PDA

View Full Version : B88gger - I've got a Virus - Help !


ExSp33db1rd
3rd Feb 2013, 07:22
Every time I open my web browser - Chrome - Delta Search browser opens instead. I can click on my Google tab and get back to Chrome, but that's not the point.

Mr. Google seems to know about this, and advises to be rid of it pronto, lest it slowly gets more aggressive, but lost me about 5 secs, into a video showing how to remove it, which appears to be most complicated.

Looks like a visit to the Computer Doctor tomorrow - unless anyone knows better ? ( and simpler )

I received an e-mail from my grandson this morning, that one about Irish Luck to be immediately forwarded, there was no attachment to open and I'd been sent -and ignored - it some time ago with no ill effects, but I'm suspicious about this one, especially as my grandson had left approx 700 other e-mails, forwarded, forwarded and re-forwarded ad infinitum, until they had reached him.

I've just written a strong word to my son, to educate said grandson into the ways of BCC and deleting all previous e-mails, but it is amazing just how many people fail to do this, since this morning I've received another e-mail forward from a professional organisation, which also had a clutch of old e-mails on it.

Will they ever learn ?

How do I get rid of Delta Search ?

mustpost
3rd Feb 2013, 08:51
Can't bear to see someone in trouble, not heard of this one, it's a bit time consuming, but the correct details look to be here. Good luck!
Delta-search Takes Control of Browser - How to Remove Search Browser Virus? - Tee Support Blog (http://blog.teesupport.com/delta-search-takes-control-of-browser-how-to-remove-search-browser-virus/)

Take care with regedit if you've not ventured there before :8

Bushfiva
3rd Feb 2013, 09:16
teesupport. Great. For free they tell you how to break your system, then encourage you to call them for paid support.

BOAC
3rd Feb 2013, 09:40
ExSp - what do you see in Tools/Option/Search in the list of search engines? Which one is selected?

Helix Von Smelix
3rd Feb 2013, 09:56
As a starting point download malwarebytes. Install and run.

Please note i said starting point, before other come along with suggestions, and say malwarebytes is not the one to use.

May be ask grandson to change his email password on his email account.

ExSp33db1rd
3rd Feb 2013, 18:47
what do you see in Tools/Option/Search in the list of search engines? Which one is selected?

.........."The default browser is currently Google Chrome."

Delta Search is one of the options, as is Bing, Yahoo! search, Chrome etc. some of which I didn't even know existed, and certainly didn't ask for ! Chrome is selected as the default and I am unable to delete and wipe off Delta Search.

One of the comments from searching Google is that when Delta Search is in control, as it appears to be now, it will override Google and open itself first, then I can click on my 'Google' tab in Favourites and resume Chrome as my browser. It is this insidious 'control' that is worrying.

It doesn't appear in the list of Programmes -that I could then try to uninstall.

Some comments from a Google search .........

Kaspersky Internet security says it's a new adware virus that came out three weeks ago.

Some people don't realise its destructive capabilty

such slow temper virus can grow into an aggressive evil if you leave it alone

Delta search is able to mess up ones favourite web programme

possibilities are made for remote hackers to take control over the infected computer

It is a virus without question as it comes into your computer without permission

I agree with bushfiva, teesupport appears to know all about it, but their instructions to remove it are way beyond me - I lose them at about the second step - and it appears that one has to mess about with register entries, then they suggest calling their technical support. Probably cheaper to buy a new computer, my being on the other side of the World from them.

Hey Ho ! off to the PC Dr. we go !! Will report back.

Milo Minderbinder
3rd Feb 2013, 19:12
First boot into safe mode
Go online, download and run Rkill. This doesn't remove anything, but it will knock the malware out of memory during this session
The reset Internet Explorer to its defaults
And go into the Chrome settings and manually remove the rogue search engine and home pages.
Then right click the C: drive in Windows Explorer, go to properties, run the disk clean up tool. Basically you're doing this to try to clean out anything hidden in the temp folders
Then download and run in turn
Hitman Pro
Combofix
Malwarebytes
Spybot

Even then it may be neccessary to reset the Windows shell commands if IE doesn't run properly - post back if thats the case and we can point you to the correct tools


RKill Download (http://www.bleepingcomputer.com/download/rkill/)
ComboFix Download (http://www.bleepingcomputer.com/download/combofix/)
Home - SurfRight (http://www.surfright.nl/en)
Malwarebytes : Free anti-malware download (http://www.malwarebytes.org/)
Spybot - Search & Destroy from Safer-Networking Ltd. (http://www.safer-networking.org/)

Note these are not alternatives - they need to be run sequentially
Even then you can't be sure they will get everything: personally I always first use Microsoft's Autoruns program to weed out unwanted stuff from loading, and then follow that up with a visual hunt through the registry

Finally, whatever is your antivirus / security program, bin it and get something that works, like Avast

If you don't want to get hijacked like this again, avoid Google Chrome
Its a vulnerable piece of crap thats easy to hijack. Use Firefox, locked down with a combination of No-Script / Adblock plus/ Adblock popup blocker / Ghostery & Better Privacy
As long as the AV software is up to date, little will get past that lot together

FWIW, Safari is equally vulnerable. IE is better, but not a lot.

Saab Dastard
3rd Feb 2013, 20:07
And don't log on as an administrator or equivalent. Unless you actually need to in order to carry out installation / maintenance.

SD

ExSp33db1rd
4th Feb 2013, 02:37
Later .......PC Dr. sort of fixed the problem, at least stopped Delta Search from opening instead of Chrome, but was a but vague as to what he had done, re-set the pages I think he said, but I'm not sure that it has been completely removed, it still shows as an option in the list of available browsers, along with all the others that I don't need, or use.

However, in view of Milos' advice I've switched to Firefox, tho' I haven't attempted all the other steps suggested yet.

Thank you for all the advice, it has been filed for possible later use.

BOAC
4th Feb 2013, 12:56
Delta Search is one of the options, as is Bing, Yahoo! search, Chrome etc. some of which I didn't even know existed, and certainly didn't ask for ! Chrome is selected as the default and I am unable to delete and wipe off Delta Search.
- is 'search' listed as a search engine? Is 'Chrome' listed as one too? I am not familiar with either. Can you not select 'edit search engines' in the address bar? I would suggest ( for next time?) that you remove ALL except the one you want.

ExSp33db1rd
5th Feb 2013, 01:08
BOAC

Thank you for the suggestion, in Chrome /Settings/Manage Search Engines/ one gets a list of search engines and is able to select a default. What you led me to was the ability to then hover over an unwanted one, this shades over and - surprise, surprise, an X appears at the end of the line - hitting this removes that selection !

Unfortunately the laptop that started all this is not available at the moment - I'll try if I can get into that same page on the installed Firefox when I get it back, and wipe out Delta Search - and Bing, and a couple of others that have appeared from nowhere.

Slowly learning !

Milo Minderbinder
5th Feb 2013, 05:50
Just because Bing is a Microsoft product, does not imply its undesirable malware. If anything for some things -e.g. tech info, its results are often better than Google. And the Bing search results tend to be less fettered with sponsored links