How do I get rid of the Claro Search !
How do I grid rid of this damned Claro Search ?
Soluzione scelta
Please download AdwCleaner and save it on your Desktop. http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner
1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.
2.Click on Delete button.
3.Confirm each time with OK.
4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.
Leggere questa risposta nel contesto 👍 45Tutte le risposte (14)
See these threads and pages about Claro-search:
- [/questions/934685] Firefox Homepage Hijacked by Claro-Search
- [/questions/933520] Whenever I click on plus tab on firefox browser, Isearch.claro page opens up.
- [/questions/934390] How do i get rid of Claro-Search taking over NEW TAB function?
Have cleared Chrome & IE Firefox is harder Unable to remove cookies, see attachment, as they are greyed out will no delete
Soluzione scelta
Please download AdwCleaner and save it on your Desktop. http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner
1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.
2.Click on Delete button.
3.Confirm each time with OK.
4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.
Finally! A fix that worked. It has taken me three days to find this answer. Everything else I found online and tried did not work but this one did. Yay and thanks for that!
Adwcleaner after I installed and ran it, restarted my laptop and told me it had deleted on reboot: Browser Manager Babylon Funmoods plus an entire profile it had created for itself.
I was amazed where these infections probably came from Cnet's download.com See below
http://insecure.org/news/download-com-fiasco.html
I blamed the software authors easeus todo but reading the above the are probably off the hook :-) It will be some time before I point my browser toward download.com
CNET's Download.com is one of the most popular (currently ranked #174 worldwide by Alexa) and longest-running (been around since 1996) major sites on the Internet. As a download repository, their key value ad was that they screened software to avoid malware, spyware, adware, viruses and other harmful content that certain shady software contains. Even many security experts recommended them as a safe place to download software online. Download.com is run by CNET, which is part of the 17-billion dollar CBS media empire. Many people assumed that a major site like this wouldn't resort to unethical monetization schemes like adding spyware and other malware to their downloads.
Unfortunately, those people were wrong. In August 2011, Download.com was taken on a new path by their General Manager and V.P. Sean Murphy. They started wrapping legitimate 3rd party software into their own installer which by default installs a wide variety of adware and other questionable software on users machines. It also does things like redirect user search queries and change their Internet home page. At first their installer forced people to accept the malware or close the installer (see screen shot of infected VLC installer in this article). Later they added a non-default "decline" button hidden way on the left side of the panel. Also, the initial installer shown in the previous screen shot claimed the software was “SAFE, TRUSTED, AND SPYWARE FREE”. In an unusual show of honesty, they removed that claim from the rogue installer.
While it is common for internet criminals to infect software installers in this way, we never expected it from a previously-reputable site like Download.com. Especially given their “Download.com Adware & Spyware Notice” which, until early 2012, said:
“In your letters, user reviews, and polls, you told us bundled adware was unacceptable--no matter how harmless it might be. We want you to know what you're getting when you download from CNET Download.com, and no other download site can promise that.”
and ...
“every time you download software from Download.com, you can trust that we've tested it and found it to be adware-free.”
Wow I did not know that. And I can virtually guarantee it was a download from CNET that gave me the Trojan. Nasty, too - took three days and countless other "fixes" that didn't help to get it off. We trusted CNET! Ah, greed I guess.
AdwCleaner worked for me. I'm sure I got the infection from download.com aka download.cnet.com. The Norton plugins that should have blocked it were disabled, that might not have been related.
None of the 20 or so other recommended solutions I tried (including Malwarebytes and Spybot) worked. There was no sign of Claro or Babylon in the file system, registry, or Programs control panel, but it still showed up as my home page in Firefox.
Download.com is the culprit. I will never download from them again!!
Well wat can i say.....This is first answer i came across on google and WOW :-D its amazing! Worked an #ABSOLUTE #TREAT ...........Thanks very much to person who posted this!!
You have saved me sooooo much time and effort!
A massive #THUMBS-UP :-D
Again Thanks :-D
Cannot not believe i used to download from there years ago and neva had an issue wat soi eva and NOW wat a crock of shit!!
Thanks to all you lots for addin this to the forum and thanks for lettin me kno wher it had come from, For sure i will not b downloadin from ther again!!!!
# AdwCleaner v2.101 - Logfile created 12/20/2012 at 22:15:12 # Updated 16/12/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : ciandlm - CIANDLM-HP # Boot Mode : Normal # Running from : C:\Users\ciandlm\Downloads\adwcleaner(2).exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml File Deleted : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\bprotector_extensions.sqlite File Deleted : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\bprotector_prefs.js ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKU\S-1-5-21-3908336352-2876483464-4255810714-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Mozilla Firefox v12.0 (en-US) Profile name : default File : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\prefs.js Deleted : user_pref("browser.search.order.1", "Claro Search"); Deleted : user_pref("browser.search.selectedEngine", "Claro Search"); Deleted : user_pref("browser.startup.homepage", "hxxp://www.claro-search.com/?affID=117452&tt=5012_1&babsrc=HP[...] Deleted : user_pref("keyword.URL", "hxxp://www.claro-search.com/?affID=117452&tt=5012_1&babsrc=KW_ss&mntrId=ac[...] -\\ Google Chrome v23.0.1271.97 File : C:\Users\ciandlm\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [5716 octets] - [12/12/2012 21:14:58] AdwCleaner[S2].txt - [2177 octets] - [16/12/2012 19:30:49] AdwCleaner[S3].txt - [2074 octets] - [20/12/2012 22:15:12] ########## EOF - C:\AdwCleaner[S3].txt - [2134 octets] ##########
Modificato da cor-el il
# AdwCleaner v2.101 - Logfile created 12/21/2012 at 19:50:30 # Updated 16/12/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Katie - KATIE-HP # Boot Mode : Normal # Running from : C:\Users\Katie\Downloads\adwcleaner(1).exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\ProgramData\Premium File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml File Deleted : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\bprotector_extensions.sqlite File Deleted : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\bprotector_prefs.js Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKU\S-1-5-21-3521296510-1739712518-1077748139-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Mozilla Firefox v17.0.1 (en-US) Profile name : default File : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\prefs.js [OK] File is clean. -\\ Google Chrome v23.0.1271.97 File : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [24747 octets] - [21/12/2012 19:45:54] AdwCleaner[S3].txt - [3107 octets] - [21/12/2012 19:50:30] ########## EOF - C:\AdwCleaner[S3].txt - [3167 octets] ##########
Modificato da cor-el il
Moderator locked this thread - we don't need AdwCleaner logs posted here.