Yahoo/Spigot Hijaked My Computer - Help Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by WishIKnewMore, Mar 2, 2013.

  1. WishIKnewMore

    WishIKnewMore Private E-2

    Hello,

    After downloading IOBit Smart Defrag from Major Geeks this morning, Yahoo/Spigot hijacked Google Chrome. Went online to research how to remove it but it's still hijacking my search engine.

    How do I remove it and is MajorGeeks aware that this malware or virus or whatever the heck it is is being downloaded via their site?

    Thank you!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The below is quoted from the download page at Major Geeks and I highlighted the last sentence.;)
    All downloads at MajorGeeks are pretested. What you do have to realize is that many "Free" applications are sometimes only able to keep being free by have sponsor type toolbars. In many cases these can be opted out of during installation and that is exactly the case here. You were presented with the below which you could have declined ( double click to expand the thumbnail )
    SmartDefrag.jpg
    and then after declining, the installation of IoBit SmartDefrag would have continued. You accepted the installation of the software. So now you will have just uninstall it.
     
  3. WishIKnewMore

    WishIKnewMore Private E-2

    Thank you for the quick response.

    While I'll admit to being majorly distracted today with a remodel going on, I honestly don't remember accepting a yahoo toolbar. I loathe them.

    What concerns me the most is that all the normal channels for an uninstall aren't working. I've uninstalled everything that I thought was associated with it. Used Google Chrome settings to eliminate yahoo as an option. Selected Google as my search engine. Every time I think I have it resolved, it comes back and literally has hijacked my computer. A quick internet search reflects the same issue with many, many computer owners.

    I've received enormous help from MajorGeeks for many years for which I am enormously grateful. I've never posted a help request as I've always found the answers I needed already answered somewhere in your site. But this one is perplexing.

    MajorGeeks has such high integrity which is why so many visit your site. If I'm just being a bonehead and there's a simple fix, you can flag me as a bonehead. But this problem appears to be far more than a simple uninstall. I'm very surprised that MajorGeeks allows this to be downloaded.

    Since it appears to be more than a simple uninstall, what is your suggestion to remove this horrid thing from my system?

    Thank you
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated, the reason is multi-fold
    • It is not considered malware or any other form of infection
    • It is optional
    • And if Major Geeks and other download sites removed every FREE application that included toolbars like this to support their products, you would have about 85% of the free applications on the internet disappear. Even large companines with pay products ( i.e., Symantec and others ) are now including toolbars and similar to help with costs.
    Shutdown your protection software and run the below.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run MGtools per the below and attach the C:\MGlogs.zip file from MGtools.
     
  5. WishIKnewMore

    WishIKnewMore Private E-2

    Hello,

    Thank you again for your quick response.

    Ran the tools as you instructed. Uploaded files per your request.

    Computer is still hijacked.

    If this were the standard and easily removable yahoo toolbar, I'd have no problem. I would have removed it and we wouldn't have this conversation.
    You're correct. Whether or not I had a moment of inattention isn't the issue here. I was the person who chose to download this.
    However, the mere fact that I'm having to resort to these lengths to remove it is highly troubling. The mere fact that it remains is even more troubling.
    Whatever label one wishes to assign it, if it hijacks a computer, it hijacks a computer. That's never a good thing.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume that you mean your default search engine has been changed?

    Is it only Google Chrome that you have an issue with or are you also having an issue with Internet Explorer?

    I'm going to assume that you do not want Yahoo as a search engine an remove it from IE down below.

    I don't disagree with the fact that it may be causing you and possibly other people similar issues. However, in most cases a proper uninstall and then a reset of your search engine defaults will correct issues like this. Sometimes it is also necessary to check what Add-ons have been attached to your browser/browsers. You could need to either disable or delete an add-on. I think these are basically what is impacting you since there is not too much showing in your logs related to Yahoo/Spigot.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com?type=902615&fr=spigot-yhp-ie

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. WishIKnewMore

    WishIKnewMore Private E-2

    Received the following error message:

    Cannot import fixme.reg The specified file is not a registry script. You can only import binary registry files from within the registry editor.

    Before I posted the first time, ran CCCleaner. Deleted all add-ons and search engines other than google.
     
  8. WishIKnewMore

    WishIKnewMore Private E-2

    Your advice resolved the issue with IE but did not with google chrome. I deleted and reinstalled google chrome and everything appears to be back to normal.

    Would deleting Google Chrome also have deleted the spigot download? I'm concerned that it's malicious and doing other harmful things to my computer.

    Thanks for your help
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you likely did not follow the instructions properly. The REGEDIT4 line must be the first line in the file. Nothing should be above it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. It would only have remove the items that had hooked into Chrome.

    It's not malicious. It is just nuisance junkware.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. WishIKnewMore

    WishIKnewMore Private E-2

    FixMe.reg - I followed directions and copied and pasted exactly as you wrote. It appears that the * or " weren't to be included. People who know nothing about registry edits don't know that. After I deleted the extraneous, it edited successfully and I've attached the requested file.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fix was correct as given. If you changed it by deleting the quotes then it did not do what was required. Please try the original fix again and make sure that only what is in bold print and inside the quote box is put into the fixme.reg file. Also REGEDIT4 must be the first line.
     
  13. WishIKnewMore

    WishIKnewMore Private E-2

    I copied the registry edit from the email. Thanks for the clarification.
     

    Attached Files:

  14. WishIKnewMore

    WishIKnewMore Private E-2

    I appreciate all of your help.

    I have considered you and the other folks at MajorGeeks as the SuperHeroes of the Computer Universe.
    It's nice to have that feeling when a computer crashes or a virus hits - especially to those of us who know very little about it.

    Whatever the spigot junkware is labeled in the computer world, in the consumer world, it is a brand killer and trust destroyer. I understand that free software comes with certain concessions. Having to go to these lengths to eliminate this from my system is beyond what most consumers will consider tolerable.
    The result of this experience for myself and probably the others who've gone through this is that I'll never download anything from IOBit.
    What bothers me more is next time I come to MajorGeeks and want to download something, I'm now going to have this experience as a filter. Not quite the trust level that was present before.

    There's a better way to incorporate a yahoo toolbar. This is not it.

    Use the force wisely
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I can understand you view point.

    You have to remember that you are the one who did not read the popup information and that you agreed to install it when you just clicked continue without reading. You can easily bypass this being installed by declining it. It is no different than many hundreds of other applications. You did not object to all the addons that Adobe added to your PC. You don't need them either. Same applies to the Chrome and Apple startups/services that are not necessary.

    Even Sun Java will install Google Toolbar unless you decline it. Avira and many other antivirus programs ( including the PAID version of Symantec ) make you install Ask Toolbar with no choice not to install it.

    It is the way the free software and now even some commercial progams have gone to cut costs. If you don't like this then you will have to avoid using any free software from now on and pay for everything you use. In addition you still need to make sure you read before clicking as noted in the link I previously gave you to >> How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds