Searchqu won't go away!

May 22, 2011 at 08:24:51
Specs: Windows Vista
Searchqu keeps opening up when I open Google Chrome and when I try to search for anything.
I have tried looking through the programmes to uninstall for Bandoo, but that isn't there, I have also tried to look through programme files for anything named bandoo or searchqu and no luck. I tried to do a system restore to before this thing started happening and nothing.
I downloaded the HiJack This and gmer, but I really do not know much about computers and have no idea how to use these programmes.

Please help!

May 24, 2011 at 20:24:30
okdokee, this one isnt such an easy one to get rid of, but, there are some steps we can take that might make it easier for you. start the computer up into safe mode with networking, this should bypass all the junk that got installed with this malware. from there, download malwarebytes from, and run that program. then post the log, this is a really user friendly option to the other two. see what it finds and let me know.


May 25, 2011 at 04:54:35
Thank you so much for your help. This is what the malwarebytes has spat out at me:

Malwarebytes' Anti-Malware

Database version: 6672

Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 7.0.6001.18000

25/05/2011 12:53:52
mbam-log-2011-05-25 (12-53-52).txt

Scan type: Full scan (C:\|F:\|)
Objects scanned: 306982
Time elapsed: 47 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Public\downloads\nero ultra home edition plus keygens\nero8x.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\Users\Public\downloads\nero ultra home edition plus keygens\Keygen\nero8.keygen-addiction\nero8x.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

May 25, 2011 at 05:00:33
But the searchqu is still there :(

July 12, 2011 at 09:14:10
I still can't get rid of it! Really, can someone help?! It's extremely frustrating!

July 12, 2011 at 12:41:12

Try the following:

Please download the Kaspersky Virus Removal Tool:

Save it to your Desktop
Right click the downloaded setup file, and select: Run as Administrator

At the main screen of the tool, in the AutoScan tab, make sure the first three options are checked

Next, scroll down to check the box next to the C:/ drive

Click on: Start Scan

When the scan is finished, click on: Report (at the bottom)

In the Detailed Report screen, make sure the three buttons at the top are set to:
Autoscan, Do not group, and, Important events

Click on Save, and save to the Desktop

>>Please provide the Kaspersky Virus Removal Tool report in your reply.<<

Now, download the following tool which will provide us information needed to remove SearchQu:

Download from:

Select: Version 2.0.4 > Installer
Save to the Desktop.

Double-click the HijackThis.exe icon on the Desktop,

When HijackThis opens, press the Scan button

When done scanning, a log appears on your Desktop.

>>Please post the HijackThis log in your reply.<<

Retired - Doin' Dis, Dat, and slapping malware.

July 24, 2011 at 23:18:44
its not a virus.
if you are using google chrome;
1)click on the spanner at the top right hand side
3)it should come up under basics
4)where it says home page, it should be on open this page:
change it to whatever you like and it will not come up as your homepage when you open your browser.

firefox users
3)click general
4)it should say home page: or whatever. change to google or whatever you want and click ok. tada! done.

IE users. basically the same as firefox. :)

August 14, 2011 at 10:09:27
August 14, 2011 at 10:27:58

Please start your own topic explaining the problem, and do not post a HijackThis log initially, since it will probably get removed.

Thanks for your cooperation.

Retired - Doin' Dis, Dat, and slapping malware.
Member of: Unified Network of Instructors and Trained Eliminators (UNITE)

