SEARCHNU/406 I cant get rid of it!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vindication, Oct 12, 2012.

  1. Vindication

    Vindication Private E-2

    Ok I've got a problem which seems alot of people have, I have read both the threads already made about the searchnu thing but I still cant get rid of it. I did everything in the READ ME FIRST area of the forum and but I am still having the same problem. Everytime I open by browser (Google Chrome) its opens two tabs, my home page, and another one searchnu.com/406. How can I get rid of this? PLEASE HELP! THANKS!
     

    Attached Files:

    Last edited by a moderator: Oct 13, 2012
  2. Vindication

    Vindication Private E-2

    I also did the browser redirecting walkthrough. Here is the log from it if you need it.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  4. Vindication

    Vindication Private E-2

    I ran the program, here's the log. Thank you very much for taking the time out of your day to help me with my problem, great response time also!
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Take a look at this:

    Warning about Porn, Keygens, Cracks, and other Illegal Software

    Delete this folder unless you know what it contains.

    C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. Vindication

    Vindication Private E-2

    So I deleted the folder C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69.
    Then I made fixME.reg, ran it, and it did merge successfully.
    And I did the last step which was running the OTL.exe and I ran it to your specifications. The logs you asked for are attached. Again thank you for replying so fast. I really appreciate it. I do still have to problem. When I open up Google Chrome it opens two different tabs. My homepage, facebook.com, and the other which is searchnu/406. However this doesnt happen to Microsoft Internet Explorer, only Chrome. We never use IE I'm guessing thats the reason.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please use Revo Uninstaller to remove Google Chrome.

    Reboot, then reinstall and then tell me if you still have the problem.
     
  8. Vindication

    Vindication Private E-2

    Sorry for not being able to reply in so long but the answer is no... I downloaded the Revo uninstaller and uninstalled Google Chrome and everything that came with it including registry entries and things like that. Then I rebooted, reinstalled, rebooted again, and finally launched the application. But unfortunately I still have the same problem. Do you think that this Malware problem might be going through the network? Sorry if this sounds stupid. But my other desktop computer had it first and now the laptop has it. But it was a month before the searchnu :crap showed up on this comp. I dont know, just a thought. I'm willing to try anything at thing point. This thing is really starting to get under my skin!!! :banghead
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this and attach the results.

    Using ESET's Online Scanner



    Please download SystemLook 64 bit
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      searchnu
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  10. Vindication

    Vindication Private E-2

    Well I ran both of the scans, and I think one of them found 8 different threats, from trojans to malware. Sadly I still have the original problem.:cry This searchnu thing is really in there...Anyways thanks for being so patient with this, here are the logs you requested.
     

    Attached Files:

  11. Vindication

    Vindication Private E-2

    Sorry!!! I forgot the other logs!!! Here they are...
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )
     
  13. Vindication

    Vindication Private E-2

    Ran the Junkware Removal Tool, still having the problem :(
     

    Attached Files:

    • JRT.txt
      File size:
      5.4 KB
      Views:
      2
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download Combofix to your desktop. Please refer to these instructions prior to running. Attach the log once done.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds