Solved How to remove BuenoSearch effectively

Custom / CUSTOM
August 13, 2014 at 06:18:43
Specs: Windows 7, IntelQuadcore 2.8 GHz
Unfortunately I somehow acquired BuenoSearch, probably by not looking consistently at what is installed automatically if you don't prevent it. I tried to remove it with Windows Uninstall, then I tried with RevoUnistaller, all to no avail. Then looking around the internet I found that Spyhunter came up number one to remove it, but actually it didn't do the job, worse still I couldn't get rid of Spyhunter. Eventually Spyhunter was removed with Microsoft's Fixit. I have also been running Malwarebytes, which finds the following two items again and again:

PUP.Optional.Conduit.A located in: C:\...\AppData\Local\Chrome\User Data\Default\Preferences
PUP.Optional.BuenoSearch.A located in: C:\...\AppData\Local\Chrome\User Data\Default\Preferences

However, when I choose to put these items in quarantine, they remain or are re-installed from some hidden place in my PC, because running MalwareBytes again, it comes up with the same Find: PUP.Optional.Conduit.A and PUP.Optional.BuenoSearch.A

When searching for "Bueno" with Windows search or with Everything search, nothing is found, but Malwarebytes finds it..

When googling "BuenoSearch" some results call it a re-directing search engine which steals your personal data, when others only call it a nuisance.

Help to get really rid of the BuenoSearch nuisance would be highly appreciated. Regards

message edited by willem1933

See More: How to remove BuenoSearch effectively

Report •

August 13, 2014 at 08:13:21
Download and Save the file from here:

Double click the saved file to run the program then select Scan. After the scan it will list what it found under various headings, although I've usually found it safe to just run the Clean. If it finds anything (almost certain) then keep the log in case you need further attention.

This little freebie is quite different to MalwareBytes because if looks for toolbars and their remnants.

I assume you have already looked in "Control Panel > Programs and Features" to ensure nothing unwanted is lurking there.

Always pop back and let us know the outcome - thanks

message edited by Derek

Report •

August 13, 2014 at 14:44:11
✔ Best Answer
Step 1: After running AdwCleaner, Copy & Paste the contents of the log in your next post please.

Step 2: Run Junkware Removal Tool
How to download from Softpedia
Download Junkware Removal Tool onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Warning! Once the scan is complete JRT will shut down your browser with NO warning.
Shut down your protection software now to avoid potential conflicts.
Temporarily disable your antivirus and any antispyware real time protection before performing a scan.
Click this link to see a list of security programs that should be disabled and how to disable them.
Run the tool by double-clicking it. If you are using Windows Vista or Windows 7/8, right-click JRT and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved onto your Desktop and will automatically open.
Copy and Paste the contents of the JRT.txt log please.

Report •

August 15, 2014 at 01:54:54
Thank you Derek and Johnw,

Ran both scans and found the following with ADWCleaner:

# AdwCleaner v3.305 - Report created 15/08/2014 at 09:31:39
# Updated 14/08/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Willem - WILLEM-PC
# Running from : C:\Users\Willem\Downloads\adwcleaner_3.305.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\DSearchLink
Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Users\Willem\AppData\Roaming\FirefoxToolbar
Folder Deleted : C:\Users\Willem\AppData\Roaming\NCH Software
File Deleted : C:\END
File Deleted : C:\Windows\System32\GroupPolicy\User\Registry.pol
File Deleted : C:\Users\Willem\daemonprocess.txt

***** [ Scheduled Tasks ] *****

Task Deleted : EPUpdater

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DefaultTab

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239

-\\ Mozilla Firefox v32.0 (x86 en-US)

[ File : C:\Users\Willem\AppData\Roaming\Mozilla\Firefox\Profiles\gwoao6ut.default\prefs.js ]

Line Deleted : user_pref("", "");

-\\ Google Chrome v38.0.2121.3

[ File : C:\Users\Willem\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://{searchTerms}
Deleted [Search Provider] : hxxp://{searchTerms}&Suggest=&stype=Homepage&useHistory=0&CUI=UN71537895711714268&UP=SP1151EEB4-F06E-4208-AB39-5E8A72976FB6&UM=2&SelfSearch=1&SearchType=SearchWeb&SearchSource=48&ctid=CT3306926&octid=CT3306926
Deleted [Search Provider] : hxxp://{searchTerms}
Deleted [Search Provider] : hxxp://{searchTerms}


AdwCleaner[R0].txt - [2396 octets] - [15/08/2014 08:27:18]

Also ran the JunkwareRemovalTool and found:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Willem on 15.08.2014 at 9:52:39.24

~~~ Services

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C505E21E-7955-482F-A821-387D69F45A76}

~~~ Files

~~~ Folders

~~~ FireFox

Emptied folder: C:\Users\Willem\AppData\Roaming\mozilla\firefox\profiles\gwoao6ut.default\minidumps [2 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 15.08.2014 at 10:00:14.06
End of JRT log

Had already protected with Ghostery and DoNotTrackMe in Chrome, but that seems to be not sufficient looking at these reports. I think I even had more rubbish lik DSearch, SearchScopes and Conduit.

Again thank you

Report •

Related Solutions

August 15, 2014 at 03:24:47
Update & Run Malwarebytes' Anti-Malware ( MBAM ) Free Version again please. Use Quick scan ( now called Threat Scan )
Click the Settings tab at the top, and then in the left column, select Detections and Protections, and if not already checked place a checkmark in the selection box to Scan for rootkits.
Copy and Paste the contents of the log, in your reply please.

Report •

August 15, 2014 at 03:27:57
After running Malwarebytes again & posting the log, run this.

Please download Farbar Recovery Scan Tool and save it onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please Copy and Paste the contents into your reply.
The first time the tool is run, it makes also another log (Addition.txt).
The logs are large, upload them using this, or upload to a site of your choosing. No account needed. Give us the links please.

Report •

Ask Question