Ready For Another Claro Adventure?

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheComposer, Sep 22, 2012.

  1. TheComposer

    TheComposer Private E-2

    I realized immediately when I got claro, which was yesterday. I system restored thinking it would help (I read things that told me not to after, d'oh) after I had gotten rid of Claro progams on my program list, and all babylon folders in my registry. At first I thought it worked, the toolbar was gone, and none of the claro extensions show up in my firefox's about:config. HOWEVER, when I go to Manage Search engines and click restore to default, Claro shows up there. So that probably means it's still SOMEWHERE. So I ran everything from the read and run me first and I have attached the logs.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. TheComposer

    TheComposer Private E-2

    Here are the files as requested.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any Claro items in your logs. Let's do this, however:

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    C:\ProgramData\Babylon
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.


    Now go back to Manage Search engines and delete and reference to Claro.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. TheComposer

    TheComposer Private E-2

    For now, it seems that it has been removed from my Firefox, because the Restore Defaults button can't be pressed (I'm guessing because now it's at default settings) and claro isn't there. In any case, here are the logs you requested.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. TheComposer

    TheComposer Private E-2

    What should I do with the files that were put into the OTL folder? Just leave them there, delete them, or what? o-o

    Edit: Nevermind, should have read everything before commenting. I see that MGclean.bat cleaned up the OTL folder. Thanks for everything.
     
    Last edited: Sep 22, 2012
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  9. TheComposer

    TheComposer Private E-2

    Oh, one last question. Should I reset my items in my about:config in case claro changed any of them, or should it be fine?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Wouldn't hurt. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds