I am trying to remove iclaro from my computer/browsers

Discussion in 'Malware Help (A Specialist Will Reply)' started by alverton, Sep 4, 2012.

  1. alverton

    alverton Private E-2

    Hi I have followed your excellent and simple to follow instructions online under the Read Me First instructions and there for attach the requested log files. Currently when I open a new tab in Firefox I get the following page refused by Trend Micro Titantium Max Security

    http://isearch.claro-search.com/?af...iclro&mntrId=a205b9ed00000000000000ff0ddc3d06

    I also have a tdskiller log but reached the max of five files in this post.

    Looking forward to your reply.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I strongly recommend that you uninstall ALL of the below adware which has added undesireable and unwanted/unnecessary toolbars to your browsers.
    BitTorrent
    BitTorrentBar Toolbar
    Conduit Engine
    Expat Shield 2.24
    Expat Shield Toolbar

    Have you read the Privacy Policy of Expat Shield?
    You have the below malware on your PC:
    http://about-threats.trendmicro.com/us/malware/WORM_KELIHOS.SM


    Please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\ProgramData\Ask
    C:\ProgramData\Babylon
    C:\ProgramData\boost_interprocess
    C:\Users\All Users\Application Data\boost_interprocess
     
    :Reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{762CA3DE-93FC-48FF-9DE7-0DA52292C21A}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7E5082E3-2D07-4490-8DEE-6F71F46F88D6}]
     
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:

    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. alverton

    alverton Private E-2

    Dear ChasLang

    Thank you for your detailed reply. I have stepped through all your instructions. The only one I did not understand was the reference to the Kelios worm - was I supposed to follow the instructions on that url? I did not because they refered to an earlier version of windows than 7.

    After completion of everything else I report that in Firefox when I open a new tab it opens the Claro 2012 search page - despite the default broser being sent to Google and the default home page being set to the Mozilla home page.

    I attach the files that you have requested.

    Looking forward to your furthe advice.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! That was just an FYI.

    This may require an uninstall, cleanup folders and reinstall. However have you check Firefox > Options > Manage Addons to see if anything from Claro is there. Also check the search addons


    Empty your recycle bin too. I want to make sure the below go away.
    C:\$Recycle.Bin\S-1-5-21-2479586879-1573352390-180901207-1004\$I36LY5O.exe
    C:\$Recycle.Bin\S-1-5-21-2479586879-1573352390-180901207-1004\$R36LY5O.exe
     
  5. alverton

    alverton Private E-2

    Dear ChasLang

    Ok good news. I emptied the trash (although the two files that you mentioned were not in there as far as I could see).

    I uninstalled firefox after backing up my bookmarks (incase the profile is corrupted) and profile. I then deleted the profile and reinstalled firefox without importing any data from other versions or browsers.

    Firefox now appears to be clean of iclaro.

    I will see how it goes for a few days.

    Finally, thank you profusely for your patience and help - this has to be one of the best geek websites on the net.

    Thanks again and I hope your postings and my feedback helps others.

    alverton
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds