Forum » Computer Security » remove “search.com”
May 18, 2012
This pesky search engine “search.com” has installed itself (and god knows what else) in Firefox. How can i remove it?
Mostly, this hijacking virus is installed together with a Rootkit Trojan. Search the web for Kasperksy’s TDSSKiller and use that tool to check whether you are infected with a rootkit. TDSSKiller will cure if your computer is positive with this Trojan.
To manually remove search.com redirect, you may follow this guide when using Firefox.
1. Open Mozilla Firefox Internet Browser.
2. On Google’s Search box, click the “arrow down” beside the logo.
3. Select “Manage Search Engine” from the drop-down list.
4. Choose your desired search default and click the button “Move up.” It should be on the top of the list to set it as default.
5. You can now remove “search.com” and other installed search engine.
i will try it
thanks to give this suggestion
I just tried that, rebooted, etc., and it still will not go away. I am afraid to use the Windows uninstall program, because I read somewhere else that this will actually reinforce search.com. If I do a search of my computer, I cannot find TNT2user.exe, so can’t remove that file. I think it piggybacked on the open source VLC Media Player program, an otherwise legitimate program I’ve used on my netbook, since that’s the only program I downloaded at the time it shows that search.com appeared. Any more suggestions? Thanks.
I am having similar issues after downloading VLC Media Player. At this point, I don’t think search.us.com has installed as it wants me to close my Google Chrome browser so it can, and I haven’t yet because I don’t want it to install. I am searching for the TNT2USER.EXE file to delete it, but it doesn’t seem to be there. Any suggestions?
I am having the same issue after having installed VLC media player. I continually see an alert dialogue asking me to close google chrome so that I can install search.com. Very annoying. Two programs running in the background seem to be the culprit, TNT2User.exe *32 and TurboVHelp.exe *32 when I close these I don’t get the dialogue, but there’s no way for me to uninstall them…. Help!
Update: On my computer the file TNT2User.exe was located here: C:\Users\Nate\AppData\Local\TNT2\184.108.40.2064
If you open your task manager, right click on the file and then go to properties, you’ll be able to find its location, even though it won’t show up on searches.
thanks for this post
I have been chasing this for hours. the hijacked web page, ‘start.search.us.com’ seems to be triggered by TNT2user.com., at ;least that’s what my registry says. You cannot stop them running or delete them or unstall them in normal mode. Other sites say it must be done in safemode
I found it under c:\documents and settings\user\local settings\application data\tnt2
Comments are closed.