Guce Asvertising Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Inkpat, Dec 21, 2019.

  1. Inkpat

    Inkpat Private E-2

    For the past week I have been hit with this message when I try to access AOL on MS Edge (Windows 10)
    "Hmm, cannot reach this page. Search for "https://guce.advertising.com" on Bing" So it's been infected by Guce Advertising. I am also having this problem on a Windows 7 computer My Yahoo home page now shows up with this added https://www.yahoo.com/?_guc_consent_skip=1576948901

    I can get my AOL on IE so it's only an Edge issue. Tried search Engine and there are many instructions for this particular malware but none seem to solve my problem (including Malwarebytes) or I can even follow other than installing a third party program which I don't trust.

    Your guidance will be appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this and if it does not work, you will need to go through the Read and Run First instructions:

    Restore Default Settings in Microsoft Edge
    Launch Microsoft Edge and then click the More Actions menu then click Settings.

    reset edge 1
    Scroll down to Clear browsing data then click Choose what to clear.

    By default, Browsing History, Cookies, saved website data, and Cached data files are checked, but you can choose from additional data options in the list. The Show more collapsed menu reveals other options to select.

    To reset the entire browser, check all options, then click Clear.
     
  3. Inkpat

    Inkpat Private E-2

    Here is the Adware file from the first page of your instructions. Should I wait until I get further instructions to add the additional files of information or just proceed now with the second page of the additional detection downloads?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try resetting Edge as I outlined?

    Yes, you can attach 5 logs per post. Please continue.
     
  5. Inkpat

    Inkpat Private E-2

    Yes, I followed your reset instructions explicitly and it did not have any effect. Many of the web pages I load in Yahoo & AOL have the "guce" expression in them, and other sites have nothing. I'll continue with the data files you have requested and submit them shortly.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK...please open each browser one by one and check your add ons.....remove any that relate to Guce. Continue with the scans and attach the logs.
     
  7. Inkpat

    Inkpat Private E-2

    I did check add-ons in both browsers (Edge and IE 11) and they had none. I was unable to get MG Tools to operate. It would open the "command window," begin to start, then a loop of nonstop "do you want to allow this program to change the registry?" prompts, to which I replied "yes," and once that was submitted, another would open..continuously and the computer was locked up until I stopped the process using the task manager. I was able to derive a "Hijack This" log from the MG tools folder and have enclosed that, but no other files.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have ad blockers installed on those browsers?

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  9. Inkpat

    Inkpat Private E-2

    MG Tools would not run under the GetRunKey or ShowNew command. Apparently, there must be a 64 bit version, but I could not find it on the link your site provided.

    UNSUPPORTED 16-BIT APPLICATION (title of informational window which opened up)

    The program or feature "\??\C:\MGTools\Itime.exe" cannot start or run due to incompatibity with 64-bit versions of Windows. Pleae contact the software vendor to ask if a 64-bit Windows compatible version is available.

    (button) OK
     
  10. Inkpat

    Inkpat Private E-2

    In response to your first question, I have no ad blockers installed. The computer uses the Windows Defender anti virus which was switched off to run MG Tools.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It runs under both versions.

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
     
  12. Inkpat

    Inkpat Private E-2

    Tim, here are the two logs from Farbar
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Next....I want you to:

    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  15. Inkpat

    Inkpat Private E-2

    Here is the fixlog.txt. Running zemana at the present time and will have a log shortly.
     

    Attached Files:

  16. Inkpat

    Inkpat Private E-2

    Zemana text; I note the "scan date" is listed as 12/21....not certain if that makes any difference, but the computer time stamp is accurate at present.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go to start / run / and type in %temp% .....when the folder opens, delete it all.
    Zemana did not find any malware in your browsers.

    Are you still having issues?
     
  18. Inkpat

    Inkpat Private E-2

    I really appreciate your in-depth walk through for this problem, however it has not gone away. Let me give you some examples. This is from my Edge browser....

    When logging into yahoo...my home page, I do reach it, but this is in the address line...
    https://www.yahoo.com/?_guc_consent_skip=1577250383

    Same with AOL
    https://www.aol.com/?_guc_consent_skip=1577250573
    (normally, it would be just the domain in both cases.)

    Then when I attempt to retrieve my mail, I get this line in Edge and my mail does not open at all
    https://guce.advertising.com/collec...-session_4e6ed3e0-e244-4a4a-a94d-e3b8ec12758c

    instead I get a mostly blank page and these few lines.....
    >>>>>>
    Hmmm...can’t reach this page
    Try this

    Details
    There were too many redirections.

    Error Code: INET_E_REDIRECT_FAILED
    >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
    I get the same extra info when doing this in IE Explorer 11...packaged with Win 10.....however, I can access my e-mail in IE 11...I am not restricted as I am in Edge.

    As you likely know Verizon now owns Yahoo & AOL.....these are the only two sites which I have a problem with.

    A mystery for certain...the corporate ownership of both of these sites took place months ago...and now, all of a sudden, I am seeing people with AOL accounts complain they can't get their mail to open in Edge. This issue took place around 10 days ago.
     
  19. Inkpat

    Inkpat Private E-2

    Tim, I did some checking on the "Down Detector" site and found a lot of complaints from various users that AOL mail access is a problem on their operating system and the "guce advertising" issue appears quite frequently. Am wondering if this is an issue exclusively with their system as far as interoperability.?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK.....let's try some manual searching.

    Hold together the Start Key and R. Type appwiz.cpl

    You are now in the Control Panel. Look for suspicious entries. Uninstall it/them.

    Type msconfig in the search field and hit enter. A window will pop-up:

    Startup —> Uncheck entries that have “Unknown” as Manufacturer or otherwise look suspicious.

    Open the start menu and search for Network Connections (On Windows 10 you just write it after clicking the Windows button), press enter.

    1. Right-click on the Network Adapter you are using —> Properties —> Internet Protocol Version 4 (ICP/IP), click Properties.
    2. The DNS line should be set to Obtain DNS server automatically. If it is not, set it yourself.
    3. Click on Advanced —> the DNS tab. Remove everything here (if there is something) —> OK.
    Right click on the browser’s shortcut —> Properties.

    Properties —–> Shortcut. In Target, remove everything after .exe.

    If using IE: Go to add ons and disable all. Then click on the gear symbol Internet Options —> change the URL to whatever you use (if hijacked) —> Apply.

    And to double check,
    Type Regedit in the windows search field and press Enter.

    Inside, press CTRL and F together and type the threat’s Name. Right click and delete any entries you find with a similar name. If they don’t show up this way, go manually to these directories and delete/uninstall them:

    • HKEY_CURRENT_USER—-Software—–Random Directory. It could be any one of them – ask us if you can’t discern which ones are malicious.
      HKEY_CURRENT_USER—-Software—Microsoft—-Windows—CurrentVersion—Run– Random
      HKEY_CURRENT_USER—-Software—Microsoft—Internet Explorer—-Main—- Random
    Let me know how that goes.
     
  21. Inkpat

    Inkpat Private E-2

    Tim, I ran all the suggestions you brought up in your last post, but could not find anything with the word "guce" in it. I did some extensive checking on the issue and determined that both AOL & YAHOO, under the ownership of Verizon, has made this malware a part of their respective systems as tracking software which they are able to sell data information to buyers.

    The internet search engines ( such as Google & Bing) is crammed full of users trying to get rid of it, and so far, there are no workarounds. Several malware suppliers are using this as a come-on to try their products, but they are unsuccessful in the removal. It would seem to me that what will happen, unless a "cure is found," is that I, and likely many, others will just stop using AOL and chose another mail system. Of course, I would be most interested to see if you could come up with a solution. I appreciate your devotion to this and time spent in my behalf.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So you found nothing under the properties in your browsers that included guce after the exe. extension? This is disturbing.



    https://secure.gravatar.com/avatar/65a03aeea84bc0a51b1b73c9c289a244?size=40&default=https%3A%2F%2Fassets.uvcdn.com%2Fpkg%2Fadmin%2Ficons%2Fuser_70-6bcf9e08938533adb9bac95c3e487cb2a6d4a32f890ca6fdc82e3072e0ea0368.pngADMINProduct Support (Product Support, AOL) responded · March 06, 2019


    We have a solution for you, please clear your browser history, cookies and cache here’s how: https://help.aol.com/articles/clear-cookies-cache-history-and-footprints-in-your-browser . If the issue persists, please disable the Ad-block and then try to log in.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Question....since Oath has partnered with them....can you scroll down to the bottom of the page and see a place to accept their new terms?

    https://help.aol.com/contact/
     
  24. Inkpat

    Inkpat Private E-2

    It appears that AOL is now aware of the problems they are creating and have this banner when you enter their customer service site across their web page.

    "AOL Mail is currently experiencing issues with specific web browsers. Google Chrome, Mozilla Firefox or Safari are not impacted and can be used until these issues are fixed.

    AOL Questions? Get 24x7 live expert help with all of your AOL needs—from email and passwords, technical questions, mobile email and more. Upgrade your account by calling 1-800-358-4860."

    I clear my browser as directed on a regular basis, and it has absolutely no effect.

    We have a Win 7 computer in the office and I notice that, though it does not have Edge, it still has Internet Explorer and it also shows the word "guce" when AOL is brought up and signed into as does Yahoo. No other site shows this characteristic, so I am convinced this is an internal AOL/Yahoo issue perpetrated by Verizon's Oath hierarchy in an effort to provide an intrusion into their customer's Internet site visiting habits.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    From what I read, it does seem they are being intrusive in order to give you targeted ads.

    Good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds