iSearch.Claro-Search malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Haruhi, Sep 8, 2012.

  1. Haruhi

    Haruhi Private E-2

    I'm willing to try anything at this point. I'll attach the necessary information.
     
    Last edited by a moderator: Sep 12, 2012
  2. thisisu

    thisisu Malware Consultant

    Ok, I'm going to attempt to log in now. Notice I have removed the attachment.
     
  3. Haruhi

    Haruhi Private E-2

    Just wanted to check in and let you know things are still looking 100% fine. No sign of Claro anywhere. I've done a reboot since your session, and still no sign. Crossing my fingers and hoping it was the end of it. Thanks again, Thisisu and everyone else on the Major Geeks team. Hopefully I wont be talking to you guys anytime soon, but I know if I need to, I'll get my problems fixed.


    Take care guys and keep up the great work!:)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please update this thread with information on what actions needed to be taken to get this fixed so that other people may benefit from it.
     
  5. thisisu

    thisisu Malware Consultant

    1. I went back into about:config via FireFox
    2. Searched for: claro
    3. Reset each of those strings to their default values.
    4. Then during the same FireFox session, did the steps better illustrated by the attached screenshot.
    5. Pressed OK afterwards in FireFox Options (exits / saves options).
    6. Closed FireFox.
    7. Re-opened FireFox, problem was gone.

    Did a bit more investigating and found this APPINIT DLL from Autoruns (also seen by runkeys.txt)

    Code:
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows
       AppInit_DLLs	REG_SZ         	c:\progra~3\browse~1\22565~1.25\{16cdf~1\browse~1.dll
    OTL
    Deleted this value (using Autoruns), and also deleted this folder (was stubborn, so I was used OTL which required a reboot) c:\ProgramData\Browser Manager

    Not sure if Browser Manager was related at all but just wanted to be thorough before I rebooted the machine :)
     

    Attached Files:

    Last edited: Sep 12, 2012
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well since uninstalling Firefox and deleting the folders would have removed all Firefox settings including everything mention in about:config for Claro, I have to assume that it may have been the Brower Manager program mentioned that was the underlying issue.

    Also previously AVG was also getting in the way of cleaning up registry settings and possibly some files.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds