Malware Removal Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by T Slavin, Jun 5, 2023.

  1. T Slavin

    T Slavin Private First Class

    I recently updated to the new version of Firefox and have since been having problems. Malware Bytes stops a threat called " survey-smiles.com.
    I have run the following programs and can not find any problems:
    Malware Bytes, Super Anti Spyware, Hijack This, and Windows Defender.
    I do not see anything that looks out of place or not normal.
    Anyone who has a suggestion please give me a few minutes of your time to remove this.
     
  2. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    survey-smiles is a browser hijacker and/or browser redirect.
    Info here: https://sensorstechforum.com/survey-smiles-com-removal/

    Removal https://sensorstechforum.com/survey-smiles-com-removal/#windows
    Skip step 4 - downloading spyhunter. I avoid installing more programs to get rid of PUA (potentially unwanted applications). I think id Malwarebytes quarantined it and you look for the registry settings you should be clear of it.

    If it still pops up, then you have to look at what addons you've installed.
     
    T Slavin likes this.
  3. T Slavin

    T Slavin Private First Class

    plodr, thank you for your fast reply!

    I will be looking into what you sent me, and as Malwarebytes, it only blocked it from going to the site that would pop up.
    I have not added any new addons in the past 6 months, so I will run the steps that you sent me and then look at the registry.
    I will let you know more in the next couple of days.
    I have to take care of my wife, then work afternoons until 8pm, go home and take care of th ehouse because the wife can't do anything anymore. I am only able to get on the computer after 1am.
     
  4. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    No hurry; I know life gets in the way of what we'd like to do.
     
  5. T Slavin

    T Slavin Private First Class

    I was able to download and run Spyhunter5 and it showed several things that needed to be taken care of, except for survey-smiles.com.
    Then it wanted me to pay $42 to remove what it found, is that normal?
    I am on a fixed income and right now can't afford to pay for it, but I will start saving for it.
    I am sort of surprised that my Malware bytes don't work on this problem and yes it is the paid version.
    Let me know if I need to purchase the spyhunter5 to remove the issues.
     
  6. T Slavin

    T Slavin Private First Class

    Plodr, I re-read what you told me to do and realize that I didn't need to do step 4 with Spyhunter5.
    I need to get another computer setup next to this one so I don't make any mistakes when going through the steps.
    I hope that I can do it without any problems as it seems the older I get the worse my memory gets.
    I will let you know what happens this weekend.
    Thanks Tim
     
  7. T Slavin

    T Slavin Private First Class

    Plodr,
    I have not been able to find the problem in the registry after following the file path from Malware Bytes to locate it.
    I have never tried anything like this before and really have no clue what to do at this point.
    I will try to copy a log of the registry and post it for you tho help when I can figure that out.
    I will try to have it for you in a couple of days.
    Do you suggest any program to assist me in this.
     
  8. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Don't bother. I'm not about to look over a log of your registry - too many entries.
    In the search/run box type regedit and press enter.

    Look here HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    expand HKEY_LOCAL_MACHINE
    expand Software
    expand Microsoft
    expand Windows
    expand Current Version
    click on Run

    Do you see anything that says survey smiles?
     
    T Slavin likes this.
  9. T Slavin

    T Slavin Private First Class

    plodr,

    I checked everything and could not find anything that said survey-smiles, but I did find something that says "The Sea App".
    I do not know how it got on my computer and I hope to remove it soon also.
    Is there anywhere else to check for survey-smiles or could it be part of The Sea App?

    Sorry if I sound stupid or dense in my old age, but this has gotten under my skin. I spent hours looking in almost every folder in the registry and only came up with what I found. I know that I don't know all the new problems of today like I did several years ago, but I am trying.
    Once again Thank You for your kind help.
     
  10. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    There are 3 other registry places you can check.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

    I never heard of sea app. This is probably it - unwanted adware
    https://www.pcrisk.com/removal-guides/7025-remove-theseaapp-adware
     
    T Slavin likes this.
  11. T Slavin

    T Slavin Private First Class

    I have gone through all the other registry places and still don't see anything with the name of "survey-smiles.com" or any with a partial name.
    I have deleted "The Sea App" from the registry and will keep looking for any other places for that also.
    I will update you in a couple of days if I find anything.
    Thank you, Tim
     
  12. T Slavin

    T Slavin Private First Class

    I finally had time to go through every item in the registry but had no luck finding anything with the words survey-smiles.com.
    I have no idea where to look next or what to do about it and it is driving me crazy trying to find it.
    Any more help would be greatly appreciated.
    Thanks, Tim
     
  13. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Are you still getting browser re-directs?
     
  14. T Slavin

    T Slavin Private First Class

    Yes they are still going on.
     
  15. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

  16. T Slavin

    T Slavin Private First Class

  17. T Slavin

    T Slavin Private First Class

    Since restarting FF and resetting the options I have not had the problem since.
    I wonder why things had changed with FF since I have not changed my setting for over a year.
    I will keep you updated on this problem and possible fix.
    Thanks Tim
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds