Remove Hao123 as homepage

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by richelle, Jul 26, 2014.

  1. richelle

    richelle Private E-2

    Hi,

    When I launch my IE/Firefox, it keeps showing hao123 as homepage even thought my default homepage is set as google. I've attached the logs for your reference. Appreciate your help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode.

    Uninstall the below:

    • savenshare
    • SearchNewTab


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. richelle

    richelle Private E-2

    Hi,

    I have put it back to restart at normal mode.
    But I can't seem to uninstall "savenshare" and "SearchNewTab". When i click uninstall there seems to be no respond. So do i still go ahead to proceed to your next instruction?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. richelle

    richelle Private E-2

    I chose "moderate" uninstall mode and I didn't remove any registry. After I completed, I still see the program in my uninstall program list. Did I missed anything? Do I need to remove the registry recommended in bold by Revo Uninstaller? Or should I choose a different uninstall mode?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nah don't bother. Let's do this instead and see what happens.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Are they still listed now?
     
  7. richelle

    richelle Private E-2

    yes, it's successfully merged! and it's not listed in the program list anymore.
    so now i can continue with the next step?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please ;)
     
  9. richelle

    richelle Private E-2

    I've attached the files. It's still showing the hao123 page when i open my IE/firefox browser :(
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you recognize all these? :confused

    • O4 - HKLM\..\Run: [????] C:\Program Files\xigua\xgyingshi.exe
    • O4 - HKLM\..\Run: [wjplay_News] "C:\Program Files\wjplay\WJia.exe" -mini
    • O4 - HKLM\..\Run: [wjplay] "C:\Program Files\wjplay\wjplay.exe" -mini
    • O4 - HKLM\..\Run: [kxesc] "c:\program files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun

    I see this listed as installed >>> Norton Internet Security as well as MSSE. Is Norton Internet Security running just a firewall, or firewall and antivirus?
     
  11. richelle

    richelle Private E-2

    Hrm... i only recognise this O4 - HKLM\..\Run: [????] C:\Program Files\xigua\xgyingshi.exe, it's a player to download movies...the rest i don't think it's of use anymore.

    Norton should be just firewall... though I'm not exactly sure... sorry, i'm kinda bad at these :cry
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I have to step out for a little while. I'll be back online later. In the mean time run the below for me please:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.


    Please also download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  13. richelle

    richelle Private E-2

    Here's the log files!
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Tell me, do you access IE and Firefox via a shortcut on your desktop/start menu? If so right click each and choose PROPERTIES > on the SHORTCUT tab, check the target. Is Hao123 mentioned anywhere in the path on any of these shortcuts?

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O4 - HKLM\..\Run: [wjplay_News] "C:\Program Files\wjplay\WJia.exe" -mini
    • O4 - HKLM\..\Run: [wjplay] "C:\Program Files\wjplay\wjplay.exe" -mini
    • O4 - HKLM\..\Run: [kxesc] "c:\program files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun
    • O18 - Protocol: KuGoo - (no CLSID) - (no file)
    • O18 - Protocol: KuGoo3 - (no CLSID) - (no file)
    After clicking Fix exit HJT.





    We need to run an OTL Fix

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    
    :files
    C:\Program Files\wjplay
    c:\program files\kingsoft
    C:\Users\Richelle\AppData\Roaming\AVG2012
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    You should try resetting your browsers: (And let us know if it makes any difference)

    Reset Internet Explorer 9, 10, and 11 to Defaults
    Reset Google Chrome to defaults
    Reset Mozilla Firefox to defaults


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  15. richelle

    richelle Private E-2

    Is Hao123 mentioned anywhere in the path on any of these shortcuts?
    --> Nope

    I've reset both firefox & IE, but still having the same problem.
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to re run Adwcleaner and have it remove what it finds please.


    I also advise you to check more into the Norton Internet Security. It's running antivirus but so is Microsoft Security Essentials! Two should not be run at the same time so let me know when the Norton expires.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: WandoujiaBHO - {000DA090-57AA-424B-A8F0-621B7C08B8F4} - C:\Program Files\WandouLabs\wandoujia_bho.dll (file missing)
    • O2 - BHO: BrowserHelper - {4BF2CB0E-658A-442B-AC83-A64EC2150BFC} - C:\ProgramData\PPBrowserHelper\BHO\TipsBHO.dll
    • O18 - Protocol: KuGoo - (no CLSID) - (no file)
    • O18 - Protocol: KuGoo3 - (no CLSID) - (no file)
    After clicking Fix exit HJT.



    Now download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" Anything showing in the "KEEP" section leave alone except for funacce.dll, we want to be rid of that.

    Then, Select the >> button to move funacce.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    =================

    • Right-click OTL.exe to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :files
    C:\Users\Richelle\AppData\Roaming\Kingsoft
    C:\Users\Richelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\6925~1  
    C:\Program Files\WandouLabs
    C:\ProgramData\PPBrowserHelper
    C:\Users\Richelle\AppData\Roaming\Baidu
    C:\baidu download
    C:\baidu player
    C:\Users\Richelle\funshion
    
    :reg
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}]
    
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Any better?
     
    Last edited: Jul 30, 2014
  17. richelle

    richelle Private E-2

    Not sure why I've got the norton internet security but it should have expired. Anyway, I downloaded the Norton Removal Tool, so i guess it should be removed now?

    still having same problem now :cry
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download Combofix to your desktop. Please refer to these instructions prior to running.

    Attach the log once complete.
     
  19. richelle

    richelle Private E-2

    No idea why, but seems like when i on my laptop today the browsers seems fine already... so do i still need to do the ComboFix?
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh that *is* a suprise! Well, I think you should surf around for a day or so and then report back to me.
     
  21. richelle

    richelle Private E-2

    yeap...seems fine now... thanks so much for your help! :)
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's awesome. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds