Hao123.com homepage problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by chi0127, Nov 5, 2014.

  1. chi0127

    chi0127 Private E-2

    To administrators of the MajorGeek forum,

    Hello sorry for the intrusion but I am currently having a problem with internet explorer and firefox setting hao123.com as my default homepage. I checked the settings for both firefox and IE and it both states that my default homepage should be a blank page. I tried uninstalling unwanted programs that could have relations to this site, and I have also tried methods suggested in previous threads. I believe that this problem is due to some sort of malware on my computer that I cannot detect.

    I have completed the basic procedure suggested for all users. I have attached the logs below. Thank you for your time and effort. I appreciate suggestions of any kind.

    Sincerely
    Loyal member of Majorgeeks.com, Chi.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. I am reviewing your logs and will get back to you with a fix asap. :)
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    • [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-2614250091-1579001393-1646641011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 
    • [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-2614250091-1579001393-1646641011-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Re run Hitman Pro and have it remove what it sees.


    Now explain how things are running.
     
  4. chi0127

    chi0127 Private E-2

    i followed your instruction and everything ran smoothly without error. however the problem of hao123.com being my default page when i open my browsers still persist. the log from roguekiller is attached below. It was not able to delete the x86 file.
     

    Attached Files:

  5. chi0127

    chi0127 Private E-2

    i re-installed firefox and IE and it seems to have fixed the problem for firefox only. The problem still persist for IE.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click on the OTL icon on your desktopto run it. (Note: if using Vista, Win7 or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds