Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Yahoo Spigot?


  • Please log in to reply
5 replies to this topic

#1 Darkspeed76

Darkspeed76

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:38 AM

Posted 01 December 2012 - 05:21 PM

Hello. Recently I downloaded a program called YoutubeDownloader. Since then, my home page has changed to "http://search.yahoo.com/?type=937811&fr=spigot-yhp-ch". I tried to change it in the Google Chrome settings but nothing works. I ran MalwareBytes Anti Malware, and found nothing. Please respond soon.

BC AdBot (Login to Remove)

 


#2 noknojon

noknojon

    Retired


  • Members
  • 9,463 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Victoria Australia
  • Local time:01:38 AM

Posted 02 December 2012 - 02:09 AM

Hello
Is this the site you downloaded from >> http://www.leawo.com/ . The site is ranked as "suspect" by WOT

Find anything related to http://www.leawo.com/ << or >> Leawo Free YouTube Downloader in Add / Remove and delete it.
Also open Accessories > Windows Explorer > My Computer > Program files and see if the program is listed > Right click > Delete -

Also please download AdwCleaner by Xplode onto your desktop.
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Delete.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

This will clear many of your Add-ons and Toolbars

Thank You -
EXTRA - Download and use WOT for site rankings to check if sites are safe -

Edited by noknojon, 02 December 2012 - 02:14 AM.


#3 Darkspeed76

Darkspeed76
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:38 AM

Posted 02 December 2012 - 10:29 PM

No, it was not the Leawo Free YouTube Downloader. The exact name was YTD Video Downloader. I downloaded and ran AdwCleaner and it fixed my problem by getting rid of the spigot that made my home page "http://search.yahoo.com/?type=937811&fr=spigot-yhp-ch" Now I go to my old home page! Thank you. But here's the log if you want it anyways. The one called "AdwCleaner[S1].txt
======================================================================================================================================================================================================================================

# AdwCleaner v2.011 - Logfile created 12/02/2012 at 22:18:28
# Updated 02/12/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Page - STUDIO_1
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Page\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\DOCUME~1\Page\LOCALS~1\Temp\Uninstall.exe
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\user.js
File Deleted : C:\WINDOWS\Tasks\Browser Manager.job
File Deleted : C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
Folder Deleted : C:\DOCUME~1\Page\LOCALS~1\Temp\avg@toolbar
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Browser Manager
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Folder Deleted : C:\Documents and Settings\Page\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\Page\Local Settings\Application Data\AskToolbar
Folder Deleted : C:\Program Files\Application Updater
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\Common Files\spigot
Folder Deleted : C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AskToolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\Tarma Installer
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Google Chrome v23.0.1271.95

File : C:\Documents and Settings\Page\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [3966 octets] - [02/12/2012 22:18:28]

########## EOF - C:\AdwCleaner[S1].txt - [4026 octets] ##########

======================================================================================================================================================================================================================================
Again, thank you. My problem is solved.

#4 hamluis

hamluis

    Moderator


  • Moderator
  • 42,067 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:10:38 AM

Posted 03 December 2012 - 07:19 AM

Is this the program?

http://www.youtubedownloaderhd.com/

Some downloaders don't work as advertised, due to changes made since original development.

Looking at your title...I don't see any connection between it and your situation.

Louis

#5 Rick Vidallon

Rick Vidallon

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia Beach
  • Local time:10:38 AM

Posted 15 December 2012 - 11:53 AM

Had the same problem with the Yahoo Spigot browser attaching itself and opening a second window in Chrome and IE.

Below I have listed what I did to solve the problem in 3 configurations
Regular boot
Safe boot
Safe boot w/ networking.

1)Tried to uninstall
2) Ran Anti Virus Spyware
3) Restore point in WIN 7
4) Reg Cleaner Pro
5) Clean Fix

All failed.

This morning I tried AdwCleaner in regular boot mode with anti-virus and spyware disabled.

SUCCESS!
No more friggin, scum-sucking Yahoo window.
The URL was still listed as a choice in Chrome and Explorer. All I had to do was manually change the preference setting under browser options.

Keeping my fingers crossed that it is gone for good.
Otherwise I think I see an OS reinstall in my near future.

#6 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 33,147 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:11:38 AM

Posted 15 December 2012 - 01:41 PM

Spigot is bundled with a number of toolbars and applications and has a variety of names. It is adware. For an example of one of the files installed see: http://www.bleepingcomputer.com/startups/SearchSettings-26217.html

Orange Blossom :cherry:

Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SuperAntiSpyware, SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users