Category Archives: Uncategorized

Salus Adware – “Ads by Salus” Removal Instructions

Do you see ads labeled “Ads by Salus” while browsing the web, even on web sites that normally don’t have any advertisements? If so, you have the Salus Adware installed on your machine. Here’s how a Salus banner might look like:Ads by salusThe Salus adware, or Salus Protector, or Salus Internet Protector as the installer refers to it is bundled with other software downloads. I found Salus bundled with an unofficial Google Chrome download. Here’s how the disclosure looks like:

salus internet protector installer

For obvious reasons, Salus is adware. However, it appears as the anti-virus scanners have not yet started to detect it. Detection rate is 0/54 according to VirusTotal. I’m sure the anti-virus scanners will detect Salus sooner than later.

So, how can the Salus Adware be removed. No problem, you can easily uninstall it with FreeFixer. Just select the salus.exe and salus.sys file as shown in the screenshots below:

salus.sys driver salus.exe startup

Or from the uninstall programs dialog:

salus uninstall

Did you also have Salus installed on your machine? Any idea how it installed itself?

Hope you found this useful.

istartsurf.com – How Did It Install On Your Machine

Did your search settings in Internet Explorer, Firefox and Chrome recently change to istartsurf.com and you are wondering how this search engine was installed on your computer? Most likely, istartsurf.com was bundled with another software download. I’ve seen it bundled a couple of times and here’s how the disclosure looked like in the installers:

istartsurf in an installer istartsurf in a unofficial Google Chrome installer

If you’d like to remove istartsurf.com, you can do so from the Add/Remove programs dialog. If that does not work you can use FreeFixer to repair your browser settings.

Did you figure out which software download that bundled istartsurf.com? Please share by posting a comment below.

isearch.omiga-plus.com – How Did It Install On You Computer?

Did your search settings recently change to isearch.omiga-plus.com and you are wondering how this search engine was installed on your machine? Most likely, Omiga-Plus  was bundled with another download. I’ve seen it bundled twice and here’s how the installer windows looked like:

omiga-plus.com installer omigaplus-installer

You can remove Omiga-Plus from the Uninstall programs dialog. If that does not work you can use FreeFixer to repair your search and homepage settings.

Did you figure out which software download that bundled Omiga-Plus? Please share by posting a comment.

What is RelevantKnowledge and How Did It Install On Your Computer?

Did you just find something called RelevantKnowledge in the Add/Remove programs dialog or did you see a process running in the background named rlvknlg64.exe, rk.exe, rlvknlg.exe or rlservice.exe?

relevantknowledge uninstall

So, how did RelevantKnownledge install on your machine? I would say that it was likely bundled with another program that you installed. At least that’s how it installed in my case. I was installing one program, and all of a sudden another window popped up with an “Additional Offer”. This is how it could have looked like when it installed on your machine:

relevant knowledge bundled

Something that’s a bit strange is that the RelevantKnowledge installer window mention Linkular, but that was not what I was installing in the first place. If you want to find out when it was installed, you can check the “Created date” on the RelevantKnowledge file.

So what the RelevantSoftware do? Basically it monitors your browsing and shopping behaviour, then anonymise the data and aggregate it with other users that also run RelevantKnowledge, and generate a report that RelevantKnowledge’s clients use.

Hope that helped you figure out what RelevantKnowledge is.

PriceLess and Supporter 1.80 Removal Instructions

Did you spot something called PriceLess and Support 1.80 on your machine? No problem,  I’ll show how to remove them. I found PriceLess bundled in a download claiming to be an episode of a famous TV-series. If you got this on your computer, you will see ads labeled “Ads by PriceLess” or “Ad by PriceLess“.

Ad by PriceLess Ads by PriceLess inserted into Google search results

PriceLess adds itself in Internet Explorer and Mozilla Firefox as an add-on.

PriceLess 5.2 in Firefox Priceless in Internet Explorer

So what’s the problem with PriceLess? The scan result from VirusTotal clearly shows why you’d want to remove the PriceLess software. Adware/Win32.Agent and Multiplug.BAY are a few of the detection name. The detection rate is pretty low though, only 12%.

priceless virustotal report

Removing PriceLess and Supporter 1.80 can be done from the Add/Remove programs dialog, or if that for some reason would fail you can remove them using FreeFixer by selecting the files as shown in the screenshots below:

PriceLess uninstall

priceless bho priceless appinit_dlls priceless firefox ext

How did you get PriceLess on your machine? Please share by posting a comment.

TinyWallet – Removal Instructions

Yesterday I was playing around with one of those installers that usually bundles a bunch of adwares. Found a new one called TinyWallet. TinyWallet installs itself as an add-on in Firefox, Internet Explorer and Chrome. If you got this on your machine, you will see ads labeled “Ad by TinyWallet” and “Powered by TinyWallet“.

Powered by TinyWallet

 

Ad by TinyWallet

Here’s how TinyWallet appears in Firefox’s add-ons menu:

TinyWallet firefox add-on

Tiny Wallet appears to be brand new. The tinywallet.net domain was registered 6 days ago, on the 4th of August, 2014.

tinywallet.net web site

According to the web site, TinyWallet will:

offer you the best deals with the lowest prices, from coupons, to discounts and the hottest sales. .. It shall offer you suitable coupons and discounts whilst you are shopping

Some of the anti-virus scanners are already picking up the TinyWallet files according to VirusTotal. Preloader, PreLoad and MultiPlug are some of the detection names.

tinywallet virustotal

Removing TinyWallet is easy. Just uninstall it from the Add/Remove programs dialog, or select the TinyWallet files for removal in FreeFixer.

TinyWallet uninstall

TinyWallet browser helper object TinyWallet firefox extension

Did you also have TinyWallet on your machine? Any idea how it got there?

Update 2014-09-22: Here’s how TinyWallet is disclosed in one of the installers that bundled it:

tinywallet installer

KeepMySearch and OneKit – Removal Instructions

Yesterday I was fooling around with one of those downloads that I know bundles various types of unwanted software. I ran the installer over and over again to see if any new bundled software would install. Bingo.

Found something called OneKit and KeepMySearch, which added a desktop icon in form of a orange magnifying glass and a process named onekit.exe running in the background. The onekit.exe file was digitally signed by Montiera Technologies LTD. The company description on the file is Pay By Ads LTD.

onekit icon

When double-clicking on the OneKit icon a dialog for something called KeepMySearch popped up.

keepmysearch popup

And when opening my Firefox browser, the Keep My Search widget appeared on the left side:

keepmysearch widget

The same KeepMySearch widget also appeared in Google Chrome.

Only a few of the anti-virus scanners are detecting the onekit.exe file according to VirusTotal. Just a 9% detection rate. Montiera and PUP.Optional.PayByAds.A are two of the detection names for onekit.exe.

onekit.exe virustotal report: 9% detection rate

OneKit has an entry in the Uninstall program dialog which should allow you to uninstall it. I have not tried it though. FreeFixer can remove the OneKit software by selecting the two entries in the scan result as shown in the screenshots below.

onekit uninstaller

onekit.exe process onekit.exe startup

Did you also get the OneKit and the KeepMySearch software on your computer? Any idea where you got it?

 

How Did ShopperFriend Install On Your Machine?

Did you find something called ShopperFriend on your machine and wonder where it came from? Chances are that you got it from clicking one of the ads over at The Pirate Bay. That’s where I found ShopperFriend, bundled in an executable that pops up when mistakenly clicking one of the ads instead of the real .torrent download.

Here’s how the minimal disclosure looks like in the installer. As you can see, there’s no explanation of what the ShopperFriend software does.

shopperfriend

Did you also get ShopperFriend from The Pirate Bay?

CashNBack and NCupons – Removal Instructions

Found another bundled piece of software this morning. It’s called Cash’n’Back or NCupons and has been around for a while. If you have this on your machine, you’ll see the CashNBack.exe process running in the background.

Cash’n’Back is bundled with other software downloads. Here’s how it is disclosed in the installer where I found it:

cashnback installer

CashNBack’s web site it ncupons.com if you’d like to review the Terms and Conditions and the Privacy Policy.

cashnback's web site is ncupons.com

If you’d like to remove NCupons/CashNBack you can do so from the Add/Remove programs dialog, or by selecting the Cash’n Back files in FreeFixer.cashnback uninstall

cashnback

I uploaded the CashNBack.exe file to VirusTotal and MalwareBytes detected it as PUP.Optional.CashNBack.A.

How To Remove The Glomatron Adware

Stumbled on an adware called Glomatron yesterday when testing a software download. Glomatron was disclosed in the installer as you can see below. Basically Glomatron will insert various types of ads by modifying the web pages you currently visit. According to the installer it may show offers, coupons, related search results, etc.

Glomatron bundled

Generally, software such as Glomatron is distributed by bundling. That is, the software is included in an unrelated download. You can avoid Glomatron and other bundled software by carefully reviewing what the installer displays and opting out from the unwanted software, before proceeding in the installer by clicking the Next, Accept or Install button.

Here’s how Glomatron appears in Firefox:

glomatron in firefox

So how can Glomatron be removed. It’s pretty easy with FreeFixer, just select the Glomatron files for removal and the ads will be gone. You can also uninstall it from the Add/Remove programs dialog.

glomatron internet explorer bho glomatron firefix add-on

Did you also get Glomatron on your machine? What kind of download was it and where did you find it?