Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Virus/Malware What is "search.mediatabtv.online", Changing my default google to Yahoo

views
     
TSn8210
post Mar 13 2018, 03:30 PM, updated 7y ago

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


I believe this problem came when I installed Eagleget download manager yesterday. Now, in my firefox search bar, everytime I type something in, it will go google, but before google gets to display anything, the address bar will temporarily display "search.mediatabtv.online/xxxxxx" and then show me the search result under Yahoo. Once it even show search results under Yaahoo. I have deleted Eagleget, remove the other search options in firefox settings, but it doesn't really go away. It keeps coming back. Everytime I go to options, search tab, there it is again "Yahoo based search".

How do I get rid of it? Nothing in in Windows > Settings > Apps and Features. Need help. Thanks.
WebWalker
post Mar 13 2018, 03:48 PM

Computer Geek
********
All Stars
12,851 posts

Joined: May 2005
From: Puchong, Selangor



If your system is infected by malware, download Malwarebytes to clean it :-

https://www.malwarebytes.com/

If you don't have a proper antivirus installed, then download AVIRA :-

https://www.avira.com/en/free-antivirus-windows
Left4Dead2
post Mar 13 2018, 03:51 PM

Regular
******
Senior Member
1,085 posts

Joined: Nov 2009
Uninstall Firefox

Use Chrome
TSn8210
post Mar 13 2018, 04:28 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


QUOTE(WebWalker @ Mar 13 2018, 03:48 PM)
If your system is infected by malware, download Malwarebytes to clean it :-

https://www.malwarebytes.com/

If  you don't have a proper antivirus installed, then download AVIRA :-

https://www.avira.com/en/free-antivirus-windows
*
I am using avira, I have downloaded malwarebytes before posting. Both didn't solve the problem. Scanned with Spybot too, still the same.
TSn8210
post Mar 13 2018, 07:10 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


other times it would appear as Yahoo, but this time I caught it with the other spelling Yaahoo


Attached thumbnail(s)
Attached Image
kherel77
post Mar 13 2018, 08:25 PM

Noobie
******
Senior Member
1,435 posts

Joined: Apr 2011
From: Blank Space



QUOTE(n8210 @ Mar 13 2018, 04:28 PM)
I am using avira, I have downloaded malwarebytes before posting. Both didn't solve the problem. Scanned with Spybot too, still the same.
*
Run Malwarebytes & AV in Safe Mode. AV 1st then Malwarebytes.
TSn8210
post Mar 13 2018, 10:36 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


QUOTE(kherel77 @ Mar 13 2018, 08:25 PM)
Run Malwarebytes & AV in Safe Mode. AV 1st then Malwarebytes.
*
Tried, couldn't find anything. Now I have uninstalled Firefox, but i think once i reinstall it, the damn search engine will be there to kacau again. Luckily I can use chrome or UC Browser. But years of personal data all with firefox. Sad.
TSn8210
post Mar 13 2018, 11:14 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


# AdwCleaner 7.0.8.0 - Logfile created on Tue Mar 13 15:11:16 2018
# Updated on 2018/08/02 by Malwarebytes
# Database: 2018-03-12.1
# Running on Windows 10 Pro (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.UCBrowser, C:\Windows\System32\config\systemprofile\AppData\Local\UCBrowser
PUP.Optional.UCBrowser, C:\Program Files (x86)\UCBrowser
PUP.Optional.UCBrowser, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\UCBrowser
PUP.Optional.UCBrowser, C:\Users\n8210\AppData\Local\UCBrowser
PUP.Optional.UCBrowser, C:\Users\n8210\AppData\Local\VirtualStore\Program Files (x86)\UCBrowser


***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

PUP.Optional.Legacy, UCBrowserUpdaterCore


***** [ Registry ] *****

PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
PUP.Optional.Legacy, [Key] - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.htm\OpenWithProgids | UCHTML.AssocFile.HTM
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.html\OpenWithProgids | UCHTML.AssocFile.HTML
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.mht\OpenWithProgids | UCHTML.AssocFile.MHT
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.shtm\OpenWithProgids | UCHTML.AssocFile.SHTM
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.shtml\OpenWithProgids | UCHTML.AssocFile.SHTML
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.webp\OpenWithProgids | UCHTML.AssocFile.WEBP
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.xht\OpenWithProgids | UCHTML.AssocFile.XHT
PUP.Optional.Legacy, [Value] - HKCU\SOFTWARE\Classes\.xhtml\OpenWithProgids | UCHTML.AssocFile.XHTML
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.htm\OpenWithProgids | UCHTML.AssocFile.HTM
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.html\OpenWithProgids | UCHTML.AssocFile.HTML
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.mht\OpenWithProgids | UCHTML.AssocFile.MHT
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.shtm\OpenWithProgids | UCHTML.AssocFile.SHTM
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.shtml\OpenWithProgids | UCHTML.AssocFile.SHTML
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.webp\OpenWithProgids | UCHTML.AssocFile.WEBP
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.xht\OpenWithProgids | UCHTML.AssocFile.XHT
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Classes\.xhtml\OpenWithProgids | UCHTML.AssocFile.XHTML
PUP.Optional.UCBrowser, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {9E3F126A-089D-4184-AE51-5698F7A07055}
PUP.Optional.UCBrowser, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {A2B0AE51-7E44-42B9-8CB5-34D2529BCB0E}
PUP.Optional.UCBrowser, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {D5A74F3F-A5EB-4EA3-84C7-9F2A3B56F926}
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.CRX
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTM
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.HTML
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.MHT
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTM
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.SHTML
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.WEBP
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHT
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\UCHTML.AssocFile.XHTML


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########
TSn8210
post Mar 13 2018, 11:16 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


tried uninstall, clean registry, reinstall firefox and there it is again... nothing has changed. tried refresh firefox with extensions/plugins disabled, still the same. nothing seems to remove it.
kherel77
post Mar 13 2018, 11:50 PM

Noobie
******
Senior Member
1,435 posts

Joined: Apr 2011
From: Blank Space



Quite stubborn malware...have you tried roll-back to any recent restore point? Before you install that Eagleget software?
TSn8210
post Mar 14 2018, 10:34 AM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


windows restore? i did try to do that, but since i am signed in to a local account for faster boot up, i could not remember my password so did not manage to do that. will try again.

TSn8210
post Mar 14 2018, 11:28 AM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


cannot restore. windows tells me there is no restoration point. sad... very sad
TSn8210
post Mar 14 2018, 11:45 AM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


What is this Umeng? Can I delete this? Couldn't find any info on this. It is located in my Appdata folder.


Attached thumbnail(s)
Attached Image
TSn8210
post Mar 14 2018, 02:08 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


ok, a small breakthrough. I did all I can to remove all traces of firefox from existence. Then reinstall. There was no Yaahoo search... Until, i login my firefox acc and sync. So this means it must be an extension. I could not find it in extension in order to remove it. I have also tried removing all other extensions and it still there. Stealth mode!! So how to really clean this SOB
ChaChaZero
post Mar 14 2018, 02:13 PM

On my way
****
Junior Member
545 posts

Joined: Sep 2006
QUOTE(n8210 @ Mar 14 2018, 02:08 PM)
ok, a small breakthrough. I did all I can to remove all traces of firefox from existence.  Then reinstall. There was no Yaahoo search... Until, i login my firefox acc and sync. So this means it must be an extension. I could not find it in extension in order to remove it. I have also tried removing all other extensions and it still there. Stealth mode!! So how to really clean this SOB
*
Open your internet explorer > click tools > internet options > connections > lan settings

see what is in the "Use automatic configuration script". thats likely your problem. If there is a strange link there, copy it to a notepad, then remove it from the settings and close it. Reopen it and see if the settings is there or not.

if it reappears, you need to search for that address you saved in the notepad in the registry. Its probably set as an auto proxy somewhere in the registry.
TSn8210
post Mar 14 2018, 03:19 PM

Look at all my stars!!
*******
Senior Member
2,659 posts

Joined: Mar 2005


Fixed. Reinstall firefox, then don't sync extensions. Others all ok. Then install all the extensions I want, and finally sync it online. This will remove all online copies of the bastard extension - Yaahoo.

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0142sec    0.22    6 queries    GZIP Disabled
Time is now: 28th March 2024 - 09:33 PM