Adlice forum

General Category => Malware removal help => Topic started by: Mars on July 15, 2016, 05:55:35 AM

Title: safesearch homepage browser hijacker infection ****FIXED*****
Post by: Mars on July 15, 2016, 05:55:35 AM
Hi there, RogueKiller is the only app Iv found that can detect this regenerating infection, but it replaces itself constantly. How do I get rid?? Im starting to have system errors now..... eg. Cannot uninstall Mozilla????

Attached last scan, still there but cannot access Mozilla now.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 06:56:40 AM
ok iv managed to get Mozilla back, it was showing a 'Couldn't load XPCOM' message.

I went to Mozilla download page and downloaded it over the top of the old one and its updated and fixed itself, now just couple of 'profile' issues where the beast is lurking....
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 11:38:53 AM
These are the 3 profiles for Mozilla that I need to 'clean' somehow, I dont know what files should be in there and what shouldnt; one must be a legit profile for me but infected, iv taken lots of screenies of whats contained within. Just doing a RK scan now to see what it picks up and will attach latest report shortly, thank you
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 12:04:22 PM
Just scanned. It is the last 2 detections foundsitting in the IE and Mozilla areas... (Im ignoring the wordpad entries.)
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 12:10:48 PM
Hi Mars,

Welcome to Adlice.com Forum.

I think there is a misunderstanding
The WPAD detections are false positives, they are legit entries.

Concerning the [PUM.SearchPage] ones :
PUM stands for Potentially Unwanted Modification. In your case, these entries are perfectly legit.
For more information, please read RogueKiller Documentation (http://www.adlice.com/software/roguekiller/documentation/).

Regards.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 12:36:02 PM
Hi thank you, so its gone!!!??????

And the profiles there are ok?

And the PUM RK is finding are ok to NOT remove??

I cant believe it!
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 12:41:45 PM
Hi Mars,

I think so.
Do you want me to thoroughly analyse your computer to make sure ?

Regards.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 12:43:33 PM
This is my registry Hkey Users, does that look ok? I should be only user plus administrator back up account.

I wonder if it was gone before I purchased RK? I dont care, its a great program!
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 12:45:27 PM
Hi Mars,

I think so.
Do you want me to thoroughly analyse your computer to make sure ?

Regards.


Would you? This has been giving me stress for over a month. Killed my pc had to factory reset lost a load of stuff.
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 12:48:56 PM
Hi Mars,

The HKEY_USERS hive may contains multiple entries.
Please download Farbar Recovery Scan Tool (x86) (http://download.bleepingcomputer.com/farbar/FRST.exe) and save it to your Desktop.
Regards.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 12:50:02 PM
ok will do thank you!
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 12:59:25 PM
FarBar scan results.

I think when I reset to factory I gave the computer a different name than my old one?? That has affected restoring from back up. Can that be changed?

Thank you Im so impressed!!!
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 01:39:09 PM
Hi Mars,

Yes, you can change your computer name at will : Change Your Computer Name in Windows 7, 8, or 10 (http://www.howtogeek.com/howto/windows-vista/change-your-computer-name-in-windows-vista/)
Did you install Nanoheal Client yourself ?

Regards.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 01:45:53 PM
great!

no it was installed by tech support, not installed but still showing, thats where i heard of RK :)
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 01:51:52 PM
Hi Mars,

Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.

How is the computer running now ?

Regards.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 02:03:36 PM
Its a bit bumpy, had to change permissions to access files from back up, lost my Office app and the license was on the PC, its in my back up but it didnt restore all files. Its been a dreadful experience to say the least, damn hacker peeps!

I will do your instructions now.....
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 02:12:59 PM
FRST asked to be restarted and then was closed at restart. There is a log file attached. Was it messy in there? Has it cleaned up ok? Thank you so much for your help, Iv actually had nightmares about it all  ;D
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 02:25:58 PM
Hi Mars,

It's all right, your computer is clean.
You could now delete FRST and the files linked to it.

Regards.
Title: Re: safe search browser hijacker infection HELP!
Post by: Mars on July 15, 2016, 02:31:35 PM
Thats fantastic. I really appreciate your help. Thats one nasty virus.....

Have a great day. Is there anything I can do for you? I know 10 star jumps, just for you ok. Thank you so much.
Title: Re: safe search browser hijacker infection HELP!
Post by: Curson on July 15, 2016, 02:36:59 PM
Hi Mars,

You are very welcome. :)
I'm glad I was able to help you.

Regards.