Remove lucky search pro pc cleaner and unico browser

Solved
MichelleCCM Posted messages 17 Status Member -  
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   -
Hello
while trying to download a PDF of a technical sheet I ended up with a lot of new software/viruses, I was able to uninstall some but now I can't.
Can you help me? Thank you for your response. Michelle

5 answers

  1. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    Hello,

    You have installed adwares and potentially unwanted programs on your PC that open ads and slow down your computer and web browsers.
    Here is the procedure to follow to remove them:

    Start with this:

    Follow the AdwCleaner tutorial https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= (by Xplode)
    Download it to your desktop or download folder.
    Run AdwCleaner, click on [Scan].
    The scan may take several minutes, please be patient.
    Once the scan is complete, do not uncheck anything, click on [Clean]

    Once the cleaning is complete, a report will open. Copy/paste the content of the report in your next response by copying and pasting.
    If that doesn't work, use the site http://pjjoint.malekal.com to host the report, provide the link to the report in a new message.

    Note: The report is also saved under C:\AdwCleaner[S1].txt

    then:

    Follow this FRST tutorial: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
    (and make sure to take the time to read it to apply correctly - everything is explained there).
    Download and run the FRST scan, this will generate three FRST reports:
    • FRST.txt
    • Shortcut.txt
    • Additional.txt


    Send, as explained, these three reports to the site http://pjjoint.malekal.com and return the three pjjoint links leading to these reports here in a new response so we can consult them.

    --
    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0
    1. MichelleCCM Posted messages 17 Status Member
       
      Oops, I'm missing the other reports, see you later :)
      0
    2. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
       
      yes, moving to FRST =)
      0
    3. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
       
      The links you just provided do not lead to the FRST reports.
      0
  2. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    Here is the correction to be made with FRST.
    You can refer to this explanatory note with screenshots to help you: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

    Open Notepad: Windows key + R, type notepad in the run field and click OK.
    Copy/paste the following into it:

    FF Extension: No Name - C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\searchengine@gmail.com [Not Found]
    FF Extension: No Name - C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\istart_ffnt@gmail.com [Not Found]
    FF Extension: No Name - C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com [Not Found]
    R2 WaNetworkEnhance Service; C:\Program Files (x86)\WaNetworkEnhance\WaNetworkEnhance Internet Enhancer\InternetEnhancerService.exe [686592 2015-03-31] () [File not signed]
    S2 sygydese; C:\Users\Lionel\AppData\Roaming\VOPackage\VOsrv.exe [X] <==== WARNING
    2015-04-01 18:38 - 2015-04-01 18:38 - 00000000 ____D () C:\Users\Lionel\AppData\Local\33444335-1427913506-3334-4D47-A45D367FCA72
    2015-04-01 18:35 - 2015-04-01 18:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaNetworkEnhance
    2015-04-01 18:35 - 2015-04-01 18:35 - 00000000 ____D () C:\Program Files (x86)\WaNetworkEnhance
    2015-04-01 18:35 - 2015-04-01 18:35 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.75
    2015-04-01 18:34 - 2015-04-01 18:54 - 00000000 ____D () C:\ProgramData\{d89dc274-7a29-dbdd-d89d-dc2747a209d1}
    2015-04-01 18:34 - 2015-04-01 18:34 - 00003464 _____ () C:\WINDOWS\System32\Tasks\avaavxvyex
    2015-04-01 18:34 - 2015-04-01 18:34 - 00000000 ____D () C:\Users\Lionel\AppData\Local\avaavxvyex
    2015-04-01 18:32 - 2015-04-01 18:32 - 00152504 _____ () C:\Users\Lionel\Downloads\adwcleaner.exe
    2015-04-01 18:03 - 2015-04-01 18:03 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
    2015-03-31 20:44 - 2015-03-31 20:44 - 00003152 _____ () C:\WINDOWS\System32\Tasks\{C91BDC06-3EEC-4B11-BF3F-594B4B4D0C7B}
    2015-03-31 20:40 - 2015-03-31 20:40 - 00007226 _____ () C:\claraInstaller.txt
    2015-03-31 20:40 - 2015-03-31 20:40 - 00003164 _____ () C:\WINDOWS\System32\Tasks\Run_Browser
    2015-03-31 20:40 - 2015-03-31 20:40 - 00000000 ____D () C:\Users\Lionel\AppData\Local\UnicoBrowser
    2015-03-31 20:39 - 2015-03-31 20:41 - 00001634 _____ () C:\WINDOWS\SysWOW64\${LOGFILE}
    2015-03-31 20:26 - 2015-03-31 20:30 - 00000000 ____D () C:\Users\Lionel\AppData\Roaming\Opera Software
    2015-03-31 20:26 - 2015-03-31 20:30 - 00000000 ____D () C:\Users\Lionel\AppData\Local\Opera Software
    2015-03-31 20:25 - 2015-03-31 20:46 - 00000000 ____D () C:\Program Files (x86)\MiniGet
    2015-03-31 20:25 - 2015-03-31 20:25 - 00000000 ____D () C:\Users\Lionel\AppData\Roaming\MiniGet
    2015-03-31 20:24 - 2015-04-01 18:53 - 00001354 _____ () C:\WINDOWS\Tasks\VEMNE.job
    2015-03-31 20:24 - 2015-03-31 20:30 - 00000000 ____D () C:\Program Files (x86)\Opera
    2015-03-31 20:24 - 2015-03-31 20:24 - 01520640 _____ (HQ CinemaV31.03) C:\Users\Lionel\AppData\Roaming\VEMNE.exe
    2015-03-31 20:24 - 2015-03-31 20:24 - 00004358 _____ () C:\WINDOWS\System32\Tasks\VEMNE
    2015-03-31 20:23 - 2015-04-01 18:53 - 00001702 _____ () C:\WINDOWS\Tasks\BMXGEJC.job
    2015-03-31 20:23 - 2015-03-31 20:23 - 01920000 _____ (HQ CinemaV31.03) C:\Users\Lionel\AppData\Roaming\BMXGEJC.exe
    2015-03-31 20:23 - 2015-03-31 20:23 - 00004708 _____ () C:\WINDOWS\System32\Tasks\BMXGEJC
    2015-03-31 20:22 - 2015-03-31 20:22 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
    2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Lionel\AppData\Roaming\BMXGEJC
    2015-03-26 21:14 - 2015-03-26 21:14 - 00004185 _____ () C:\Users\Lionel\AppData\Roaming\VEMNE
    2015-04-01 18:09 - 2015-02-04 04:31 - 00000000 ____D () C:\ProgramData\0c3a7392-abfa-41f5-95a9-5e339ac76b7b

    Once the text is pasted into Notepad.
    File menu then Save As.
    On the left, select the desktop.
    In the bottom field, file name enter: fixlist.txt
    Click on Save - this will create a fixlist.txt file on the desktop.

    Restart FRST and click on the Fix button
    Depending on how a restart is necessary (not mandatory).
    A text file appears, copy/paste the content here in a new message.

    Restart the computer

    Then reset your browsers:
    ==================================
    Reset your browsers or manually reconfigure your web browsers (homepage, search engine, etc.) and also remove/disable unnecessary/parasite extensions:

    --
    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0
    1. MichelleCCM Posted messages 17 Status Member
       
      Here is the new FIX report
      Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
      Ran by Lionel at 2015-04-01 21:32:38 Run:1
      Running from C:\Users\Lionel\Desktop
      Loaded Profiles: Lionel (Available profiles: Lionel)
      Boot Mode: Normal
      ==============================================

      Content of fixlist:

    2. FF Extension: No Name - C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\searchengine@gmail.com [Not Found]
      FF Extension: No Name - C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\istart_ffnt@gmail.com [Not Found]
      FF Extension: No Name - C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com [Not Found]
      R2 WaNetworkEnhance Service; C:\Program Files (x86)\WaNetworkEnhance\WaNetworkEnhance Internet Enhancer\InternetEnhancerService.exe [686592 2015-03-31] () [File not signed]
      S2 sygydese; C:\Users\Lionel\AppData\Roaming\VOPackage\VOsrv.exe [X] <==== ATTENTION
      2015-04-01 18:38 - 2015-04-01 18:38 - 00000000 ____D () C:\Users\Lionel\AppData\Local\33444335-1427913506-3334-4D47-A45D367FCA72
      2015-04-01 18:35 - 2015-04-01 18:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaNetworkEnhance
      2015-04-01 18:35 - 2015-04-01 18:35 - 00000000 ____D () C:\Program Files (x86)\WaNetworkEnhance
      2015-04-01 18:35 - 2015-04-01 18:35 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.75
      2015-04-01 18:34 - 2015-04-01 18:54 - 00000000 ____D () C:\ProgramData\{d89dc274-7a29-dbdd-d89d-dc2747a209d1}
      2015-04-01 18:34 - 2015-04-01 18:34 - 00003464 _____ () C:\WINDOWS\System32\Tasks\avaavxvyex
      2015-04-01 18:34 - 2015-04-01 18:34 - 00000000 ____D () C:\Users\Lionel\AppData\Local\avaavxvyex
      2015-04-01 18:32 - 2015-04-01 18:32 - 00152504 _____ () C:\Users\Lionel\Downloads\adwcleaner.exe
      2015-04-01 18:03 - 2015-04-01 18:03 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
      2015-03-31 20:44 - 2015-03-31 20:44 - 00003152 _____ () C:\WINDOWS\System32\Tasks\{C91BDC06-3EEC-4B11-BF3F-594B4B4D0C7B}
      2015-03-31 20:40 - 2015-03-31 20:40 - 00007226 _____ () C:\claraInstaller.txt
      2015-03-31 20:40 - 2015-03-31 20:40 - 00003164 _____ () C:\WINDOWS\System32\Tasks\Run_Browser
      2015-03-31 20:40 - 2015-03-31 20:40 - 00000000 ____D () C:\Users\Lionel\AppData\Local\UnicoBrowser
      2015-03-31 20:39 - 2015-03-31 20:41 - 00001634 _____ () C:\WINDOWS\SysWOW64\${LOGFILE}
      2015-03-31 20:26 - 2015-03-31 20:30 - 00000000 ____D () C:\Users\Lionel\AppData\Roaming\Opera Software
      2015-03-31 20:26 - 2015-03-31 20:30 - 00000000 ____D () C:\Users\Lionel\AppData\Local\Opera Software
      2015-03-31 20:25 - 2015-03-31 20:46 - 00000000 ____D () C:\Program Files (x86)\MiniGet
      2015-03-31 20:25 - 2015-03-31 20:25 - 00000000 ____D () C:\Users\Lionel\AppData\Roaming\MiniGet
      2015-03-31 20:24 - 2015-04-01 18:53 - 00001354 _____ () C:\WINDOWS\Tasks\VEMNE.job
      2015-03-31 20:24 - 2015-03-31 20:30 - 00000000 ____D () C:\Program Files (x86)\Opera
      2015-03-31 20:24 - 2015-03-31 20:24 - 01520640 _____ (HQ CinemaV31.03) C:\Users\Lionel\AppData\Roaming\VEMNE.exe
      2015-03-31 20:24 - 2015-03-31 20:24 - 00004358 _____ () C:\WINDOWS\System32\Tasks\VEMNE
      2015-03-31 20:23 - 2015-04-01 18:53 - 00001702 _____ () C:\WINDOWS\Tasks\BMXGEJC.job
      2015-03-31 20:23 - 2015-03-31 20:23 - 01920000 _____ (HQ CinemaV31.03) C:\Users\Lionel\AppData\Roaming\BMXGEJC.exe
      2015-03-31 20:23 - 2015-03-31 20:23 - 00004708 _____ () C:\WINDOWS\System32\Tasks\BMXGEJC
      2015-03-31 20:22 - 2015-03-31 20:22 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
      2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Lionel\AppData\Roaming\BMXGEJC
      2015-03-26 21:14 - 2015-03-26 21:14 - 00004185 _____ () C:\Users\Lionel\AppData\Roaming\VEMNE
      2015-04-01 18:09 - 2015-02-04 04:31 - 00000000 ____D () C:\ProgramData\0c3a7392-abfa-41f5-95a9-5e339ac76b7b


      C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\searchengine@gmail.com not found.
      C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\istart_ffnt@gmail.com not found.
      C:\Users\Lionel\AppData\Roaming\Mozilla\Firefox\Profiles\e802xux2.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com not found.
      WaNetworkEnhance Service => Unable to stop service
      WaNetworkEnhance Service => Service deleted successfully.
      sygydese => Service deleted successfully.
      C:\Users\Lionel\AppData\Local\33444335-1427913506-3334-4D47-A45D367FCA72 => Moved successfully.
      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaNetworkEnhance => Moved successfully.

      "C:\Program Files (x86)\WaNetworkEnhance" directory move:

      Could not move "C:\Program Files (x86)\WaNetworkEnhance" directory. => Scheduled to move on reboot.

      C:\Program Files (x86)\Optimizer Pro 3.75 => Moved successfully.
      C:\ProgramData\{d89dc274-7a29-dbdd-d89d-dc2747a209d1} => Moved successfully.
      C:\WINDOWS\System32\Tasks\avaavxvyex => Moved successfully.
      C:\Users\Lionel\AppData\Local\avaavxvyex => Moved successfully.
      C:\Users\Lionel\Downloads\adwcleaner.exe => Moved successfully.
      C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
      C:\WINDOWS\System32\Tasks\{C91BDC06-3EEC-4B11-BF3F-594B4B4D0C7B} => Moved successfully.
      C:\claraInstaller.txt => Moved successfully.
      C:\WINDOWS\System32\Tasks\Run_Browser => Moved successfully.

      "C:\Users\Lionel\AppData\Local\UnicoBrowser" directory move:

      Could not move "C:\Users\Lionel\AppData\Local\UnicoBrowser" directory. => Scheduled to move on reboot.

      C:\WINDOWS\SysWOW64\${LOGFILE} => Moved successfully.
      C:\Users\Lionel\AppData\Roaming\Opera Software => Moved successfully.
      C:\Users\Lionel\AppData\Local\Opera Software => Moved successfully.
      C:\Program Files (x86)\MiniGet => Moved successfully.
      C:\Users\Lionel\AppData\Roaming\MiniGet => Moved successfully.
      C:\WINDOWS\Tasks\VEMNE.job => Moved successfully.
      C:\Program Files (x86)\Opera => Moved successfully.
      C:\Users\Lionel\AppData\Roaming\VEMNE.exe => Moved successfully.
      C:\WINDOWS\System32\Tasks\VEMNE => Moved successfully.
      C:\WINDOWS\Tasks\BMXGEJC.job => Moved successfully.
      C:\Users\Lionel\AppData\Roaming\BMXGEJC.exe => Moved successfully.
      C:\WINDOWS\System32\Tasks\BMXGEJC => Moved successfully.
      C:\WINDOWS\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf => Moved successfully.
      C:\Users\Lionel\AppData\Roaming\BMXGEJC => Moved successfully.
      C:\Users\Lionel\AppData\Roaming\VEMNE => Moved successfully.
      C:\ProgramData\0c3a7392-abfa-41f5-95a9-5e339ac76b7b => Moved successfully.

      > Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-04-01 21:35:09)<

      C:\Program Files (x86)\WaNetworkEnhance => Is moved successfully.
      C:\Users\Lionel\AppData\Local\UnicoBrowser => Is moved successfully.

      End of Fixlog 21:35:09

0
  • Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    Finish the rest and see what it gives.

    --
    Comme l'ange que tu es, tu ris en créant une légèreté dans ma poitrine,
    Tes yeux me pénètrent,
    (Ta réponse est toujours 'peut-être')
    C'est à ce moment-là que je me suis levé et suis parti.
    0
    1. MichelleCCM Posted messages 17 Status Member
       
      Good evening
      I have reset the internet and it seems to be working on Google with the internet server, but Mozilla, which I use for my Free email, remains connected to Lucky search
      Thank you
      I will try restarting again
      0
    2. MichelleCCM Posted messages 17 Status Member
       
      Well, I turned off and restarted both internet servers, it's Lucky Search that comes back,
      good night and thank you very much anyway.
      0
    3. MichelleCCM Posted messages 17 Status Member
       
      Hello
      I was away hence my silence, I just ran zhp cleaner, do you want the report? By the way, I was reading about how to protect the computer on your forum but I don't see a version for Windows 8, is it the same as Windows Vista/Seven/8?
      I'm restarting the computer to see if they are finally gone :)
      0
    4. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
       
      ZHPCleaner resolved the Lucky Search issue?
      0
  • Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    =))

    There you go, it's done, you can delete the programs used.

    Some advice:

    To prevent malicious sites, you can install Blockulicious: https://forum.malekal.com/viewtopic.php?t=46656&start=

    To avoid getting caught again.
    Read - Unwanted programs / PUPs: https://www.malekal.com/adwares-pup-protection/

    The rest of the security: http://forum.malekal.com/comment-securiser-son-ordinateur.html

    --
    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0