Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Warning for "URL http://4dmng.com/FIF/sfan404fif5.exe"


  • Please log in to reply
11 replies to this topic

#1 paw51

paw51

  • Members
  • 81 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:34 PM

Posted 18 February 2014 - 03:16 PM

My laptop has been acting strangely.  Today after asking for Firefox to start I got a warning, instructed Avast to not open that URL, and looked at details which were as above in topic.  Earlier, for the past few weeks, Firefox frequently stops working and goes somewhere a few pages back when doing this.  It knows it is not working and says so at the top left of the page.  Most of the time a little patience brings all back to normal.  Rarely, I must "hard shutdown" and start over.

.

Looks like my Dell Latitude/E6400 laptop, running Vista Business Service Pack 2 has gotten infected.  Here are some details you might wish:

 

Processor: Intel Core 2 Duo CPU

RAM: 6.0 Gb

64 vbit operating system

 

Security programs:

Avast Premium w/Safe Zone

Win Patrol (free version)

 

Please help.

 

Pat Armstrong



BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • BC Advisor
  • 12,986 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:34 PM

Posted 18 February 2014 - 03:48 PM

4dmng, oddly enough, is a Dell laptop battery identifier. But that doesn't explain the URLthat is either blocked or unreachable on my comp. Use the programs below to

find and remove adware and other malware that may be on your computer.

 

http://www.malwarebytes.org/mbam.php
Download MBAM from link above.
* Double-click on mbam-setup.exe to install the application.
* When the installation begins, follow the prompts and do not make any changes to default settings.
* When installation has finished, make sure you leave both of these checked:
o Update Malwarebytes' Anti-Malware
o Launch Malwarebytes' Anti-Malware
* Then click Finish.

MBAM will automatically start and you will be asked to update the program before performing a scan.

* If an update is found, the program will automatically update itself.
* Press the OK button to close that box and continue.
On the Scanner tab:

* Make sure the "Perform Quick Scan" option is selected.
* Then click on the Scan button.
* If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
* The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
* When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
* Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

* Click on the Show Results button to see a list of any malware that was found.
* Make sure that everything is checked, and click Remove Selected.
* When removal is completed, a log report will open in Notepad.
* The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
* Copy and paste the contents of that report in your next reply and exit MBAM.

Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you after scanning with MBAM. Please temporarily disable such programs or permit them to allow the changes.

 

download AdwCleaner to your desktop.

 

  • Run adwcleaner.exe
  • Hit Scan and wait for the scan to finish.
  • Confirm the message but don´t uncheck anything.
  • Hit Clean
  • When the run is finished, it will open up a text file
  • Please post its contents within your next reply
  • You´ll find the log file at C:\AdwCleaner[S1].txt also

 

 

 

 

download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file....
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#3 paw51

paw51
  • Topic Starter

  • Members
  • 81 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:34 PM

Posted 19 February 2014 - 02:59 PM

I also wanted to report that FF keeps saying it is not working.  Usually, if you let it alone everything is OK.  But not always.  I can give more details if you need them.  Upon start up I received the same messge which prompted this correspondence.

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.02.19.07

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Pat :: MININT-1KDBOVV [administrator]

2/19/2014 7:21:14 AM
mbam-log-2014-02-19 (07-21-14).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239194
Time elapsed: 4 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 

 

***** [ Files / Folders ] *****

[!] Folder Deleted : C:\Users\Pat\AppData\Roaming\Common\LuaRT

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DataMgr]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3BC93E76-92F8-5FDA-B676-5AFEE3735BF1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3BC93E76-92F8-5FDA-B676-5AFEE3735BF1}
Key Deleted : HKCU\Software\OfferMosquito
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{DD85D6BF-4787-4A93-99A5-3F0CF0AE8834}
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\Wincert\WIN64C~1.DLL

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16533


-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\xo07p3hm.default-1390688603177\prefs.js ]

Line Deleted : user_pref("extensions.browserprotect.searchProviderExceptions", "hxxp://en.wikipedia.org/wiki/Special:Search;hxxp://search.yahoo.com/search;hxxp://www.amazon.com/exec/obidos/external-search/;hxxp://ww[...]
Line Deleted : user_pref("om.config", "{\"active\":true,\"name\":\"jan2014\",\"id\":36,\"dispId\":\"CH-36\",\"aboutLink\":\"\",\"trackingGeneral\":false,\"xhrDomains\":[\"become\",\"shopzilla\",\"twenga\",\"bizrate\[...]

*************************

AdwCleaner[R0].txt - [2441 octets] - [18/12/2013 15:30:54]
AdwCleaner[R1].txt - [897 octets] - [21/01/2014 16:46:43]
AdwCleaner[R2].txt - [956 octets] - [21/01/2014 16:49:06]
AdwCleaner[R3].txt - [1202 octets] - [23/01/2014 21:53:30]
AdwCleaner[R4].txt - [1621 octets] - [25/01/2014 16:09:52]
AdwCleaner[R5].txt - [3407 octets] - [19/02/2014 07:27:20]
AdwCleaner[S0].txt - [2297 octets] - [18/12/2013 15:34:50]
AdwCleaner[S1].txt - [1016 octets] - [21/01/2014 16:49:43]
AdwCleaner[S2].txt - [1266 octets] - [23/01/2014 21:54:18]
AdwCleaner[S3].txt - [1702 octets] - [25/01/2014 16:10:40]
AdwCleaner[S4].txt - [3101 octets] - [19/02/2014 07:31:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [3161 octets] ##########

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows ™ Vista Business x64
Ran by Pat on Wed 02/19/2014 at  7:49:28.68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\Pat\AppData\Roaming\mozilla\firefox\profiles\xo07p3hm.default-1390688603177\prefs.js

user_pref("extensions.browserprotect.urlBarExceptions", "hxxp://www.google.com;hxxp://search.yahoo.com;hxxp://search.live.com;hxxp://en.wikipedia.org;chrome://*;chrome://brows
Emptied folder: C:\Users\Pat\AppData\Roaming\mozilla\firefox\profiles\xo07p3hm.default-1390688603177\minidumps [10 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 02/19/2014 at  7:56:05.30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

ESET scan showed no malicious items and produced no logl.



#4 buddy215

buddy215

  • BC Advisor
  • 12,986 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:34 PM

Posted 19 February 2014 - 03:55 PM

You had a mix of adware...as you can see in the logs.

In Firefox, click on help and then click on disable add-ons. Try running without add-ons long enough to tell if that message is seen again or not.

If it doesn't show up, add each add-on back one at a time until you find the one causing the message.

 

Use CCleaner's default settings to cleanup the caches, logs, cookies, etc. Pay close attention while installing and UNcheck offers of toolbars...especially Yahoo.

CCleaner - PC Optimization and Cleaning - Free Download

 

One or more of the items removed by tools previously used may have made changes that need to be corrected. Use Windows Repair (All In One) Download

 

EDIT:  What version of Firefox do you have....27 or other?


Edited by buddy215, 19 February 2014 - 04:14 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#5 paw51

paw51
  • Topic Starter

  • Members
  • 81 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:34 PM

Posted 19 February 2014 - 08:00 PM

I have already removed Adblock Plus and and use CCleaner Free about once or twice a week.  I have Firefox 27.0.1.  Also I get that warning message before I open anything on my computer.  Am going to disable add-ons, close computer and try again.

 

Pat



#6 buddy215

buddy215

  • BC Advisor
  • 12,986 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:34 PM

Posted 19 February 2014 - 08:11 PM

Yeah, I noticed a bit ago when I updated another comp that 27 has been updated.

Why did you remove Adblock Plus? If it was because it allows some ads then that can be changed in its preferences to block all.

 

I know nothing about Avast settings or messages, but couldn't that message be something Avast wants you to respond to someway?

Ever open up its GUI and poke around? Somehow I was thinking you only saw that when Firefox opened.

That URL is dead according to OpenDNS...my DNS server. When it shows up again, right click on it and see if you can get some info

maybe 'properties'.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#7 paw51

paw51
  • Topic Starter

  • Members
  • 81 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:34 PM

Posted 20 February 2014 - 09:05 PM

When the message shows up, Avast gives the option to mark it as a false positive.  I did not want to do this if it was caused by a virus.  Will request it be changed to false positive next start up.

 

Last night, late, I checked my Big Fish Games account and found I could "buy" two games with the credits I had accrued.  I have an account with them which debits my debit card once a month and then I get a game for free every month.  I have used Big Fish for about 3 years with no problems, but last night I had to reinstall the game manager.  I made sure I was doing a custom install so I did not add something unwanted, and still ended up with default-search which I thought I had just gotten rid of.  Ugggg!  I want to go back to Adblock Plus and am going to do so tonight. 

 

I googled how to get rid of default-search on Firefox and Explorer.  I worked on Explorer just in case I use it.  Firefox is my default browser.  I have had no luck and don't see default-search in Control Panel: Uninstall Programs.

 

I'm guessing Big Fish Games has changed and is now sneaking in stuff I don't want.  Too bad, I really liked their games.  Should I just uninstall the games manager and dump the games I downloaded last night or is there a way to get rid of this search engine without losing my games.



#8 buddy215

buddy215

  • BC Advisor
  • 12,986 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:34 PM

Posted 20 February 2014 - 10:19 PM

One of those programs in my first post will probably remove the default-search....

Yeah, that's foistware or foist install of adware...no chance to deny its install.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#9 paw51

paw51
  • Topic Starter

  • Members
  • 81 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:34 PM

Posted 21 February 2014 - 05:09 PM

Here are the logs again. Looks to me like all is fine, but I still have default-search as my search engine. I also remember accidently downloading Speed Up My PC. I guess that is where this junk came from. I uninstalled SUMPC, but this search engine was left behind.

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.02.21.09

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Pat :: MININT-1KDBOVV [administrator]

2/21/2014 12:38:25 PM
mbam-log-2014-02-21 (12-38-25).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239003
Time elapsed: 3 minute(s), 32 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


# AdwCleaner v3.019 - Report created 21/02/2014 at 14:49:24
# Updated 17/02/2014 by Xplode
# Operating System : Windows ™ Vista Business Service Pack 2 (64 bits)
# Username : Pat - MININT-1KDBOVV
# Running from : C:\Users\Pat\Downloads\adwcleaner(3).exe
# Option : Clean

***** [ Services ] *****

Opening a new tab still shows unwanted search engine.


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{DD85D6BF-4787-4A93-99A5-3F0CF0AE8834}

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16533


-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\xo07p3hm.default-1390688603177\prefs.js ]


*************************

AdwCleaner[R0].txt - [2441 octets] - [18/12/2013 15:30:54]
AdwCleaner[R1].txt - [897 octets] - [21/01/2014 16:46:43]
AdwCleaner[R2].txt - [956 octets] - [21/01/2014 16:49:06]
AdwCleaner[R3].txt - [1202 octets] - [23/01/2014 21:53:30]
AdwCleaner[R4].txt - [1621 octets] - [25/01/2014 16:09:52]
AdwCleaner[R5].txt - [3407 octets] - [19/02/2014 07:27:20]
AdwCleaner[R6].txt - [4263 octets] - [20/02/2014 22:14:35]
AdwCleaner[R7].txt - [2039 octets] - [21/02/2014 14:47:12]
AdwCleaner[S0].txt - [2297 octets] - [18/12/2013 15:34:50]
AdwCleaner[S1].txt - [1016 octets] - [21/01/2014 16:49:43]
AdwCleaner[S2].txt - [1266 octets] - [23/01/2014 21:54:18]
AdwCleaner[S3].txt - [1702 octets] - [25/01/2014 16:10:40]
AdwCleaner[S4].txt - [3245 octets] - [19/02/2014 07:31:28]
AdwCleaner[S5].txt - [4230 octets] - [20/02/2014 22:56:02]
AdwCleaner[S6].txt - [1792 octets] - [21/02/2014 14:49:24]

########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt - [1852 octets] ##########


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows ™ Vista Business x64
Ran by Pat on Fri 02/21/2014 at 15:02:32.39
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Pat\appdata\locallow\datamngr"



~~~ FireFox

Successfully deleted the following from C:\Users\Pat\AppData\Roaming\mozilla\firefox\profiles\xo07p3hm.default-1390688603177\prefs.js

user_pref("extensions.browserprotect.urlBarExceptions", "hxxp://www.google.com;hxxp://search.yahoo.com;hxxp://search.live.com;hxxp://en.wikipedia.org;chrome://*;chrome://brows



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 02/21/2014 at 15:08:36.23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=012e8889b9540746bdaa288fdb72883d
# engine=17141
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-19 06:46:01
# local_time=2014-02-19 12:46:01 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=772 16777213 83 82 0 10360044 0 0
# compatibility_mode=5892 16776574 100 100 20354910 229434386 0 0
# scanned=144424
# found=0
# cleaned=0
# scan_time=2887
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=012e8889b9540746bdaa288fdb72883d
# engine=17174
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-21 09:58:17
# local_time=2014-02-21 03:58:17 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=772 16777213 83 82 0 10544380 0 0
# compatibility_mode=5892 16776574 100 100 20539246 229618722 0 0
# scanned=146876
# found=0
# cleaned=0
# scan_time=2753

#10 buddy215

buddy215

  • BC Advisor
  • 12,986 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:34 PM

Posted 21 February 2014 - 06:10 PM

Open Firefox and next to the Google icon in the little search box on the right you will see a small arrow. Click on that arrow which will

allow you to see a list of search engines. Delete all but Google...if that is your default search engine.

Sometimes that is all that is needed.

 

Check your add-ons in all browsers for unknown extensions and plugins. Remove or disable any you don't recognize as being installed by you.

 

You can also check your Add/ Remove list for the programs you installed and attempt to uninstall them. Especially that Speed Up My PC.

 

You can use CCleaner for uninstalling programs, too. It has another useful feature that will show you what programs are in startup of browsers

and Windows. It allows you to block there startup. Preventing programs such as Office programs, media players, Java, etc. can reduce 

boot time and you might just see something in startup of your browsers that you want to kill.


Edited by buddy215, 21 February 2014 - 06:18 PM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”


#11 paw51

paw51
  • Topic Starter

  • Members
  • 81 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:34 PM

Posted 22 February 2014 - 02:22 PM

I have used FF options to change my search engine.  I also entered about:config and changed to Google.  I used CCleaner after I uninstalled Speed Up My PC.  I have very few add-ons, two for weather watching, Forecast Fox and Rain Alarm, Adblock Edge, Avast, NoScript and Settings Manager.  Today I still have this rogue search engine.  Please help me get rid of it.



#12 buddy215

buddy215

  • BC Advisor
  • 12,986 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:04:34 PM

Posted 22 February 2014 - 03:35 PM

Use this again or if you haven't used it. Windows Repair (All In One) Download

 

If that doesn't solve the problem then post your problem in Virus, Trojan, Spyware, and Malware Removal Logs Forum - BleepingComputer.com forum

and following instruction #6 in this guide for creating a DDS log...Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help - Virus, Trojan, Spyware, and Malware Removal Logs


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss

A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users