Hao123 removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by JustSymphony, Oct 23, 2013.

  1. JustSymphony

    JustSymphony Private E-2

    Hi admins of Major Geeks,

    I am a new member of this forum so please do pardon me for any mistakes that I made and correct me if i am doing anything wrong.

    Ok the problem lies with the browser that i am using which is google chrome, the startup page will always be this --> hao123.com/?tn=29065018_59_hao_pg . I have tried uninstalling and even resetting the settings in google chrome but it still appears. So i did those scans and have those logs attached on this post.

    Please do give me advices after taking a look at my logs.

    Thank you very much for your time.
     

    Attached Files:

    Last edited by a moderator: Oct 24, 2013
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1ClickDownloader <--- uninstall this.


    Delete this:
    C:\Windows\tasks\AutoKMS.job


    Re run Hitman and have it delete all Malware remnants & Potential Unwanted Programs.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. JustSymphony

    JustSymphony Private E-2

    I thank you for your response Kestrel13.

    Ok i have done all the instructions that you have said.

    Firstly i could not find 1clickdownloader after searching for it so i assume i must have uninstalled it long ago.

    All Malware remnants & Potential Unwanted Programs have been removed and a reboot was done.

    As for the fixMe.reg, it shows a successful message indicating that it have edited my registry side.

    So what do i do next?

    Hope to hear from you soon!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes.

    Ready for final steps? :)
     
  5. JustSymphony

    JustSymphony Private E-2

    Yes i am, just shoot the steps even if it's a long list :)

    Appreciate your help so much!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  7. JustSymphony

    JustSymphony Private E-2

    Ok as for the final steps it's to clear up those installed stuffs and set back the settings.

    But even after i did the steps you mentioned, the hao123 startup page is still there for the google chrome.

    Is there any ways around it?

    Thank you for your help!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh I apologise. I presumed wrongly that had been corrected. I'm afraid the best thing to do is to uninstall Google Chrome with Revo Uninstaller. Then reinstall from fresh. Let me know how it goes.
     
  9. JustSymphony

    JustSymphony Private E-2

    Ok i did tried uninstalling with and without that revouninstall but to no avail. A reboot was done but still the hao123 startup page was there at the second time, but when i installed it fresh and it open up the first time, the hao123 was not there.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download OTL by OldTimer.
     
  11. JustSymphony

    JustSymphony Private E-2

    Ok i have done the OTL scan as mentioned by you. Here is the attachment txt file of it :) .
     

    Attached Files:

    • OTL.Txt
      File size:
      286.9 KB
      Views:
      1
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  13. JustSymphony

    JustSymphony Private E-2

    Ok as for now i didn't uninstall qvod and the problems seems to be gone :).

    i monitored for 2-3 days and the problem didn't arise back so i assume it must have been cleared out.

    Thanks alot for your help and your patience Kestrel13!

    Love you and MajorGeeks supports!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So QVOD did not show up in Revo as being uninstalled? (There are remnants of it in your logs I'm sure)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds