MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 07-30-12, 10:14
FMLsrsly FMLsrsly is offline
Private E-2
 
Join Date: Jul 2012
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Unhappy Remove Claro-search engine?

Hi,

I was stupid to install something that started this problem and now I need help.
I've Google.com set as my home page on FireFox but I'm experiencing problems when opening new tabs because it opens this page: isearch.claro-search.com/?affID=114164&tt=3012_5&babsrc=NT_iclro&mntrId=9cc67150000000000000001e8ca94e64 . This shit is also opening on other internet browsers, like Google Chrome together with a new google tab.

How do I remove it? Help would be very much appreciated since I suck at computers. And english.
Reply With Quote
Sponsored links
  #2  
Old 07-30-12, 16:17
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,434 Times in 1,355 Posts
Default Re: Remove Claro-search engine?

Hello FMLsrsly

Please download OTL by OldTimer.
  • Save it to your desktop.
  • Double click on the OTL icon on your desktop.
  • Check the "Scan All Users" checkbox.
  • Check the "Standard Output".
  • Change the setting of "Drivers" and "Services" to "All"
  • Copy the text in the code box below and paste it into the text-field.
    Code:
    activex
    netsvcs
    /md5start
    afd.sys
    i8042prt.sys
    ipsec.sys
    netbt.sys
    svchost.exe
    tcpip.sys
    /md5stop
    %windir%\$ntuninstallkb*. /30
    %windir%\system32\drivers\*.sys /lockedfiles
  • Now click the button.
  • One report will be created:
    • OTL.txt <-- Will be opened
  • Attach OTL.txt to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #3  
Old 08-02-12, 14:02
FMLsrsly FMLsrsly is offline
Private E-2
 
Join Date: Jul 2012
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Remove Claro-search engine?

Hi,
I've done everything you wrote and here's the OTL.txt
Attached Files
File Type: txt OTL.Txt (169.7 KB, 28 views)

Last edited by TimW; 08-02-12 at 14:20..
Reply With Quote
  #4  
Old 08-02-12, 14:33
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,434 Times in 1,355 Posts
Default Re: Remove Claro-search engine?

From Add/Remove Programs (via Control Panel), please uninstall the below:
  • Java(TM) 6 Update 30

Fix items using OTL by OldTimer

Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Copy the text in the code box below and paste it into the text-field.
Code:
:otl
IE - HKU\S-1-5-21-1659004503-1644491937-1417001333-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://isearch.claro-search.com/?q={searchTerms}&affID=114164&tt=3012_5&babsrc=SP_iclro&mntrId=9cc67150000000000000001e8ca94e64
IE - HKU\S-1-5-21-1659004503-1644491937-1417001333-1004\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/?source=c3348dd4&tbp=rbox&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Claro Search"
FF - prefs.js..browser.search.order.1: "Claro Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=616163&ilc=12"
FF - prefs.js..keyword.URL: "http://isearch.claro-search.com/?affID=114164&tt=3012_5&babsrc=KW_iclro&mntrId=9cc67150000000000000001e8ca94e64&q="
[2012-07-26 14:04:00 | 000,006,531 | ---- | M] () -- C:\Program\mozilla firefox\searchplugins\babylon.xml
[2011-12-16 23:14:50 | 000,002,067 | ---- | M] () -- C:\Program\mozilla firefox\searchplugins\blekkotb.xml
CHR - homepage: http://isearch.claro-search.com/?affID=114164&tt=3012_5&babsrc=HP_iclro&mntrId=9cc67150000000000000001e8ca94e64
CHR - homepage: http://isearch.claro-search.com/?affID=114164&tt=3012_5&babsrc=HP_iclro&mntrId=9cc67150000000000000001e8ca94e64
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
[2012-07-26 14:03:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yo\Application Data\Babylon
[2012-07-26 14:03:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Babylon
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
:commands
[emptytemp]
[resethosts]
Now click the button.
If the fix needed a reboot please do it.
Click the OK button (upon reboot).
When OTL is finished, Notepad will open. Close Notepad.
A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Attach this log to your next message. (How to attach)

__

Let me know if the problem still persists after completing the above.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #5  
Old 08-02-12, 15:36
FMLsrsly FMLsrsly is offline
Private E-2
 
Join Date: Jul 2012
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Remove Claro-search engine?

It seems it didn't work for some reason, I'll attach the log here.
Attached Files
File Type: log 08022012_221901.log (10.9 KB, 3 views)

Last edited by TimW; 08-02-12 at 15:41..
Reply With Quote
Sponsored links
  #6  
Old 08-02-12, 15:42
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,434
Thanks: 430
Thanked 4,580 Times in 4,334 Posts
Default Re: Remove Claro-search engine?

Please stop quoting Thisisu! It puts your post into moderation each time.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #7  
Old 08-02-12, 15:57
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,434 Times in 1,355 Posts
Default Re: Remove Claro-search engine?

This was in your OTL fix log
Code:
Use Chrome's Settings page to change the HomePage.
The Claro-search homepage / search engine should have been removed from all browsers except Google Chrome. It seems you will have to edit it yourself through Chrome's settings. I do not know where exactly because I do not use Chrome but another route you could take is to uninstall and reinstall Google Chrome to see if that helps.

Please rescan with OTL (same way you did before) so I can check for any remnants
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #8  
Old 08-04-12, 17:54
FMLsrsly FMLsrsly is offline
Private E-2
 
Join Date: Jul 2012
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Remove Claro-search engine?

Thank you, thisisu. The search engine was still there, opening a claro search tab and a Google tab (this was my setting) on Google Chrome and opening on FireFox whenever I opened a new tab. I uninstalled them and reinstalled them and it seems that did the trick. I'll post the OTL report too.



And to TimW: I'm sorry, it's just a bad habit I have from other forums. Haven't been on this one before.
Attached Files
File Type: txt OTL.Txt (167.6 KB, 12 views)
Reply With Quote
  #9  
Old 08-04-12, 18:19
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,162
Thanks: 269
Thanked 1,434 Times in 1,355 Posts
Default Re: Remove Claro-search engine?

Very good Your OTL log is clean now.

If you are not having any other malware related problems, it is time to do our final steps:
  • Any programs we had you download and/or install can be removed at this time.
  • If we had you download and run ComboFix, here is how to uninstall it:
    • Press and hold the Windows key and then press the letter R on your keyboard.
    • This opens the Run dialog box.
    • Copy and paste the below text inside the text-field:
      • "%userprofile%\desktop\ComboFix" /uninstall
    • Now press ENTER
    • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
  • You can re-enable your Disk Emulation software at this time via DeFogger.
  • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
  • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
  • Now we will toggle System Restore to remove any infected system restore points.
  • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
  • Be safe
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
FOXIT Upgrade installed ASK search engine - how can I remove it? George_s Software 12 09-24-10 12:11
Search links not working in any search engine iitsus Malware Removal 1 03-26-08 01:39
Clearing entries in a search engine search bar franklyorange Software 2 02-29-08 17:00
Search Engine a9 SportsNut The Lounge 2 05-25-05 12:36
Unable to remove "bestfind4u.com/index.htm" as search engine for IE hariraghavan Malware Removal 7 01-03-05 01:55


All times are GMT -5. The time now is 00:05.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger