Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Search Selector Beta

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Content is republished with permission from Malwarebytes.

What is Search Selector Beta?

The Malwarebytes research team has determined that Search Selector Beta is a search hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice.

How do I know if my computer is affected by Search Selector Beta?

You may see this entry in your list of installed Chrome extensions:

main.png

and these warnings during install:

warning1.png

warning2.png

warning3.png

You will see this icon in your Chrome menu-bar:

icons.png

and this changed setting:

warning5.png

How did Search Selector Beta get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was downloaded from the webstore:

webstore.png

How do I remove Search Selector Beta?

Our program Malwarebytes can detect and remove this potentially unwanted program.
  • Please download Malwarebytes to your desktop.
  • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Search Selector Beta?
  • No, Malwarebytes removes Search Selector Beta completely.
How would the full version of Malwarebytes help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

Technical details for experts

Possible signs in FRST logs:

CHR DefaultSearchURL: Default -> hxxp://selected-search.com/search?q={searchTerms}&
CHR DefaultSearchKeyword: Default -> ss
CHR Extension: (Search Selector Beta) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof [2019-11-05]
Alterations made by the installer:

File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0
       Adds the file About.pdf"="9/11/2019 12:31 PM, 62988 bytes, A
       Adds the file manifest.json"="11/5/2019 8:48 AM, 1953 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata
       Adds the file computed_hashes.json"="11/5/2019 8:48 AM, 12000 bytes, A
       Adds the file verified_contents.json"="9/11/2019 3:06 PM, 4525 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\css
       Adds the file popup.css"="9/11/2019 2:59 PM, 144 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\html
       Adds the file popup.html"="9/11/2019 2:59 PM, 1007 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines
       Adds the file bing.png"="9/11/2019 2:59 PM, 16569 bytes, A
       Adds the file google.png"="9/11/2019 2:59 PM, 21125 bytes, A
       Adds the file yahoo.png"="9/11/2019 2:59 PM, 49488 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons
       Adds the file 128.png"="11/5/2019 8:48 AM, 4123 bytes, A
       Adds the file 16.png"="11/5/2019 8:48 AM, 380 bytes, A
       Adds the file 256.png"="11/5/2019 8:48 AM, 9753 bytes, A
       Adds the file 32.png"="11/5/2019 8:48 AM, 813 bytes, A
       Adds the file 48.png"="11/5/2019 8:48 AM, 1485 bytes, A
       Adds the file 64.png"="11/5/2019 8:48 AM, 1868 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs
       Adds the file jquery.autocomplete.js"="9/11/2019 2:59 PM, 33061 bytes, A
       Adds the file jquery.js"="9/11/2019 2:59 PM, 247597 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\css
       Adds the file bootstrap.css"="9/11/2019 2:59 PM, 146082 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts
       Adds the file glyphicons-halflings-regular.eot"="9/11/2019 2:59 PM, 20127 bytes, A
       Adds the file glyphicons-halflings-regular.svg"="9/11/2019 2:59 PM, 108738 bytes, A
       Adds the file glyphicons-halflings-regular.ttf"="9/11/2019 2:59 PM, 45404 bytes, A
       Adds the file glyphicons-halflings-regular.woff"="9/11/2019 2:59 PM, 23424 bytes, A
       Adds the file glyphicons-halflings-regular.woff2"="9/11/2019 2:59 PM, 18028 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\js
       Adds the file bootstrap.js"="9/11/2019 2:59 PM, 68954 bytes, A
    Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts
       Adds the file background.js"="9/11/2019 3:05 PM, 1317 bytes, A
       Adds the file consts.js"="9/11/2019 2:59 PM, 850 bytes, A
       Adds the file popup.js"="9/11/2019 2:59 PM, 341 bytes, A
       Adds the file utils.js"="9/11/2019 2:59 PM, 2356 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings]
       "gboaiodgdajeapekadgejlbmabjganof"="REG_SZ", "ABF55023E4AD7B7381DCB832626AACD3B79676C479AEB58770647D03DC513BA6"
Malwarebytes log:

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 11/5/19
Scan Time: 9:00 AM
Log File: 5facfd40-ffa2-11e9-ba7c-00ffdcc6fdfc.json

-Software Information-
Version: 3.8.3.2965
Components Version: 1.0.629
Update Package Version: 1.0.13181
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 234082
Threats Detected: 46
Threats Quarantined: 46
Time Elapsed: 8 min, 8 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 1
PUP.Optional.SelectedSearch, HKCU\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|gboaiodgdajeapekadgejlbmabjganof, Quarantined, [277], [757187],1.0.13181

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 14
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\css, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\html, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\css, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GBOAIODGDAJEAPEKADGEJLBMABJGANOF, Quarantined, [277], [757187],1.0.13181

File: 31
PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GBOAIODGDAJEAPEKADGEJLBMABJGANOF\2.0_0\MANIFEST.JSON, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\css\popup.css, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\html\popup.html, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines\bing.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines\google.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines\yahoo.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\128.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\16.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\256.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\32.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\48.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\64.png, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\css\bootstrap.css, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.eot, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.svg, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.ttf, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.woff, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.woff2, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\js\bootstrap.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\jquery.autocomplete.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\jquery.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\background.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\consts.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\popup.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\utils.js, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata\computed_hashes.json, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata\verified_contents.json, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\About.pdf, Quarantined, [277], [757187],1.0.13181
PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [277], [757186],1.0.13181

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
The full version of Malwarebytes can protect your computer against threats of this type.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.