Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Bing has hijacked everything


  • Please log in to reply

#1
Mavric on the sea

Mavric on the sea

    New Member

  • Member
  • Pip
  • 4 posts

Synopsis:

 

OS: Windows 8.1

Browser: Firefox 54.0 (32- bit)

Homepage on Firefox: www.Google.com

Search engine set to Google in Firefox - Bing removed from the browser options in Firefox

 

No matter what I do, all search results return with Bing results only.

 

So bad that if I go to Google's homepage and do a search from their homepage using their Google search engine, all results still come back with Bing results.

 

What I've tried:

 

1) I started by doing a "system restore" as the problem came up yesterday. It didn't fix the problem

 

2) went to control panel to uninstall Bing, but Bing is not listed. Nor are there any programs called "research", "convert" or "conduit" or any new programs in the last 6 months except Windows upgrade several days ago - two or three days before this problem started so I don't think it's with the Windows upgrades.

 

3) right clicked the Windows app on the bottom toolbar of the desktop, clicked "search", typed in "appwiz.cpl" and "run". Nothing found with "Bing", "research", etc.

 

4) went to the upper corner of desktop and used the search function to find anything called "Bing" in my computer. Came back with two responses: "search settings" and "choose whether to include search suggestions and results from Bing". If you click on "search settings" it takes you to the other page "choose whether to include search suggestions and results from Bing" anyway. So I turned all Bing searches to "OFF". It did nothing, every search result in Google still comes back with Bing results

 

5) I have a watchdog program called WinPatrol that analyzes my computer and shows all start up programs, delayed start programs, cookies, hidden files, etc. It showed nothing that indicated Bing was running in any file.

 

6) I've run EMSI-SOFT Anti-malware, Trojan Horse Removal, etc. Did not help

 

7) I've uninstalled my Google toolbar and reinstalled it. Did not help

 

I've rebooted my computer more times than I can count. Driving me crazy.

I do not feel comfortable using "Regedit" and manually making changes to the registry

 

Any help would be greatly appreciated.


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,142 posts
  • MVP
 
Download : ADWCleaner to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @BleepingComputer
 
NOTE: If using Internet Explorer and you get an alert that stops the program downloading, click on the warning and allow the download to complete.
 
Close  all programs, pause your anti-virus and run AdwCleaner (Vista or Win 7 => right click and Run As Administrator).
 
scan-results.jpg
 
Click on Scan  and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.
 
The report will be saved in the C:\AdwCleaner folder.
 
 
 
Junkware-Removal-Tool
 
Please download Junkware Removal Tool to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @Author's site
  • Pause your anti-virus.  Close all browsers.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  •  
     
     
     
     
    [*]Get FRST from
    You need to download the appropriate tool for your PC.  If you don't know if you have a 32 or 64 bit system get them both.  Only one will work and that's the right one.
    [*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer. 
    [*]Check the Addition.txt box
    [*]Press Scan button. 
    [*]It will produce a log called FRST.txt in the same directory the tool is run from.  
    [*]Please copy and paste log back here. 
    [*]It will generate another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply. 

    • 0

    #3
    Mavric on the sea

    Mavric on the sea

      New Member

    • Topic Starter
    • Member
    • Pip
    • 4 posts

    Thanks for the quick response. I ran the first program and have the log file. I will post it here. I have to do a lot of running today and will be home off and on, but I will continue our dialogue as time permits. Meanwhile, here's the log:

     

    # AdwCleaner v6.047 - Logfile created 24/06/2017 at 07:33:31
    # Updated on 19/05/2017 by Malwarebytes
    # Database : 2017-06-23.1 [Local]
    # Operating System : Windows 8.1  (X64)
    # Username : Ric - MAIN
    # Running from : C:\Users\Ric\Desktop\AdwCleaner.exe
    # Mode: Clean
    # Support : https://www.malwarebytes.com/support



    ***** [ Services ] *****



    ***** [ Folders ] *****

    [-] Folder deleted: C:\Users\Ric\AppData\LocalLow\iac
    [#] Folder deleted on reboot: C:\Users\Ric\AppData\LocalLow\IAC
    [-] Folder deleted: C:\Users\Administrator\Favorites\StumbleUpon
    [-] Folder deleted: C:\Users\Guest\Favorites\StumbleUpon
    [-] Folder deleted: C:\Users\Public\Documents\Goobzo
    [-] Folder deleted: C:\Users\Public\Documents\Downloaded Installers
    [-] Folder deleted: C:\Program Files (x86)\Common Files\freemake shared


    ***** [ Files ] *****

    [-] File deleted: C:\END
    [-] File deleted: C:\Users\Ric\AppData\Roaming\Mozilla\Firefox\Profiles\4j4fw2fk.default\extensions\@searchassistincognito.xpi


    ***** [ DLL ] *****



    ***** [ WMI ] *****



    ***** [ Shortcuts ] *****



    ***** [ Scheduled Tasks ] *****

    [-] Task deleted: BBQLeads


    ***** [ Registry ] *****

    [-] Key deleted: HKU\S-1-5-21-3958933120-3896213070-55288377-1001\Software\Microsoft\KanarCore
    [-] Key deleted: HKU\S-1-5-21-3958933120-3896213070-55288377-1001\Software\WEDLMNGR
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3958933120-3896213070-55288377-1001\Software\SourceApp
    [#] Key deleted on reboot: HKCU\Software\Microsoft\KanarCore
    [#] Key deleted on reboot: HKCU\Software\WEDLMNGR
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3958933120-3896213070-55288377-1001\Software\SourceApp
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\KanarCore
    [#] Key deleted on reboot: [x64] HKCU\Software\WEDLMNGR
    [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}
    [-] Data restored: HKU\S-1-5-21-3958933120-3896213070-55288377-1001\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
    [-] Data restored: HKU\S-1-5-21-3958933120-3896213070-55288377-500\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages]
    [-] Data restored: HKU\S-1-5-21-3958933120-3896213070-55288377-500\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
    [-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
    [-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
    [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
    [-] Data restored: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Secondary Start Pages]
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\afraidtoask.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\azlyrics.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dotomi.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\forums.afraidtoask.com
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inbox.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\afraidtoask.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\azlyrics.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dotomi.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\forums.afraidtoask.com
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\inbox.com


    ***** [ Web browsers ] *****

    [-] Firefox preferences cleaned: "extensions.webextensions.uuids" -  "{\"[email protected]\":\"4a41dbb2-3516-4594-8d79-bdb9bf9ae2b7\",\"@searchassistincognito\":\"0c685621-df98-4ac6-a774-3914260e39e6\",\"[email protected]\":\"0bb6319e-2697-45b9-9053-fdfe4276a8ec\"}"


    *************************

    :: "Tracing" keys deleted
    :: Winsock settings cleared

    *************************

    C:\AdwCleaner\AdwCleaner[C0].txt - [4924 Bytes] - [24/06/2017 07:33:31]
    C:\AdwCleaner\AdwCleaner[S0].txt - [4974 Bytes] - [24/06/2017 07:28:08]
    C:\AdwCleaner\AdwCleaner[S1].txt - [5046 Bytes] - [24/06/2017 07:32:45]

    ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5143 Bytes] ##########
     


    • 0

    #4
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 23,142 posts
    • MVP

    No hurry.  Do them when you can.


    • 0

    #5
    Mavric on the sea

    Mavric on the sea

      New Member

    • Topic Starter
    • Member
    • Pip
    • 4 posts

    Seems to have worked - thanks


    • 0

    #6
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 23,142 posts
    • MVP

    Which worked?


    • 0

    #7
    Mavric on the sea

    Mavric on the sea

      New Member

    • Topic Starter
    • Member
    • Pip
    • 4 posts

    Which worked?

     

    <script type="text/javascript"> //</script>

     

    The AdwCleaner worked. The Junkware-removal-tool popped up in DOS format and requested that I put in a restore date, but it didn't let me type anything in. I finally gave up and closed it out and checked to see if I had Google back and it was back and running fine.


    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP