AQUB search page after windows start up

Discussion in 'Malware Help (A Specialist Will Reply)' started by goobz, Sep 1, 2012.

  1. goobz

    goobz Private E-2

    Hi - Hoping someone can help me with this issue, every time windows starts up IE loads this page called "AQUB search"! if I close it and reopen a new browser window my normal homepage loads but obviously I want too get rid of the AQUB page!
    I have attached the RogueKiller log because there were detections, the other apps didn't find anything but can upload the reports for these if requested!

    One other thing is after running the scans in the guide I now have 2 desktop.ini ghost files on my desktop everytime my windows starts up, looks like the "show hidden files and folders" option in explorer keeps on turning on when windows starts up
    Thanks for any help in advance!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes!!!!! You need to attach logs from running all the other programs in these instructions. Thanks :) READ & RUN ME FIRST. Malware Removal Guide
     
  3. goobz

    goobz Private E-2

    Thanks Kestrel - I relized that I had forgot to turn on the "show hidden files and folders" when performing last nights scans so I ran all 5 again today and have attached all 5 of the reports to this reply so you might want to disregard the Roguekiller log from my previous post !
    Thanks again:)
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. goobz

    goobz Private E-2

    Thanks Kestrel - here you go, logs attached
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The desktop.ini files you mentioned are fine. Now how is IE, are you still having problems?
     
  7. goobz

    goobz Private E-2

    Hi Kestrel - The AQUB search page is still showing up after windows boots up:(, apart from that my IE is working fine, the only thing I did with the OTL was run a scan like you told me to, I didn't fix any of the detections just like RogueKiller when it found detections but the Malware guide here says not to fix anything just to save the log.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, the OTL does not show anything, you see. I just wondered if you were still affected or not.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :regfind
      AQUB
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  9. goobz

    goobz Private E-2

    Hi Kestrel - Here is my SystemLook log, looks like quite a lot of hits! a lot from my searches on how to get rid of it!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. goobz

    goobz Private E-2

    Wow! ESET had found 9 viruses and spyware that my Avira missed! unfortunatly the AQUB search page still loads when IE starts up:(
    I think I read something in the section for hijacked browser homepages about the possibility the maleware/virus could be hiding in a router?

    Thanks again for your help, ESET log attached.
     

    Attached Files:

    • log.txt
      File size:
      3.3 KB
      Views:
      4
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below:

    • BitTorrentBar Toolbar
    • conduitEngine
    • Registry Mechanic_is1
    • SpywareGuard_is1

    Now let's flush the Java Cache

    • Click Start > Settings > Control Panel
    • Double click the Java icon (be patient, it may take a while to open)
    • Now click the General tab and under the Temporary Internet File area
    • Click the Settings button and then click the Delete Files... button.
    • In the next popup click OK.
    If you have multiple Java plugin icons in Control Panel follow the above to clear all their caches.


    Now let's flush the FireFox Cache
    To flush your FireFox Cache:

    • click Tools
    • select Options
    • select Privacy
    • Clear your recent history

    Now let's flush the Internet Explorer Cache
    To flush your Internet Explorer Cache:

    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.

    Any difference?
    And is this ONLY affecting IE??
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Goobz there's something else you can try. Click start and type in regedit click on regedit.exe which will open up you registry.

    Click on Edit > Find > (make sure keys value and data are check marked)
    Search for aqub and AQUB seperately and let me know whether anything is found or not.
     
  14. goobz

    goobz Private E-2

    Hi Kestrel - followed all instructions from your last reply but AQUB is still there, today Avira did detect an infection on my D drive called something like " aqb redirect" which after deleting I thought I had finally got rid of it but it wasn't to be.

    I tried the regedit find when I first got the virus and didn't find anything, I also did it again today after reading your instructions and it highlighted a registry entry for itunes, but after looking at the code, I didn't find the AQUB word in there!.

    Just a few things I noticed that might help you:

    1. When I boot up in safemode with networking it's fine! IE opens on my homepage and there is no sign of the AQUB page

    2. I dont have another browser, I just use IE

    3. the address in the IE url is : http://aqub.co.uk and it looks like the google home page
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is your home page set as in IE? Check for me.
     
  16. goobz

    goobz Private E-2

    espnsoccernet.com used to be bbc.co.uk, the first thing I did was to see if the spyware/virus changed my homepage settings in IE but it didn't!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Damn frustrating.

    Let's try this! :)
    How to reset Internet Explorer settings

    You can either do it manually or have it done for you automatically.
    Let me know how you make out. I must go to bed now and will not get back online until tomorrow evening.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a case of hijacking. It is more likely due to what you installed on your PC. My first guess is that it is from Faceb662 version 1.5

    IE does not normally run at startup, but you have allowed the below to be put in your startup processes and this may be why IE is opening.

    O4 - Startup: C:\Users\gloopz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Faceb662.url ()


    Before fixing this, you need to uninstall the extremely old and outdated SpywareGuard if it is still installed. You have better protection already within your antivirus program. Then disabled all protection ( including your AV, and IoBit Malware Fighter ) and then do the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - Startup: Faceb662.url

    After clicking Fix, exit HJT.

    Then reboot your PC and see if IE still opens at startup.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\MGlogs.zip
     
  19. goobz

    goobz Private E-2

    GOT IT! finally rid my PC of the aqub page! thanks guys, yup Chaslang the fixed/deletion of "faceb662" from start up did the trick! got rid of a bunch of spyware and viruses to thanks to the ESET scan :-D:major

    here's the Mglogs
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thankyou Chaslang!! I looked at that a couple of times and wrote it off as being the cause!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You may want to consider uninstalling the root cause. You do have Faceb662 version 1.5 installed.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds