Adware.SearchGo

Short bio

Adware.SearchGo is Malwarebytes’ detection for a family of browser hijackers targeting Windows systems.

Protection

Malwarebytes protects users from Adware.SearchGo by using real-time protection.

block Adware.SearchGo

Malwarebytes blocks Adware.SearchGo

Remediation

Malwarebytes can detect and remove Adware.SearchGo without further user interaction.

  1. Please download Malwarebytes to your desktop.
  2. Double-click MBSetup.exe and follow the prompts to install the program.
  3. When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
  4. Click on the Get started button.
  5. Click Scan to start a Threat Scan.
  6. Click Quarantine to remove the found threats.
  7. Reboot the system if prompted to complete the removal process.

For users that have had their browsers hijacked, we recommend having a look at our Browser Restore page.

Malwarebytes removal log

A Malwarebytes log of removal will look similar to this:

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 8/4/17
Scan Time: 9:12 AM
Log File: mbamSearchgoi.txt
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2505
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 320447
Threats Detected: 10
Threats Quarantined: 10
Time Elapsed: 1 min, 29 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 2
Adware.RuKometa, C:\WINDOWS\MICROSOFT\SVCHOST.EXE, Quarantined, [147], [421085],1.0.2505
Adware.RuKometa, C:\WINDOWS\MICROSOFT\SVCHOST.EXE.EXE, Quarantined, [147], [419654],1.0.2505

Module: 2
Adware.RuKometa, C:\WINDOWS\MICROSOFT\SVCHOST.EXE, Quarantined, [147], [421085],1.0.2505
Adware.RuKometa, C:\WINDOWS\MICROSOFT\SVCHOST.EXE.EXE, Quarantined, [147], [419654],1.0.2505

Registry Key: 1
Adware.RuKometa, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SvcHost Service Host, Delete-on-Reboot, [147], [421085],1.0.2505

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 5
Adware.RuKometa, C:\WINDOWS\MICROSOFT\SVCHOST.EXE, Delete-on-Reboot, [147], [421085],1.0.2505
Adware.RuKometa, C:\WINDOWS\MICROSOFT\SVCHOST.EXE.EXE, Delete-on-Reboot, [147], [419654],1.0.2505
Adware.SearchGo, C:\USERS\{username}\DESKTOP\SEARCHGOI.EXE, Delete-on-Reboot, [3560], [411104],1.0.2505
Adware.SearchGo, C:\USERS\{username}\APPDATA\LOCAL\TEMP\SEARCHGO0.DLL, Delete-on-Reboot, [3560], [411104],1.0.2505
Adware.SearchGo, C:\USERS\{username}\APPDATA\LOCAL\TEMP\SEARCHGO0.NEW.EXE, Delete-on-Reboot, [3560], [411104],1.0.2505

Physical Sector: 0
(No malicious items detected)


(end)

Select your language