is the next step?

    Thank you.
     
  29. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You are welcome.

    Any remaining malware problems before I post final steps?
     
  30. Jassmin

    Jassmin Corporal

    I don't see any problems right ...
    Only Avast is telling me that 6 useless programs can be deactivated. I am using free version so I can't uninstall them with it. Is there any other uninstaller maybe?

    But this is not a real problem. Only question.

    TY.
     
  31. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    That sounds like a "Bonus" tool that you must upgrade your software in order to use. ;) I do my own "software usefulness" sorting, and also use GeekUninstaller.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  32. Jassmin

    Jassmin Corporal

    Sorry, but I don't see HijackThis among programs for uninstall. Sorry will be here later to finish this.

    Thank you a lot for your kidness and help.
     
  33. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If HijackThis isn't listed in either Vista's Programs & Features or GeekUninstaller, I would just move on to the next steps.

    Again - you are very welcome!
     
  34. Jassmin

    Jassmin Corporal

    OK, sorry wasn't here for a while. I disabled system restore and unticked cdrive there. After reboot when I enabled system restore I ticked cdrive back. Is it ok?
     
  35. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, you did that correctly.
     
  36. Jassmin

    Jassmin Corporal

    I think I did everything. Should I also uninstall AdwCleaner and Hitman? Or keep them.
     
  37. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You can uninstall Hitman Pro and just delete the AdwCleaner.exe application.
     
  38. Jassmin

    Jassmin Corporal

    OK, many thanks again for your great assistance and wish you a wonderful summer !!

    :wave
     
  39. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I hope that you're having a cooler summer than I am!
     
  40. Jassmin

    Jassmin Corporal

    Not at all ....
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds