can't get rid of claro-search

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Philip1, Sep 9, 2012.

  1. Philip1

    Philip1 Private E-2

    Can someone help me with getting rid of claro from my system please,
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. Philip1

    Philip1 Private E-2

    Hi,
    I've rune all the scans from READ & RUN ME FIRST. Malware Removal Guide, you suggested but it's still here,

    Do you have any idea what to do next,

    I attached the logs,

    Thank you,
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can attach the MGlogs.zip please from running MGTools.exe. Thanks.
     
  5. Philip1

    Philip1 Private E-2

    log's in the attachment,

    Tx!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to take a look at this:
    Warning about Porn, Keygens, Cracks, and other Illegal Software


    Re run Hitmanpro and have it delete all it finds.

    Delete this file:
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml

    Delete these folders:
    C:\ProgramData\Babylon
    C:\ProgramData\GboxUpdater
    C:\ProgramData\OptimizerPro
    C:\ProgramData\SpeedyPC Software

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. Philip1

    Philip1 Private E-2

    Hi,

    log in attachment, couldn't find Extras.Txt,

    Thank you,
     

    Attached Files:

    • OTL.Txt
      File size:
      66.6 KB
      Views:
      7
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Driver Pro v3.0 <--- Uninstall this unless you paid for it.

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    CHR - homepage: http://www.claro-search.com/?affID=111304&tt=090812_clr_3212_4&babsrc=HP_ss&mntrId=74a861ca0000000000000625567e6496
    CHR - homepage: http://www.claro-search.com/?affID=111304&tt=090812_clr_3212_4&babsrc=HP_ss&mntrId=74a861ca0000000000000625567e6496
    [2012/08/11 13:07:47 | 000,000,000 | ---D | M] -- C:\Users\Philip\AppData\Roaming\Babylon
    @Alternate Data Stream - 176 bytes -> C:\ProgramData\Temp:ECF54A0E
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:DFC5A2B2
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:430C6D84
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    How is everything running now?
     
  9. Philip1

    Philip1 Private E-2

    Hi,

    In the attachment is the log,

    All OK but claro is still here and my windows installer doesn’t work,
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run OTL again and attach the log please.
     
  11. Philip1

    Philip1 Private E-2

    Loge in the attachment,
     

    Attached Files:

    • OTL.Txt
      File size:
      65.4 KB
      Views:
      3
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is it only Chrome this is affecting?
     
  13. Philip1

    Philip1 Private E-2

    No my firefox only,
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Philip.

    We are going to be uninstalling your old version of FireFox and installing the new version. (Except please use REVO instead of the standard uninstall method!) So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox (with Revo) and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:
    • C:\Program Files (x86)\Mozilla Firefox
    • C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    --------------

    Better?
     
  15. Philip1

    Philip1 Private E-2

    Hi
    Sorry I was away,

    I did follow the instructions, and uninstalled Firefox and installed it again.

    Now it doesn't redirect me to the claro search engine page, but the little claro icon is present in the address box all the time.

    Any idea?

    Thank you!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You mean the address bar? Or search box? (Top right)
     
  17. Philip1

    Philip1 Private E-2

    yes address bar,
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run OTL and attach the log please.
     
  19. Philip1

    Philip1 Private E-2

    log in the attachment,
     

    Attached Files:

    • OTL.Txt
      File size:
      66.5 KB
      Views:
      5
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    :otl
    CHR - homepage: http://www.claro-search.com/?affID=111304&tt=090812_clr_3212_4&babsrc=HP_ss&mntrId=74a861ca0000000000000625567e6496
    CHR - homepage: http://www.claro-search.com/?affID=111304&tt=090812_clr_3212_4&babsrc=HP_ss&mntrId=74a861ca0000000000000625567e6496
    CHR - Extension: ADDICT-THING = C:\Users\Philip\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckaomfkdabdhbhdnoleeclneakpepdik\1.0_0\
    
    :files
    C:\Users\Philip\AppData\Roaming\CleanMyPC Software
    C:\Users\Philip\AppData\Roaming\SpeedyPC Software
    C:\ProgramData\ADDICT-THING
    C:\ProgramData\Babylon
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    • Now run OTL again normally, no fix, just a scan and attach log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  21. Philip1

    Philip1 Private E-2

    Hi,

    Logs in the attachment,

    Thank you,
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is your homepage set to in Chrome? Chrome may have to be uninstalled and reinstalled to get rid of Claro.
     
  23. Philip1

    Philip1 Private E-2

    Hi,
    I don't have Chrome, only Firefox and Internet Explorer, but claro is only in Firefox.
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So what's this I am seeing installed?

     
  25. Philip1

    Philip1 Private E-2

    HA I'm sorry, forgot about it, never used it, but it looks like is also infected,

    Can I uninstall it?
     
  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, uninstall it and then rerun OTL again and attach the new log please.
     
  27. Philip1

    Philip1 Private E-2

    Hi,

    Loge in the attachment,

    Thank you,
     

    Attached Files:

    • OTL.Txt
      File size:
      63.6 KB
      Views:
      2
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not reinstall Chrome yet did you?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  29. Philip1

    Philip1 Private E-2

    Here is the loge,

    Thank you so much!
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    CHR - homepage: http://www.claro-search.com/?affID=111304&tt=090812_clr_3212_4&babsrc=HP_ss&mntrId=74a861ca0000000000000625567e6496
    CHR - homepage: http://www.claro-search.com/?affID=111304&tt=090812_clr_3212_4&babsrc=HP_ss&mntrId=74a861ca0000000000000625567e6496
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Rerun OTL again (no fix just scan) and attach the new log.
     
  31. Philip1

    Philip1 Private E-2

    Hi,
    Logs in attachment,

    Thank you,
     

    Attached Files:

  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reinstall Chrome and let me know how it is. If your homepage is still set at Claro then simply change it and see if it sticks. Let me know!
     
  33. Philip1

    Philip1 Private E-2

    I don't really use Chrome, I use Firefox, and on Firefox it is still there, redirecting me to claro. My home page is www.wildwindsafaris.com, and it opens when i start Firefox, but there is little claro icon on the address bar next to any website address i type or open.
    Even if I try to force Google to be my default search engine it changes to claro.

    Any idea?
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      *claro*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  35. Philip1

    Philip1 Private E-2

    Here is the log.
     

    Attached Files:

  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I should have had you use the 64bit version of systemlook for better results.

    I have to go out soon, and also, think its time I asked colleagues about this for you.

    In the mean time please oprn up your registry and run a search for Claro. Let me know the results!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds