What is Search Selector Beta?
The Malwarebytes research team has determined that Search Selector Beta is a search hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice.
How do I know if my computer is affected by Search Selector Beta?
You may see this entry in your list of installed Chrome extensions:
and these warnings during install:
You will see this icon in your Chrome menu-bar:
and this changed setting:
How did Search Selector Beta get on my computer?
Browser hijackers use different methods for distributing themselves. This particular one was downloaded from the webstore:
How do I remove Search Selector Beta?
Our program Malwarebytes can detect and remove this potentially unwanted program.
- Please download Malwarebytes to your desktop.
- Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
- Then click Finish.
- Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
- If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
- When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
- Restart your computer when prompted to do so.
- No, Malwarebytes removes Search Selector Beta completely.
We hope our application and this guide have helped you eradicate this hijacker.
Technical details for experts
Possible signs in FRST logs:
CHR DefaultSearchURL: Default -> hxxp://selected-search.com/search?q={searchTerms}& CHR DefaultSearchKeyword: Default -> ss CHR Extension: (Search Selector Beta) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof [2019-11-05]Alterations made by the installer:
File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0 Adds the file About.pdf"="9/11/2019 12:31 PM, 62988 bytes, A Adds the file manifest.json"="11/5/2019 8:48 AM, 1953 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata Adds the file computed_hashes.json"="11/5/2019 8:48 AM, 12000 bytes, A Adds the file verified_contents.json"="9/11/2019 3:06 PM, 4525 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\css Adds the file popup.css"="9/11/2019 2:59 PM, 144 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\html Adds the file popup.html"="9/11/2019 2:59 PM, 1007 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines Adds the file bing.png"="9/11/2019 2:59 PM, 16569 bytes, A Adds the file google.png"="9/11/2019 2:59 PM, 21125 bytes, A Adds the file yahoo.png"="9/11/2019 2:59 PM, 49488 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons Adds the file 128.png"="11/5/2019 8:48 AM, 4123 bytes, A Adds the file 16.png"="11/5/2019 8:48 AM, 380 bytes, A Adds the file 256.png"="11/5/2019 8:48 AM, 9753 bytes, A Adds the file 32.png"="11/5/2019 8:48 AM, 813 bytes, A Adds the file 48.png"="11/5/2019 8:48 AM, 1485 bytes, A Adds the file 64.png"="11/5/2019 8:48 AM, 1868 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs Adds the file jquery.autocomplete.js"="9/11/2019 2:59 PM, 33061 bytes, A Adds the file jquery.js"="9/11/2019 2:59 PM, 247597 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\css Adds the file bootstrap.css"="9/11/2019 2:59 PM, 146082 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts Adds the file glyphicons-halflings-regular.eot"="9/11/2019 2:59 PM, 20127 bytes, A Adds the file glyphicons-halflings-regular.svg"="9/11/2019 2:59 PM, 108738 bytes, A Adds the file glyphicons-halflings-regular.ttf"="9/11/2019 2:59 PM, 45404 bytes, A Adds the file glyphicons-halflings-regular.woff"="9/11/2019 2:59 PM, 23424 bytes, A Adds the file glyphicons-halflings-regular.woff2"="9/11/2019 2:59 PM, 18028 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\js Adds the file bootstrap.js"="9/11/2019 2:59 PM, 68954 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts Adds the file background.js"="9/11/2019 3:05 PM, 1317 bytes, A Adds the file consts.js"="9/11/2019 2:59 PM, 850 bytes, A Adds the file popup.js"="9/11/2019 2:59 PM, 341 bytes, A Adds the file utils.js"="9/11/2019 2:59 PM, 2356 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "gboaiodgdajeapekadgejlbmabjganof"="REG_SZ", "ABF55023E4AD7B7381DCB832626AACD3B79676C479AEB58770647D03DC513BA6"Malwarebytes log:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 11/5/19 Scan Time: 9:00 AM Log File: 5facfd40-ffa2-11e9-ba7c-00ffdcc6fdfc.json -Software Information- Version: 3.8.3.2965 Components Version: 1.0.629 Update Package Version: 1.0.13181 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 234082 Threats Detected: 46 Threats Quarantined: 46 Time Elapsed: 8 min, 8 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 1 PUP.Optional.SelectedSearch, HKCU\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|gboaiodgdajeapekadgejlbmabjganof, Quarantined, [277], [757187],1.0.13181 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 14 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\css, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\html, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\css, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GBOAIODGDAJEAPEKADGEJLBMABJGANOF, Quarantined, [277], [757187],1.0.13181 File: 31 PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GBOAIODGDAJEAPEKADGEJLBMABJGANOF\2.0_0\MANIFEST.JSON, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\css\popup.css, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\html\popup.html, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines\bing.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines\google.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\engines\yahoo.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\128.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\16.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\256.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\32.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\48.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\images\icons\64.png, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\css\bootstrap.css, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.eot, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.svg, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.ttf, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.woff, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\fonts\glyphicons-halflings-regular.woff2, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\bootstrap\js\bootstrap.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\jquery.autocomplete.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\libs\jquery.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\background.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\consts.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\popup.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\scripts\utils.js, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata\computed_hashes.json, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\_metadata\verified_contents.json, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gboaiodgdajeapekadgejlbmabjganof\2.0_0\About.pdf, Quarantined, [277], [757187],1.0.13181 PUP.Optional.SelectedSearch, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [277], [757186],1.0.13181 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end)The full version of Malwarebytes can protect your computer against threats of this type.
We use different ways of protecting your computer(s):
- Dynamically Blocks Malware Sites & Servers
- Malware Execution Prevention