Need Help Getting Rid Of Malware

Discussion in 'Software' started by Jesse Newell, May 14, 2017.

  1. Jesse Newell

    Jesse Newell MajorGeek

    I was having a problem recently with a shortcut icon on my desktop (Windows 8.1 laptop). Although the app (Any Video Converter) opened perfectly normally, the icon itself was just a sheet of white paper. Trying to figure out what the problem might be, I opened Geek Uninstaller and found I had two versions of Any Video Converter (one older, one newer). I tried uninstalling the older version, but that completely removed all traces of the app. So I went to its homepage to redownload the latest version. During installation, I was asked if I wanted to install two optional pieces of junk software (one a browser called Chromium, and the other a Yahoo! something). Before unchecking both boxes, I clicked back just to check I hadn't missed any other "optional extras". When I clicked forward again, the app just started installing, without giving me the option again to unselect the crap. So the crap installed. My homepage was changed from google.com to yahoo.co.uk or whatever, and I found a Chromium shortcut on my desktop. After changing my underwear and cleaning my bowel contents off the floor, I did a system restore. That took about 20 minutes. When the system came back on again, the Chromium shortcut had gone, and my homepage was back to normal. Thinking everything was fine and dandy, I went about my business as usual. However, I've just discovered that when I point to this in Firefox,

    Capture.PNG

    instead of saying "Search with Google" or DuckGoGo or whatever, it says Search using Yahoo! Powered. So I still have this **** on my system. I searched with Everything for Yahoo! Powered and found an xml file that I immediately deleted. I then ran a MalwareBytes scan that found a whopping 366 PUPs. The last MalwareBytes scan I ran found only 9.

    I've attached the complete results,

    As you can see, there are several files that have the word chromium attached to their names, and there are also several yahoo files. Should I just get rid of all these with MalwareBytes? Will that fix the problem? And what about the ByteFence files? Are they harmless or malicious?
     

    Attached Files:

  2. Jesse Newell

    Jesse Newell MajorGeek

    Update: I didn't want to wait anymore for an answer so I got rid of everything that wasn't booking.com or bytefence. Still had yahoo powered in my search bar so had to manually remove it in the Search section of Firefox Options. Should I still worry though, or am I OK for now?
     
  3. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

  4. Jesse Newell

    Jesse Newell MajorGeek


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds