MySearchResults malware removal

My eldest was abused by this criminal enterprise earlier this week. He made a valiant effort to rip its tentacles from his Windows PC, but in the end the Chief Engineer had to step in.

The thing that makes mysearchresults particularly offensive is that it infects not only the profile of the active user, but all other users on a machine. The changes it makes to redirect its victim’s search efforts are global. Of course some might argue that this is only a problem if the user is running with admin rights, but since we’re talking about Windows here I won’t bother to respond to such a nonsensical point (Microsoft and most Windows software vendors have made it impossible by design to run applications, even the browser, with reduced privileges).

Because the software both resets the user’s home page and installs add-ins that redirect searches it, as well as making a considerable number of registry changes, removing it can be tedious.

Fortunately mysearchresults is now included in the latest Malware Bytes free (MBAM) signature files and can therefore be (mostly) eradicated by a quick scan with an updated version of that product.

The process I followed to remove mysearchresults started with a visit to the Windows Control Panel where I used Uninstall to remove the software.

This was only the beginning, however. To clean both Firefox and Internet Explorer required I had to manually remove the corresponding Add-in (in Firefox this was for each user) and reset the browser home page. In Firefox I also had to remove mysearchresults as a search provider and set a new default (in my case, startpage.com).

It wasn’t until late in the game that I thought to run MalwareBytes, after updating with the latest signatures. I’m actually not sure that MBAM alone would be sufficient, due to the embedding of add-in code in each user’s browser profile.

This entry was posted in Security, System Administration on by .

About phil

My name is Phil Lembo. In my day job I’m an enterprise IT architect for a leading distribution and services company. The rest of my time I try to maintain a semi-normal family life in the suburbs of Raleigh, NC. E-mail me at philipATlembobrothersDOTcom. The opinions expressed here are entirely my own and not those of my employers, past, present or future (except where I quote others, who will need to accept responsibility for their own rants).