Browser redirecting to "http://ad.yieldmanager.com/st%3Fad_typ

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by victorydoc, Aug 11, 2008.

  1. victorydoc

    victorydoc Private E-2

    Hello All,

    Thanks in advance for your help and the tutorial. Hopefully I have been able to help-out and not make matters worse.

    Basically, my computer (doesn't happen on other machines) keeps redirecting me from my Yahoo e-mail to Dell/Google search page stating, "Sorry, we couldn't find http://ad.yieldmanager.com/st?ad_type. Here are some related websites:"

    This has been going on for about a week and I've run updated and most current versions Ad-Aware, Spybot, CCleaner, MABM, and my Symantec to no avail. Ran through the instructions and it's still occurring.

    I have performed the instructions as outlined in "READ & RUN ME FIRST"

    1. No malware programs were present to uninstall.
    2. All old Sun Java updates (7 in total) were uninstalled and Java(TM) 6 Update 10 was installed.
    3. MSConfig was set-up for Normal Mode.
    a. Now it is taking longer to start-up.
    b. I keep having to cancel a Windows Installer for ScanSoft PaperPort 10 as it says that I need to insert the CD that came with it.
    c. A lot more sh-- is in the right lower corner.
    d. This is secondary once the primary issue gets resolved (hopefully).
    4. I have the corporate edition of Symantec and it won't let me delete ~35 infected files that are backed-up in quarantine. And now, it is missing from the icon tray!
    5. Recycle Bin is emptied
    6. CCleaner has been run.
    7. Hidden files, system files, and file extensions are enabled.
    8. SAS was dowloaded and ran. Log is attached. No problems were found.
    9. Spybot was updated and ran. A problem was fixed (Microsoft security
    center thing that always pops up.
    10. MBAM ran and found nothing. Log is attached.
    11. ComboFix was run and deleted a file. Log is attached.
    12. MGTools was run and log will be uploaded in next post in this thread.

    Re-started my computer, and noted the same re-direct. Plus, as mentioned, my Symantec icon is now missing from the icon tray, in addition to the little start-up issues.

    Again, thanks for your help. Sorry if this was a long initial post, just wanted to assure you that I read and followed the directions.
     

    Attached Files:

  2. victorydoc

    victorydoc Private E-2

    Here's the 4th log file. Thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Is the below registry setting something you recognize?


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button.
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Also Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.


    Delete the below file:
    C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (LAPTOP-Ara Metjian).job



    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!



    Now let's flush the Java Cache
    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.


    Now let's flush the Internet Explorer Cache
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.
    Now run Ccleaner!


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. victorydoc

    victorydoc Private E-2

     
  5. victorydoc

    victorydoc Private E-2

    Please ignore previous post! I had my head up my @$$ and didn't see the MGTools folder in C:\. I kept clicking on the .exe file over and over again.

    Ok...

    Ran analyse.exe and fixed all the entries EXCEPT:
    04-HKLM\...\Run:[UserFaultCheck] - I couldn't find it.

    Deleted the 06 file

    Question: Do I need the 02-BHO DriveLetterAccess; 02-BHO Browser Address Error Redirector, or the 02 - BHO: JQSIEStartDirector...? I was going over the HJT tutorial and the CSLID didn't show up for these two. Just curious.

    Plus, what can I get rid of from the 016?

    I have IE7, so I think I did what I was supposed to. When I re-loaded it, I had to start all over again.

    Flushed Java in the Control Panel.

    I also have JInitiator 1.3.1.28 and DID NOT reset anything, as I was not sure which things to clear/not clear. There is a Reset tab at the bottom of all windows.

    Flushed IE cache

    Ran CCleaner.

    Made the Notepad file and it stated that it was successful.
    Question Did I have Kazaa? I've never downloaded it before or used it.

    Ran CCleaner again and it cleaned about ~0.3Mb.

    Ran MGtools\GetLogs.bat and have attached the .zip file.

    Things so far look ok. I have to re-download IE7 for some reason or another, which is going on in another window right now...

    Question: How can I get my Symantec icon back in the tray? Is it still active? Which/how should I keep other things from starting up - I have to admit I used the msconfig to modify the start-up.

    Question: Which programs from the "READ & RUN" section should I keep?

    Question: Should I change the "View" for my folders?

    Thanks for your help!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are not malware. The first came with your Dell PC ( I believe it is installed as "URL Assistant" ) and you can uninstall it if desired. You may wish to read this: http://www.gadgetizer.com/2006/02/10/is-dell-stealing-traffic/

    And the second BHO is for Java.

    Also not malware, but you can remove all them if you wish. Just be aware that if these are sites that you use, all the files related to those will have to be redownloaded when you access those sites and try to use the related features.

    You will have to ask in the Software Forum or look within your program to see if it has an option to enable an disable the tray icon. Also make sure it is just not hidden from view.

    Read the link given in step 1 of the READ & RUN ME.




    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. victorydoc

    victorydoc Private E-2

    Chaslang,

    Thanks for the help. Things are moving along now, except I goofed up on another thing - I deleted Combofix from the desktop prematurely and as a result, the Run command didn't work. Anything else I will need to do to restore Windows? I deleted the other programs as instructed.

    As for the Symantec, I got rid of it and installed Avast! instead. On the prelim run it found a Trojan in the System Restore point.

    Appreciate all of your time and effort.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Then you did not finish my instructions which said to toggle System Restore.

    Since Symantec rarely uninstalls properly, it may be a good idea for you to run the below just to be sure it is all gone:

    Norton Removal Tool (SymNRT)
     
  9. victorydoc

    victorydoc Private E-2

    Sorry about that - when I tried to run Symantec from the Start Menu, an error message popped saying that it was missing some .dll file. I got panicky, un-installed it, and went for Avast!.

    Downloaded the Norton Removal device, ran it, re-booted, and then toggled the System Restore. It didn't ask to restart during the process.

    Is there anything else I need to do to remove the ComboFix files since I goofed that one up also?

    Should I restore the "View" options to not show extensions or hidden files?
     
  10. victorydoc

    victorydoc Private E-2

    Chaslang,

    For the most part, everything seems to be back to normal.

    There are some odd changes here and there. In IE7 browser lines are closer together and the font seems off. Also, I noticed that my SpywareBlaster and SpyBot had the database and "immunizations" rolled back, respectively. I re-applied them and it seems to have stuck.

    Is this expected with the changes we made?

    And, anything else I need to do about messing up the Combofix deletion?

    Again, thanks for your time. It's scary how busy this forum is...
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No.


    It is not a big deal but if you wish, you could just download the combofix.exe to your Desktop again and then run the removal instructions.

    Yes we are extremely busy. The good word spread quickly on the internet. ;)
     
  12. victorydoc

    victorydoc Private E-2

    Chaslang

    Thanks for all your help. Just need one more thing - how do I uninstall IE7? I installed Firefox and then went to unistanll IE7.

    I did it via the Control Panel, but it royally F'd up my system. When I restarted, it wouldn't go past the Microsoft logo and was just a blank black screen. I opened it up in Safe Mode, and was then able to restart in normally.

    Is there a better way to remove IE7?

    Just when you thought I would go away...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcme.

    Don't uninstall IE7. You may as well keep it since it is somewhat more secure that IE6 which is what you will wind up with if IE7 is uninstalled. You need IE on your system. It is an integral part of Windows and without it many websites cannot be used properly including Microsoft to get updates.
     
  14. victorydoc

    victorydoc Private E-2

    Chaslang,

    Just found that "Thanks" tab - if I had seen it earlier, it would've been pressed with every response.

    I'm reloading IE7 - should I just keep it in the background and used Firefox?

    We'll be posting a new thread on Monday as now my wife's browser is doing the same thing. And, she hasn't used her computer in about a week.

    What causing this re-direct?

    ----
    Update:

    Re-installed IE7 and restarted. No luck. Gets stuck on a plain black screen. The blue-tooth light is on, but that's about it. Have to manually turn off the computer and when rebooting, needed to use the "Last known good configuration..." option before Windows loaded.

    Damm...Just when I was ready to back-up everything and start really using this...
     
    Last edited: Aug 15, 2008
  15. victorydoc

    victorydoc Private E-2

    Alright - seems to be back to "normal".

    Should I run through the READ & RUN, toggle my system restore, and then back-up my computer?

    Thanks again for your help.
     
  16. victorydoc

    victorydoc Private E-2

    One more thing, but this time it's not my computer.

    While running through the READ & RUN (getting ready to do this to my wife's computer), I noticed a discrepancy in recommendation on how to manage start-ups.

    Your post, http://forums.majorgeeks.com/showthread.php?t=149804 says not to use CCleaner to manage start-ups. I saw this after I followed Major Attitude's page, http://forums.majorgeeks.com/showthread.php?t=106650 which says you can (should?) use CCleaner.

    CCleaner has a "Disable" and a "Delete" tab. If we want something not to start-up, is it preferable to use HJT or CCleaner, and should it be deleted or disabled if we can't do it through the program.

    Thanks.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Poor choice of wording. In the background would mean you have it running but are not actively using it. What I believe you mean is what I said, just keep it installed and only use it when necessary. ;)

    New PC questions belong in a new thread and can only be answered there. If having problems, run the READ & RUN ME.

    Please post in the Software Forum about your problems with IE7.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you want to run the READ & RUN ME on your PC again? I already requested that you toggle system restore back in msg # 6.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start a new thread for this PC.

    Major Attitude's thread is not up to date with the current version of CCleaner. DO NOT use it to control startups.
     
  20. victorydoc

    victorydoc Private E-2

    We'll be posting a new thread...

    I did toggle my System Restore afterward. Incidentally, Major Attitude's thread about toggling doesn't say to restart between disabling/enabling the System Restore. Does this matter?

    As for running through the READ & RUN again - I didn't know if by not toggling the System Restore when I should've initially, whether "something" could've have remained hidden or snuck back in or whatever.

    Please remember, if I knew what I was doing, I probably wouldn't have gotten that crud or be in such desperate need for help.

    Thanks for all of your help. This should be about it.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it does not matter. It is just something that I personally prefer a user to do after disabling SR. The restore points are supposed to be gone as soon as SR is disabled.

    Things in SR do not come back on their own. You have to use SR to restore from an infected restore point and then the malware could return. Restore points need to be deleted so that at some later point in time you do not restore from an infection restore point.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds