Articles

Solved what is ri.search.yahoo.com about?

March 4, 2014 at 02:50:05
Specs: Windows 7

Searching via Copernic Agent (RIP) or Google gives many results with "ri.search.yahoo.com" prefix and a string of mixed characters. Links don't work - URL not found, etc. Very recent occurrence and blighting searches.

See More: what is ri.search.yahoo.com about?

Report •


#1
March 4, 2014 at 03:18:00

Copernic Agent is not a search engine itself, it merely polls a whole variety of search engines so links it displays could be coming from anywhere - - even dead links.

You should use a proper search engine like Google or Yahoo to avoid the problem, and get rid of Copernic.


Report •

#2
March 4, 2014 at 03:52:39

Thanks - Copernic Agent is as you say - its attraction, to me, is that it adds a pretty decent management layer to search engine results. I shall miss it... I don't think the problem is one specifically related to Copernic or my choice of search engines, but I have noticed other reports of similar issues:
http://answers.yahoo.com/question/i...
http://answers.yahoo.com/question/i...
http://uk.answers.yahoo.com/questio...

Report •

#3
March 4, 2014 at 17:04:25
✔ Best Answer

Download ADWCleaner file from here (blue download button at top):
http://www.bleepingcomputer.com/dow...

Double click the saved file then run the Search. Best copy/paste the Report (log) on here, although it is usually safe to then run the Clean (there are options too).

Always pop back and let us know the outcome - thanks


Report •

Related Solutions

#4
March 5, 2014 at 02:52:01

Thanks Derek.Very kind of you to suggest ADW. I have done a little cleaning up, but significantly disabled Altavista and Fast Search in the Copernic search engine selection, which has stopped the ri.search entries.
This is the log from the ADW run:
# AdwCleaner v3.020 - Report created 05/03/2014 at 10:43:17
# Updated 27/02/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : A Acer - A ACER-PC
# Running from : C:\Users\A Acer\Downloads\AdwCleaner(1).exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found C:\Program Files (x86)\myfree codec
Folder Found C:\ProgramData\~0
Folder Found C:\ProgramData\boost_interprocess
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Folder Found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue
Folder Found C:\Users\A~1\AppData\Local\Temp\pccustubinstaller
Folder Found C:\Users\A Acer\AppData\Local\PackageAware

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Key Found : HKCU\Software\Myfree Codec
Key Found : [x64] HKCU\Software\APN PIP
Key Found : [x64] HKCU\Software\Myfree Codec
Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Found : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Key Found : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Key Found : HKLM\SOFTWARE\Classes\speedupmypc
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\Software\Driver-Soft
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Key Found : HKLM\Software\Myfree Codec
Key Found : HKLM\Software\PIP
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\A Acer\AppData\Roaming\Mozilla\Firefox\Profiles\ys8k0214.default-1381767339615\prefs.js ]


-\\ Google Chrome v33.0.1750.146

[ File : C:\Users\A Acer\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [4773 octets] - [05/03/2014 10:43:17]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [4893 octets] ##########


Report •

#5
March 5, 2014 at 11:53:29

I can't see anything on the log that you need retain and plenty that you would be better off without, so if you haven't done so already then run the Clean.

See if it makes any difference to your issue but in any event you don't want the dubious stuff. Mostly you get these from free downloads so watch for any pre-checked stuff. In some cases you get it even if you do avoid the stated goodies.

Always pop back and let us know the outcome - thanks


Report •

#6
March 6, 2014 at 05:29:53

Thanks Derek. I ran the ADWcleaner and deleted what was on the log. Laptop seems snappier so probably a healthy thing to do. Adding Altavistaback into the search engines in Copernic still results in the ri.search entries, but I shall live without Altavista search and, at some point, ditch Copernic and solely rely on Google as Phil22 suggests. Many thanks for the assistance guys. :)

Report •

#7
March 7, 2014 at 09:46:01

Glad to hear things are better. However the ADWCleaner showed a lot of things so if you want to be sure that there is nothing still lurking it would be best to run a few more programs on it - they all find different things.

If you want to go ahead download Junkware Removal Tool from here (blue button near top):
http://www.bleepingcomputer.com/dow...

It is the same procedure as ADWCleaner, you save the file somewhere you can find it (desktop will do) then double click the saved file to run the program. Press a key when requested in the black box and OK any permission box that arrives. Wait until the log appears on the desktop. Copy/Paste the log on here please.

Always pop back and let us know the outcome - thanks


Report •

#8
March 10, 2014 at 09:45:57

Thanks, Derek. Have downloaded and run the JRT, too, but inadvertently closed the dialogue box without copying - apologies. Results of second run, below. I shall check out their other products. Thanks again for your advice.

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Home Premium x64
Ran by A Acer on 10/03/2014 at 16:14:30.75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"

~~~ FireFox

Emptied folder: C:\Users\A Acer\AppData\Roaming\mozilla\firefox\profiles\ys8k0214.default-1381767339615\minidumps [14 files]



Report •

#9
March 10, 2014 at 13:24:48

Are you using any auto online backup service - in particular one called "Cloudfogger"?

Could you install and run MalwareBytes please and paste that log on here too:
http://www.filehippo.com/download_m...
(use green icon top right of page)

EDIT: Typo (Cloudfogger)

Always pop back and let us know the outcome - thanks

message edited by Derek


Report •

#10
March 10, 2014 at 15:05:49

"Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
If you are using a Dell comp, put the Dell Digital Delivery service to manual
http://www.dell.com/content/topics/...

Report •

#11
March 10, 2014 at 15:43:40

Thanks John - it's an Acer, not Dell. but I'll take a closer look at the use of boost_interprocess.

Report •

#12
March 10, 2014 at 16:11:07

"it's an Acer"
Ok, looks like they use the same.

Report •

#13
March 10, 2014 at 16:28:26

I see now why Derek mentioned Cloudfogger, my googling picked that up as well, they also use boost_interprocess.

When you run Malwarebytes, it should not show it, they have ID it as a false positive.
https://forums.malwarebytes.org/ind...


Report •

#14
March 10, 2014 at 16:38:28

I have a feeling boost_interprocess is not a problem but let's see what MWB finds.

Always pop back and let us know the outcome - thanks


Report •

#15
March 11, 2014 at 01:34:59

Thanks Derek. Ran Malwarebytes:
A Acer :: AACER-PC [administrator]

Protection: Enabled

10/03/2014 22:47:17
mbam-log-2014-03-10 (22-47-17).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 310248
Time elapsed: 43 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\A Acer\Downloads\produkey_setup.exe (PUP.PSWTool.ProductKey) -> Quarantined and deleted successfully.

(end)

Backup is to a hard drive. Also use Pogoplug for offline storage. Will look at Cloudfogger, but it's not in use.
(Just seen the above discussion re Cloudfogger and boost_interprocess... tks, both.)

message edited by Toots48


Report •

#16
March 11, 2014 at 03:47:23

RunTFC
http://www.geekstogo.com/forum/file...
http://www.bleepingcomputer.com/dow...
http://oldtimer.geekstogo.com/TFC.exe
http://www.itxassociates.com/OT-Too...
Please double-click TFC.exe to run it. Note: If you are running on Vista/Windows 7/8, right-click on the file and choose Run As Administrator).
It will close all programs when run, so make sure you have saved all your work before you begin.
Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

Report •


Ask Question