This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

How do I get rid of the Claro Search !

more options

How do I grid rid of this damned Claro Search ?

How do I grid rid of this damned Claro Search ?

Chosen solution

Please download AdwCleaner and save it on your Desktop. http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner

1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.

2.Click on Delete button.

3.Confirm each time with OK.

4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

Read this answer in context 👍 45

All Replies (14)

more options

See these threads and pages about Claro-search:

more options

Have cleared Chrome & IE Firefox is harder Unable to remove cookies, see attachment, as they are greyed out will no delete

more options

Chosen Solution

Please download AdwCleaner and save it on your Desktop. http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/2-adwcleaner

1.Right-click on adwcleaner.exe and select Run As Administrator to launch the application.

2.Click on Delete button.

3.Confirm each time with OK.

4.Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

more options

Finally! A fix that worked. It has taken me three days to find this answer. Everything else I found online and tried did not work but this one did. Yay and thanks for that!

Adwcleaner after I installed and ran it, restarted my laptop and told me it had deleted on reboot: Browser Manager Babylon Funmoods plus an entire profile it had created for itself.

more options

I was amazed where these infections probably came from Cnet's download.com See below

http://insecure.org/news/download-com-fiasco.html

I blamed the software authors easeus todo but reading the above the are probably off the hook :-) It will be some time before I point my browser toward download.com

CNET's Download.com is one of the most popular (currently ranked #174 worldwide by Alexa) and longest-running (been around since 1996) major sites on the Internet. As a download repository, their key value ad was that they screened software to avoid malware, spyware, adware, viruses and other harmful content that certain shady software contains. Even many security experts recommended them as a safe place to download software online. Download.com is run by CNET, which is part of the 17-billion dollar CBS media empire. Many people assumed that a major site like this wouldn't resort to unethical monetization schemes like adding spyware and other malware to their downloads.

Unfortunately, those people were wrong. In August 2011, Download.com was taken on a new path by their General Manager and V.P. Sean Murphy. They started wrapping legitimate 3rd party software into their own installer which by default installs a wide variety of adware and other questionable software on users machines. It also does things like redirect user search queries and change their Internet home page. At first their installer forced people to accept the malware or close the installer (see screen shot of infected VLC installer in this article). Later they added a non-default "decline" button hidden way on the left side of the panel. Also, the initial installer shown in the previous screen shot claimed the software was “SAFE, TRUSTED, AND SPYWARE FREE”. In an unusual show of honesty, they removed that claim from the rogue installer.

While it is common for internet criminals to infect software installers in this way, we never expected it from a previously-reputable site like Download.com. Especially given their “Download.com Adware & Spyware Notice” which, until early 2012, said:

   “In your letters, user reviews, and polls, you told us bundled adware was unacceptable--no matter how harmless it might be. We want you to know what you're getting when you download from CNET Download.com, and no other download site can promise that.”


and ...

   “every time you download software from Download.com, you can trust that we've tested it and found it to be adware-free.”
more options

Wow I did not know that. And I can virtually guarantee it was a download from CNET that gave me the Trojan. Nasty, too - took three days and countless other "fixes" that didn't help to get it off. We trusted CNET! Ah, greed I guess.

more options

AdwCleaner worked for me. I'm sure I got the infection from download.com aka download.cnet.com. The Norton plugins that should have blocked it were disabled, that might not have been related.

None of the 20 or so other recommended solutions I tried (including Malwarebytes and Spybot) worked. There was no sign of Claro or Babylon in the file system, registry, or Programs control panel, but it still showed up as my home page in Firefox.

more options

Download.com is the culprit. I will never download from them again!!

more options

Well wat can i say.....This is first answer i came across on google and WOW :-D its amazing! Worked an #ABSOLUTE #TREAT ...........Thanks very much to person who posted this!!

You have saved me sooooo much time and effort!

A massive #THUMBS-UP :-D

Again Thanks :-D

more options

Cannot not believe i used to download from there years ago and neva had an issue wat soi eva and NOW wat a crock of shit!!

Thanks to all you lots for addin this to the forum and thanks for lettin me kno wher it had come from, For sure i will not b downloadin from ther again!!!!

more options
more options
# AdwCleaner v2.101 - Logfile created 12/20/2012 at 22:15:12
# Updated 16/12/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : ciandlm - CIANDLM-HP
# Boot Mode : Normal
# Running from : C:\Users\ciandlm\Downloads\adwcleaner(2).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\bprotector_extensions.sqlite
File Deleted : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\bprotector_prefs.js

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKU\S-1-5-21-3908336352-2876483464-4255810714-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (en-US)

Profile name : default 
File : C:\Users\ciandlm\AppData\Roaming\Mozilla\Firefox\Profiles\mi03zeuc.default\prefs.js

Deleted : user_pref("browser.search.order.1", "Claro Search");
Deleted : user_pref("browser.search.selectedEngine", "Claro Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://www.claro-search.com/?affID=117452&tt=5012_1&babsrc=HP[...]
Deleted : user_pref("keyword.URL", "hxxp://www.claro-search.com/?affID=117452&tt=5012_1&babsrc=KW_ss&mntrId=ac[...]

-\\ Google Chrome v23.0.1271.97

File : C:\Users\ciandlm\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [5716 octets] - [12/12/2012 21:14:58]
AdwCleaner[S2].txt - [2177 octets] - [16/12/2012 19:30:49]
AdwCleaner[S3].txt - [2074 octets] - [20/12/2012 22:15:12]

########## EOF - C:\AdwCleaner[S3].txt - [2134 octets] ##########

Modified by cor-el

more options
# AdwCleaner v2.101 - Logfile created 12/21/2012 at 19:50:30
# Updated 16/12/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Katie - KATIE-HP
# Boot Mode : Normal
# Running from : C:\Users\Katie\Downloads\adwcleaner(1).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\ProgramData\Premium
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\bprotector_extensions.sqlite
File Deleted : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\bprotector_prefs.js
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Folder Deleted : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKU\S-1-5-21-3521296510-1739712518-1077748139-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v17.0.1 (en-US)

Profile name : default 
File : C:\Users\Katie\AppData\Roaming\Mozilla\Firefox\Profiles\q8pckmc1.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v23.0.1271.97

File : C:\Users\Katie\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [24747 octets] - [21/12/2012 19:45:54]
AdwCleaner[S3].txt - [3107 octets] - [21/12/2012 19:50:30]

########## EOF - C:\AdwCleaner[S3].txt - [3167 octets] ##########

Modified by cor-el

more options

Moderator locked this thread - we don't need AdwCleaner logs posted here.