X
Tap here to go to the mobile version of the site.
Your Firefox is out of date and may contain a security risk! Upgrade Firefox

Support Forum

How do I get rid of the Claro Search !

Posted

How do I grid rid of this damned Claro Search ?

Chosen solution

Please download AdwCleaner and save it on your Desktop. http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner

1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.

2.Click on Delete button.

3.Confirm each time with OK.

4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

Read this answer in context 45

Additional System Details

Installed Plug-ins

  • The QuickTime Plugin allows you to view a wide variety of multimedia content in Web pages. For more information, visit the QuickTime Web site.
  • Shockwave Flash 11.5 r502
  • SiteAdvisor
  • Facebook Video Calling Plugin
  • Google Update
  • McAfee MSC FF plugin DLL
  • iTunes Detector Plug-in
  • DNL Reader
  • 5.1.10411.0
  • Adobe PDF Plug-In For Firefox and Netscape 10.1.4
  • ActiveTouch General Plugin Container Version 105
  • Best Buy pc app Detector Plug-in
  • GEPlugin
  • Yahoo Application State Plugin version 1.0.0.7
  • Coupons, Inc. Coupon Printer DLL
  • The plug-in allows you to open and edit files using Microsoft Office applications
  • npdnupdater2

Application

  • User Agent: Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0

More Information

cor-el
  • Top 10 Contributor
  • Moderator
10761 solutions 96861 answers

See these threads and pages about Claro-search:

balsamlake 1 solutions 4 answers

Have cleared Chrome & IE Firefox is harder Unable to remove cookies, see attachment, as they are greyed out will no delete

balsamlake 1 solutions 4 answers

Chosen Solution

Please download AdwCleaner and save it on your Desktop. http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner

1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.

2.Click on Delete button.

3.Confirm each time with OK.

4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

poppin2 0 solutions 2 answers

Finally! A fix that worked. It has taken me three days to find this answer. Everything else I found online and tried did not work but this one did. Yay and thanks for that!

Adwcleaner after I installed and ran it, restarted my laptop and told me it had deleted on reboot: Browser Manager Babylon Funmoods plus an entire profile it had created for itself.

balsamlake 1 solutions 4 answers

I was amazed where these infections probably came from Cnet's download.com See below

http://insecure.org/news/download-com-fiasco.html

I blamed the software authors easeus todo but reading the above the are probably off the hook :-) It will be some time before I point my browser toward download.com

CNET's Download.com is one of the most popular (currently ranked #174 worldwide by Alexa) and longest-running (been around since 1996) major sites on the Internet. As a download repository, their key value ad was that they screened software to avoid malware, spyware, adware, viruses and other harmful content that certain shady software contains. Even many security experts recommended them as a safe place to download software online. Download.com is run by CNET, which is part of the 17-billion dollar CBS media empire. Many people assumed that a major site like this wouldn't resort to unethical monetization schemes like adding spyware and other malware to their downloads.

Unfortunately, those people were wrong. In August 2011, Download.com was taken on a new path by their General Manager and V.P. Sean Murphy. They started wrapping legitimate 3rd party software into their own installer which by default installs a wide variety of adware and other questionable software on users machines. It also does things like redirect user search queries and change their Internet home page. At first their installer forced people to accept the malware or close the installer (see screen shot of infected VLC installer in this article). Later they added a non-default "decline" button hidden way on the left side of the panel. Also, the initial installer shown in the previous screen shot claimed the software was “SAFE, TRUSTED, AND SPYWARE FREE”. In an unusual show of honesty, they removed that claim from the rogue installer.

While it is common for internet criminals to infect software installers in this way, we never expected it from a previously-reputable site like Download.com. Especially given their “Download.com Adware & Spyware Notice” which, until early 2012, said:

   “In your letters, user reviews, and polls, you told us bundled adware was unacceptable--no matter how harmless it might be. We want you to know what you're getting when you download from CNET Download.com, and no other download site can promise that.”


and ...

   “every time you download software from Download.com, you can trust that we've tested it and found it to be adware-free.”
poppin2 0 solutions 2 answers

Wow I did not know that. And I can virtually guarantee it was a download from CNET that gave me the Trojan. Nasty, too - took three days and countless other "fixes" that didn't help to get it off. We trusted CNET! Ah, greed I guess.

rlauriston 0 solutions 1 answers

Helpful Reply

AdwCleaner worked for me. I'm sure I got the infection from download.com aka download.cnet.com. The Norton plugins that should have blocked it were disabled, that might not have been related.

None of the 20 or so other recommended solutions I tried (including Malwarebytes and Spybot) worked. There was no sign of Claro or Babylon in the file system, registry, or Programs control panel, but it still showed up as my home page in Firefox.

commlines 0 solutions 1 answers

Download.com is the culprit. I will never download from them again!!

J4ybo 0 solutions 2 answers

Well wat can i say.....This is first answer i came across on google and WOW :-D its amazing! Worked an #ABSOLUTE #TREAT ...........Thanks very much to person who posted this!!

You have saved me sooooo much time and effort!

A massive #THUMBS-UP :-D

Again Thanks :-D

J4ybo 0 solutions 2 answers

Cannot not believe i used to download from there years ago and neva had an issue wat soi eva and NOW wat a crock of shit!!

Thanks to all you lots for addin this to the forum and thanks for lettin me kno wher it had come from, For sure i will not b downloadin from ther again!!!!

cianlim 0 solutions 1 answers
# AdwCleaner v2.101 - Logfile created 12/20/2012 at 22:15:12
# Updated 16/12/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : ciandlm - CIANDLM-HP
# Boot Mode : Normal
# Running from : C:\Users\ciandlm\Downloads\adwcleaner(2).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\bprotector_extensions.sqlite
File Deleted : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\bprotector_prefs.js

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKU\S-1-5-21-3908336352-2876483464-4255810714-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (en-US)

Profile name : default 
File : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\prefs.js

Deleted : user_pref("browser.search.order.1", "Claro Search");
Deleted : user_pref("browser.search.selectedEngine", "Claro Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://www.claro-search.com/?affID=117452&tt=5012_1&babsrc=HP[...]
Deleted : user_pref("keyword.URL", "hxxp://www.claro-search.com/?affID=117452&tt=5012_1&babsrc=KW_ss&mntrId=ac[...]

-\\ Google Chrome v23.0.1271.97

File : C:\Users\ciandlm\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [5716 octets] - [12/12/2012 21:14:58]
AdwCleaner[S2].txt - [2177 octets] - [16/12/2012 19:30:49]
AdwCleaner[S3].txt - [2074 octets] - [20/12/2012 22:15:12]

########## EOF - C:\AdwCleaner[S3].txt - [2134 octets] ##########

Modified by cor-el

katie_28 0 solutions 1 answers
# AdwCleaner v2.101 - Logfile created 12/21/2012 at 19:50:30
# Updated 16/12/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Katie - KATIE-HP
# Boot Mode : Normal
# Running from : C:\Users\Katie\Downloads\adwcleaner(1).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\ProgramData\Premium
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\bprotector_extensions.sqlite
File Deleted : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\bprotector_prefs.js
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKU\S-1-5-21-3521296510-1739712518-1077748139-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v17.0.1 (en-US)

Profile name : default 
File : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v23.0.1271.97

File : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [24747 octets] - [21/12/2012 19:45:54]
AdwCleaner[S3].txt - [3107 octets] - [21/12/2012 19:50:30]

########## EOF - C:\AdwCleaner[S3].txt - [3167 octets] ##########

Modified by cor-el

the-edmeister
  • Top 10 Contributor
  • Moderator
3197 solutions 24404 answers

Moderator locked this thread - we don't need AdwCleaner logs posted here.