Redirected to yahabags when searching with Google

Discussion in 'Malware Help (A Specialist Will Reply)' started by Reed, Mar 26, 2007.

  1. Reed

    Reed Private E-2

    On my computer, everytime I click a link on explorer (typically from Google) it is redirected to another site through yahabags.com. Furthermore, I have followed the READ & RUN ME FIRST Malware Removal Guide. What's next?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Next its to attach the logs requested in the read me as in the ones below.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Reed

    Reed Private E-2

    Here are the logs, Counterspy would not run in Safemode so I ran AVG Anti-Spyware. We have 4 user accts I ran Ccleaner & SpyBot in safemode for all plus Admin. All of these logs were run in Safemode. I have done this procedure twice, the 1st time I was still redirected to yahabags. After the 2nd time I have not been redirected yet. It's only been 15 minutes.
     

    Attached Files:

    Last edited: Mar 27, 2007
  4. Reed

    Reed Private E-2

    Other 3 logs.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Distributed Process Services
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteMSDPSV into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {1FFB1A32-1D58-46CF-BE8B-237586AF7F2F} - (no file)
    O2 - BHO: (no name) - {45300C76-DED3-4C37-B8A1-B31F2014D7Bd} - C:\WINDOWS\system32\niatmnpc.dll (file missing)
    O2 - BHO: (no name) - {66054621-5126-4ED2-B567-E245FE42EB54} - C:\WINDOWS\system32\niatmnpc.dll (file missing)
    O2 - BHO: (no name) - {95EFA619-C8CE-4FDE-A994-047A67AFD799} - (no file)
    O2 - BHO: (no name) - {97A0C8A3-1065-431A-9B4E-E56567C5506e} - C:\WINDOWS\system32\niatmnpc.dll (file missing)
    O2 - BHO: (no name) - {DC772431-7BE7-4EB0-9019-8A91216F99A4} - C:\WINDOWS\system32\niatmnpc.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\niatmnpc.dll
    C:\WINDOWS\system32\msdpsv.exe
    C:\WINDOWS\system32\ttstv.bak1
    C:\WINDOWS\system32\ttstv.bak2
    C:\WINDOWS\system32\denavuyh.ini
    C:\WINDOWS\system32\ttstv.ini
    C:\WINDOWS\system32\wduqpxyp.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  6. Reed

    Reed Private E-2

    Completed all your suggested steps. I have been doing all these steps from our main account that is the only Administrator. First step Distributed Process Services under Properties service was already stopped.

    Further down to running Pocket Killbox step, Counter Spy tried to install but failed. I canceled out of the failed attempts and continued with running Killbox, everything else went fine.

    I have gone into all 5 user accounts and searches are working smoothly.

    The only other item that is different is when opening 1 of the user accounts c:\windows\system32 window is open. This does not happen on any other accounts.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is frequently not due to malware. Quite often it is just due to improperly terminated (or null terminated) registry key that is access at boot up. Let's finish your cleanup and then take a quick look at this later, but if I don't see anything obvious I will be sending you to the Software Forum for this.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Counterspy

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot in normal mode

    Now locate the below folder and delete it if found:
    C:\Program Files\Video ActiveX Object

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew


    Make sure you tell me how things are working now!

    Now reboot your PC and logon to the account that has the c:\windows\system32 folder open at startup. Get me two logs while logged into this account and attach them to a second message separate from the above logs:
    • GetRunKey
    • ShowNew
     
  8. Reed

    Reed Private E-2

    Uninstalled the Sunbelt CounterSpy trial and deleted the C:\Documents and Settings\All Users\Application Data\Sunbelt Software this was the only folder that existed.

    fixME.reg went fine.

    C:\Program Files\Video ActiveX Object did not exist.

    and ran Ccleaner

    Internet searches in all user accounts are working great.
     

    Attached Files:

  9. Reed

    Reed Private E-2

    Here are the logs for the account that has the c:\windows\system32 folder open at startup.

    This happened when I rebooted and logged into this account, 1st time I have seen this.

    McAfee Detected Registry Change opened with the below message. I blocked it.
    C:\Program Files\QuickTime\qttask.exe
    Process Publisher: Apple Computer, Inc.
    Affected Items: C:\Program Files\QuickTime\qttask.exe, HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QuickTime Task

    Not sure if this is significant.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs from the first account are clean now!

    This could be related to the fact that I was having you deleted this registry key in a previous procedure. Not allowing the change would cause it to come back. You should fix this key in all user accounts. It is an unnecessary startup that is a waste of system resources.

    I see no apparent issues in those logs that could be the cause of the system32 folder opening. You will have to work this in the Software Forum since it is not a malware related problem. You could try giving the following a run to see if it helps: MSConfig Cleanup


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. Reed

    Reed Private E-2

    Thank you for all your help Chaslang, this is the best place on the web to receive advice and help.

    Evreything is working great!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds