Jump to content

Can't get rid of adware and search


Recommended Posts

I first reported this problem to Malwarebytes in about May, 2018 through the regular channels.  Today, they directed me to this "I'm infected - what do I do now".   My problem has remained about the same over this time, getting a little worse.  

I have 3 attachments from this morning's results.  

1.  My Malwarebytes Premium ran automatically this morning, and did not find any threats.  (attachment #1)

2.  After surfing with Google Chrome for a while, I ran AdwCleaner, as I also did yesterday, and many other days, with the same results - 9 threats.  (attachment #2)

3.  After restarting, but before I started any other programs, I ran AdwCleaner again, and got the same results - 9 threats. (attachment #3)

4.  I ran the FRST program, and log is attached

5.  Addition log is attached

Note:  one thing that I have always noticed is a folder called "search" appears in my downloads folder after every restart.  I have not been able to get rid of it.  If I double click on it, I get to a "data" folder.  If I double click on that, I get to a "temp" folder.  If I double click on that, I get to a "usgthrsvc" folder.  If I double click on that, I get a "folder is empty"; however I think there may be hidden data in there; because deleting it may result in more folders being deleted than are evident.  Sometimes, I am initially denied access to this lowest folder until I say "continue"

 

1 - Malwarebytes report - nothing found.PNG

2 - AdwCleaner[C64] 9 found.txt

3 - AdwCleaner[S65].txt

4 -FRST.txt

5 - Addition.txt

Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Remove this program in bold via the Control Panel > Programs > Programs and Features.
CCleaner (HKLM\...\CCleaner) (Version: 5.45 - Piriform)

Version 5.45 is compromised. Delete it and get the the latest version.
https://www.ccleaner.com/

Information.
https://www.bleepingcomputer.com/news/software/ccleaner-v545-pulled-due-to-anger-over-usage-data-collection/
===

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png or the 3 vertical dots located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset and clean up" > "Restore settings to their original defaults"
 
Restart Chrome.
<<<>>>

Quote

Note:  one thing that I have always noticed is a folder called "search" appears in my downloads folder after every restart.  I have not been able to get rid of it.  If I double click on it, I get to a "data" folder.  If I double click on that, I get to a "temp" folder.  If I double click on that, I get to a "usgthrsvc" folder.  If I double click on that, I get a "folder is empty"; however I think there may be hidden data in there; because deleting it may result in more folders being deleted than are evident.  Sometimes, I am initially denied access to this lowest folder until I say "continue"

This is part of the Windows Search service.
https://superuser.com/questions/964861/upgraded-windows-7-to-windows-10-window-search-service-no-longer-starts/1105784

If you have any problems check the status.
===

If your problem persists check this out.
If you are Syncing Chrome with other devices?
To remove it you will have to reset the Sync in Chrome.

Read this article and proceed.

Chrome Secure Preferences detection always comes back
https://forums.malwarebytes.com/topic/214325-chrome-secure-preferences-detection-always-comes-back/
<<<>>>

Let me know what problem persists with this computer.

 

Link to post
Share on other sites

OK, Nasdaq,,

I upgraded CCleaner to the lastest version

I ran FRST, and clicked on Fix, and am attaching logs

I reset Chrome settings to default

I also uninstalled Direct Folders, because Google Chrome had a problem with it

I restarted, and ran Adwcleaner, and it found only 1 threat, which I think may be a false positive (Windows Search Service)

I started Google Chrome, and started my yahoo, google, and facebook pages

I ran AdwCleaner again, and it found adware again...

I will attach all the logs

Thank you

 

Addition.txt

Fixlog.txt

FRST.txt

AdwCleaner[S74].txt

AdwCleaner[S73].txt

AdwCleaner[C72].txt

AdwCleaner[S72].txt

AdwCleaner[S71].txt

AdwCleaner[S70].txt

AdwCleaner[S69].txt

AdwCleaner[C68].txt

AdwCleaner[S68].txt

Link to post
Share on other sites

I had previously unhidden files/folders, and there was still nothing shown.  One reason that makes me think that there is something there that I can't see is that there are 4 levels of supposedly empty folders:  "search", "temp", "data", and "usgthrsvc"; however when I delete the highest level "search" folder, the system says that 6 items have been deleted, rather than 4. 

Link to post
Share on other sites

Hi,

Lets see what we can find in the Registry.

Run the Farbar program .exe as an Administrator.

In the Search text area, copy and paste the following:
usgthrsvc
Once done, click on the Search Registry button and wait for FRST to finish the search
On completion, a log will open in Notepad. Copy and paste its content in your next reply
====

Link to post
Share on other sites

OK, here you are:

Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Skipper (19-10-2018 11:17:56)
Running from C:\Users\Skipper\Downloads\programs\Malwarebytes FRST scan program
Boot Mode: Normal

================== Search Registry: "usgthrsvc" ===========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager]
"TempPath"="C:\Users\Skipper\Downloads\Search\Data\Temp\usgthrsvc"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\PerformanceCounters]
"USGTHRSVC"="UGTHRSVC"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Search\Gathering Manager]
"TempPath"="C:\Users\Skipper\Downloads\Search\Data\Temp\usgthrsvc"
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Search\PerformanceCounters]
"USGTHRSVC"="UGTHRSVC"

====== End of Search ======

Link to post
Share on other sites

  • 4 weeks later...
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.