Another hao123 cry for help

Discussion in 'Malware Help (A Specialist Will Reply)' started by pwiry, Aug 23, 2013.

  1. pwiry

    pwiry Private E-2

    Hi helpful geeks,

    I have problems with removing hao123 from my IE9. I never use IE, so I have no idea when I got it/where I got it from. I only noticed this problem today when trying to rearrange my desktop icons.

    I ran the READ & RUN ME FIRST steps, to no avail. I've read through other threads on this topic, but just in case, I'm posting my own. I believe RogueKiller found multiple issues that I did not fix (because the instructions told me not to). I've attached the 5 logs from my initial attempt. Please help!

    Pwiry

    P.S. Not sure if relevant/important, but I recently ran a registry cleanup on CCleaner (already had it on my computer). I noticed that the instructions strictly noted not to run a registry clean, so sorry if that changes anything. :hammer
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. pwiry

    pwiry Private E-2

    Problem still exists. Here's the log.
     

    Attached Files:

    • JRT.txt
      File size:
      21.3 KB
      Views:
      3
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you update to IE10 and let me know if this still occurs?
     
  5. pwiry

    pwiry Private E-2

    I updated IE via windows update, and after restarting my IE won't open at all. When I click on IE on my desktop I see my cursor turn for maybe 2 seconds, then it turns back to the normal arrow, and nothing else happens. Attempting to start IE from start menu also does nothing, even if I choose to start with no add-ons.

    I can tell the hao123 is still affecting IE when I right-click on the icon. The only options I get are "My home page" "delete" "paste" in chinese, and "cut" "create shortcut" in english.
    my home page -> hao123 (now nothing, IE won't open)
    delete -> internet options (still pops up)
    paste -> internet options
    cut -> nothing
    create shortcut -> I'd rather not.

    edit: Also, I had a problem with Security Update KB2835361, not sure why. Error code according to microsoft only means 'incomplete installation', nothing specific.
     
  6. pwiry

    pwiry Private E-2

    Patched again after restarting, the update worked this time. IE is in same condition as last post.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Follow these instructions and let me know how you get on. I realise it isn't installed, or doesn't show as being anyway. Just go through what you can of that. Let me know if it makes a difference.
     
  8. pwiry

    pwiry Private E-2

    That was the first thing I tried even before coming on this forum, because it's so straightfoward. Unfortunately, nothing worked. And no matter how I change IE's settings, it'll change it back as soon as the settings window is closed. (Of course, now I can't even open IE. Not sure which is better.)

    I read in another thread here that the person asking for help found a chinese program that was responsible for the hao123 business. I've already gone through and deleted what I could before posting this thread as well. :(

    Granted I never use IE, this really isn't something that's getting in my way, and I'm not sure if I'd want to reset my entire computer for this. But I really don't like the implications that I might have other unknown things on my computer, etc etc. If it seems to be purely adware, and on a program I'm not even using, what do you think would be the best approach?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Exactly, I agree wholeheartedly, I wouldn't want it lingering either despite the fact you don't use IE.

    Please download Combofix to your desktop. Please refer to these instructions prior to running.
     
  10. pwiry

    pwiry Private E-2

    Hi there! Log is attached. Combofix somehow decided to install itself in Chinese, so sorry if you have any trouble reading it. After running combofix, my IE icon now looks like a blank page, like this, and has no name under it. Double clicking does nothing, and right clicking now shows "cut" "create shortcut" and "delete" in English.

    So I guess that's some sort of improvement? If i click on delete, I get a notification that says: "Are you sure you want to delete these icons from your desktop? To restore it later, go to Control Panel." I can't tell if this is a broken piece of IE, or what, but it seems like my computer now thinks it's IE (and delete no longer takes me to internet options).

    What should my next step be? Should I try to reinstall/fix IE somehow to check if hao123 is actually gone, or leave it as is?
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  12. pwiry

    pwiry Private E-2

    First I deleted everything, and it didn't really make a difference. The icon was still inactive. However, I searched for IE from start menu, and went straight to internet options without trying to open IE first (I probably should have tried, just to see..), and reset IE. IE opened just fine from the start menu, yay!!

    The icon still did nothing, so I deleted it from my desktop. It's easy enough to make a IE shortcut to the desktop so that's not a problem at all.

    YAY! Thank you very much for all your help! :drool I'm glad that's finally been taken care of. Is there a thread you can link me to for safely uninstalling all the programs I put onto my computer? Or can I just delete most of them directly?

    Thanks again!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. pwiry

    pwiry Private E-2

    Awesome! Thank thank and thank you so much for your help and your time! :heart
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome! safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds