I was watching a corel draw 7 youtube tutorial when i was prompted to update adobe flash. I mistakenly clicked on it and it delivered search.safefinder.com malware as my home page when loading explorer, google chrome,& mozilla which sends me to McAfee WebAdvisor warning page.
I uninstalled programs from control panel but still get directed to: search.safefinder.com -> http://www.siteadvisor.com/restricted.html?domain=http:%2F%2Fsearch.safefinder.com%2F%3Fst=sc%26q=&originalURL=-788708971&pip=false&premium=false&client_uid=484392383&client_ver=4.0.2.183&client_type=IEPlugin&suite=true&aff_id=105&locale=en_us&ui=1&os_ver=6.2.0.0
I am in a windows 10 environment.
I ran aswMBR and Farbar. I have attached aswMBR.txt but am unable to add FRST.txt to this post.
Thank you, Paul
aswMBR.txt
search.safefinder.com malware [Solved]
20 min read
Hello Paul2010 and welcome to the WTT forum.
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
Note: Please run these in the order given in the instructions.
===================================================
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
- run AdwCleaner by clicking on Scan
- when it has finished, leave everything that was found checked, (ticked), then click on Clean
- if it asks to reboot, allow the reboot
- on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================
Download and run Junkware Removal Tool
Please download Junkware Removal Tool to your desktop.
- shut down your protection software now to avoid potential conflicts.
- run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
- the tool will open and start scanning your system
- please be patient as this can take a while to complete depending on your system's specifications
- on completion, a log (JRT.txt) is saved to your desktop and will automatically open
- post the contents of JRT.txt into your next message.
===================================================
Run Farbar Recovery Scan Tool
Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
- right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
- press Scan button
- it will produce a log called Frst.txt in the same directory the tool is run from
- please copy and paste log back here.
- the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.
Logs to include with next post:
AdwCleaner log
JRT.txt
Frst.txt
Addition.txt
Thanks
Satchfan
Hi Satchfan,
Thank you for your reply and help.
I ran a all three app tools as directed.
There’s a lot of rubbish on there but nothing that we can’t deal with, (hopefully
).
Uninstall programs
Uninstall the following programs:
Search App by Ask
To do this:
- right-click the Start button and click Control Panel
- go to “Programs and Features” - (if your Control Panel is in “Category” view, go to “Uninstall a Program”)
- locate the program you want to uninstall, click it to select it, and then click Uninstall.
===================================================
Let’s have a look with a different tool.
Download zoek.exe to your Desktop:
Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.
- on Windows Vista, 7/8, 10 right-click Zoek.exe and select: Run as Administrator
- give it a few seconds to appear
- copy/paste the entire script inside the codebox below into the input field of Zoek:
createsrpoint; autoclean; emptyalltemp; ipconfig /flushdns >>"%temp%\log.txt";b
- make sure that the Scan All Users option is checked
- close any open programs.
- click the Run script button, and wait. It takes a few minutes to run.
- when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
- if a reboot is needed, the log will be opened after the reboot.
================================================
Please run FRST again and post the new log.
Logs to include with next post:
zoek-results.log
New Frst.txt
Thanks
Satchfan
Hi Satchfan,
Thank you again for your help.
I removed search.ask
I ran zoek.exe per your instructions.
I ran FRST per your instructions.
I attached each log as you instructed.
Thank you, Paul
Some things happening with these logs that shouldn’t be so we’ll have to run some scans again.
First, let’s clean up what was found.
Run Farbar Recovery Scan Tool
Open notepad. Please copy the contents of the code box below and paste it into Notepad.
HKLM-x32\…\Run: [] => [X]
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-29] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-29] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-29] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-29] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-29] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-29] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
HKU\S-1-5-21-2029319556-1583947356-1219303936-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFog82AJz1-QwRvKiFdXd7fHNODonIk–KDVZ8lW5Ly0jqoVlJHVMKwfTCoGckg2Tyj46fsaQ3ixAT_Fpp201d12lhRKErSKT0WBSWDX9cetLarObKmqztVIsU87a9CViRkNMGm3Tx2HDz2oGeF8tnV6YblPz6Em-kwv5xZAryMALWx09l_1M,&q={searchTerms}
HKU\S-1-5-21-2029319556-1583947356-1219303936-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFog82AJz1-QwRvKiFdXd7fHNODonIk–KDVZ8lW5Ly0jqoVlJHVMKwfTCoGckg2Tyj46fsaQ3ixAT_Fpp201d12ltr1FH6VrY0riYEnrKsN3hZl7VEzWgn9bht9ufy1_v9f5MRfWwG9YOHHOdyYd0umtBo8WtEnUF4QOMHnQI9BFwM9O4Db8,
HKU\S-1-5-21-2029319556-1583947356-1219303936-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFog82AJz1-QwRvKiFdXd7fHNODonIk–KDVZ8lW5Ly0jqoVlJHVMKwfTCoGckg2Tyj46fsaQ3ixAT_Fpp201d12lhRKErSKT0WBSWDX9cetLarObKmqztVIsU87a9CViRkNMGm3Tx2HDz2oGeF8tnV6YblPz6Em-kwv5xZAryMALWx09l_1M,&q={searchTerms}
HKU\S-1-5-21-2029319556-1583947356-1219303936-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFog82AJz1-QwRvKiFdXd7fHNODonIk–KDVZ8lW5Ly0jqoVlJHVMKwfTCoGckg2Tyj46fsaQ3ixAT_Fpp201d12lhRKErSKT0WBSWDX9cetLarObKmqztVIsU87a9CViRkNMGm3Tx2HDz2oGeF8tnV6YblPz6Em-kwv5xZAryMALWx09l_1M,&q={searchTerms}
HKU\S-1-5-21-2029319556-1583947356-1219303936-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> DefaultScope {A78B65C3-AEDF-4D52-9232-DFF1D18CD178} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites_14_11_ie&cd=2XzuyEtN2Y1L1Qzuzy0C0DtBtC0EtDtB0Bzz0AtBtDtD0CtCtN0D0Tzu0SzztDtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyByByBzytCyEyCyBtGyDyCyE0EtGyCtBzztAtG0C0C0EyDtGtCyCzzyCyCyByC0E0D0A0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyB0EyCtC0F0C0DtGyByE0AtDtG0FtCtCtCtG0C0FyB0EtGyC0FyCyCyEzytDtBzy0DzztC2Q&cr=502717392&ir=
SearchScopes: HKLM -> {A78B65C3-AEDF-4D52-9232-DFF1D18CD178} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites_14_11_ie&cd=2XzuyEtN2Y1L1Qzuzy0C0DtBtC0EtDtB0Bzz0AtBtDtD0CtCtN0D0Tzu0SzztDtCtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyByByBzytCyEyCyBtGyDyCyE0EtGyCtBzztAtG0C0C0EyDtGtCyCzzyCyCyByC0E0D0A0DtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDyB0EyCtC0F0C0DtGyByE0AtDtG0FtCtCtCtG0C0FyB0EtGyC0FyCyCyEzytDtBzy0DzztC2Q&cr=502717392&ir=
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKU\S-1-5-21-2029319556-1583947356-1219303936-1001 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFog82AJz1-QwRvKiFdXd7fHNODonIk–KDVZ8lW5Ly0jqoVlJHVMKwfTCoGckg2Tyj46fsaQ3ixAT_Fpp201d12lhRKErSKT0WBSWDX9cetLarObKmqztVIsU87a9CViRkNMGm3Tx2HDz2oGeF8tnV6YblPz6Em-kwv5xZAryMALWx09l_1M,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2029319556-1583947356-1219303936-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFog82AJz1-QwRvKiFdXd7fHNODonIk–KDVZ8lW5Ly0jqoVlJHVMKwfTCoGckg2Tyj46fsaQ3ixAT_Fpp201d12lhRKErSKT0WBSWDX9cetLarObKmqztVIsU87a9CViRkNMGm3Tx2HDz2oGeF8tnV6YblPz6Em-kwv5xZAryMALWx09l_1M,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2029319556-1583947356-1219303936-1002 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2029319556-1583947356-1219303936-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
CHR HomePage: Default -> search.ask.com/?gct=hp
CHR RestoreOnStartup: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggTIg4NBVhFQBhCdF8BTA1FFQEOIQ8PWRRDFQQaI1hZUQxJQAIFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlEmRFdoLlZP"
CHR StartupUrls: Default -> "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggTIg4NBVhFQBhCdF8BTA1FFQEOIQ8PWRRDFQQaI1hZUQxJQAIFIk0FA1oDB0VXfV5bFElXTwhwJVhKAlEmRFdoLlZP"
2016-04-11 11:06 - 2016-04-11 11:06 - 11137520 _____ (SparkTrust) C:\Users\Paul\Downloads\SparkTrust PC Cleaner Plus Setup_46DAD8E3-AB3D-4816-BBE0-31C16181BB87_.exe
2016-04-11 09:41 - 2016-04-11 09:41 - 00003328 _____ C:\WINDOWS\System32\Tasks\{FE65BEED-DD1F-432C-B5B4-BD7C818659EE}
2016-04-11 09:17 - 2016-04-11 09:18 - 00000000 ____D C:\ProgramData\Tampstrings
2016-04-11 09:16 - 2016-04-11 09:16 - 00000000 ____D C:\Users\Paul\AppData\Roaming\efo
2016-04-11 09:13 - 2016-04-12 13:17 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google
2016-04-11 09:10 - 2016-04-11 09:10 - 00130144 _____ C:\Users\Paul\Downloads\adobe_flash_setup-15914127.exe
2016-04-11 09:10 - 2016-04-11 09:10 - 00130144 _____ C:\Users\Paul\Downloads\adobe_flash_setup-15914127 (2).exe
2016-04-11 09:10 - 2016-04-11 09:10 - 00130144 _____ C:\Users\Paul\Downloads\adobe_flash_setup-15914127 (1).exe
EmptyTemp:
CMD: ipconfig /flushdns
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
- save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
- run FRST64 then click Fix just once and wait
- it will create a log on your desktop, (Fixlog.txt); please post it to your reply.
================================================
Uninstall AdwCleaner
- double click on adwcleaner.exe to run the tool
- click on Uninstall
- confirm with Yes
Download AdwCleaner again from here and save it to your desktop.
- run AdwCleaner
- when it has finished, allow AdwCleaner to deleteeverything it found, then click on Clean
- if it asks to reboot, allow the reboot
- on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================
Please run FRST again and make sure there is a checkmark next to "Addition.txt" before you hit “Scan”.
Logs to include with next post:
Fixlog.txt
New Frst.txt
New Addition.txt
Thanks
Satchfan
Hi Satchfan,
Again thank you for your help.
1) I made the file fixlist.txt as directed and ran Frst64.exe as requested.
2) I uninstalled, reinstalled, and ran AdwCleaner as requested.
3) I tried to run Frst64.exe again but got the following error alert: No fixlist.txt found.
It looks like the file was deleted after the first run ???? In any case I thought it best not to remake the file but instead ask for your guidance.
Thank you, Paul
Please just run FRST again and make sure there is a checkmark next to "Addition.txt" before you hit “Scan”.
Don't forget to post both.
Thanks
Nina
Hi Nina,
I scanned and attached as requested.
Thank you, Paul
Hi Paul.
Let’s try something else because AdwCleaner somehow didn’t clear up all that it should and there are still a few areas I’d like to look at.
Let’s have another type of look.
Run RogueKiller
IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!
Close all running programs.
Download RogueKiller to your desktop
- close all running programs
- for Windows Vista/7/8/10, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
- when the pre-scan is finished, click on Scan
- click on Report and copy/paste the content in your next post
- NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.
Please post the contents of the RKreport.txt in your next reply and let me know if there is any change.
Nina
Hi Nina,
I ran the app successfully the first time.
It is attached below.
Thank you, Paul
Run RogueKiller
IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
- close all programs
- right-click RogueKiller.exe and select Run as Administrator'
- after it has completed it's prescan, click on Scan
- click on the click on the “Registry” tab
- make sure the following entries there are checked:
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0011211460551711mcinstcleanup (C:\WINDOWS\TEMP\001121~1.EXE -cleanup -nolog) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\0011211460551711mcinstcleanup (C:\WINDOWS\TEMP\001121~1.EXE -cleanup -nolog) -> Found
- then press the Delete button and post the log it produces.
===================================================
Download Malwarebytes-Anti-Malware
Click here.
- double-click mbam-setup.exe and follow the prompts to install the program – (Note: Vista & Windows 7, 8, 10 users, please right-click and select “Run as Administrator”)
- select the “Scan” tab at the top
- there are three scan types; choose Threat Scan, then click on Scan
- when the scan is complete, if no malicious items are found you can close the program
- if malicious items are found be sure that everything is checked and click Quarantine
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Logs to include with the next post:
RogueKiller fix log
Mbam.txt
Can you tell me how things are now.
Nina
Hi Nina,
I ran RogueKiller.exe and had a power failure. I rebooted, ran the test and found no threats.
I ran Mbam.exe with no threats found.
I rebooted and did the same two tests again with no threats found.
Does the ower failure interupotion trouble you?
Thank you, Paul
Hello Paul
Does the ower failure interupotion trouble you?
No, it is unlikely to have anything to do with what we are looking at.
I’d like another scan please.
Run Security Check
Download Security Check by screen317 from here.
- save it to your Desktop.
- double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
- a Notepad document should open automatically called checkup.txt; please post the contents of that document.
NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.
Can you tell me how things are now.
Nina
Hi Nina,
When I go to the "Run Security Check " Link, I get account suspended with no download.
Thank you, Paul
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI