Sites popping up and different things

Discussion in 'Malware Help (A Specialist Will Reply)' started by DarkWolfXV, May 29, 2013.

  1. DarkWolfXV

    DarkWolfXV Private E-2

    I have a problem with V9 portal site (and qvo6-something) popping up each time i open my browser, i did everything specified in read me and malware removed thread and i seek advice. Logs are in attachment(s). Hitman also detected trojan or something but i followed advice to not delete it at the moment. Please help.
     

    Attached Files:

  2. DarkWolfXV

    DarkWolfXV Private E-2

    Here is the sixth attachment
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&u...EX-22RKKA0_WD-WCC1S034539045390&ts=1368973015
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&u...EX-22RKKA0_WD-WCC1S034539045390&ts=1368973015
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&u...EX-22RKKA0_WD-WCC1S034539045390&ts=1368973015
    O4 - HKLM\..\Run: [RegistryQuick.exe] C:\Program Files (x86)\ReQuick\RegistryQuick.exe

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Users\Maciej\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe
    C:\Users\Maciej\AppData\Roaming\DealPly
    C:\Users\Maciej\Downloads\RegistryQuick_install.exe
    C:\Program Files (x86)\ReQuick
    C:\Windows\TEMP\*.*
    C:\Users\Maciej\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "RegistryQuick.exe"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{8DC34340-BDA2-4105-B823-E4142423A6CC}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{8DC34340-BDA2-4105-B823-E4142423A6CC}"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. DarkWolfXV

    DarkWolfXV Private E-2

    So i did everything you told me to and apparently qvo6 is gone but V9 is still there. I couldn't attach MGLogs.zip because site says i already did so, but here are two other files.
     

    Attached Files:

  5. DarkWolfXV

    DarkWolfXV Private E-2

    Oh silly me, i forgot to run GetLogs.bat.
    Here is the third file
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you mean in Chrome. Just reset your home page to what you want.

    If that does not resolve the issues with Chrome you will have to uninstall Chrome and then reinstall.
     
  7. DarkWolfXV

    DarkWolfXV Private E-2

    I did it and everything works nicely. Thank you. So i should follow rest of the procedure now, right? Also im seeing desktop.ini files and various other system files, will that be fixed by finishing the procedure?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. DarkWolfXV

    DarkWolfXV Private E-2

    So i did everything and it worked, but then i turned on Internet Explorer and it still has i the problem (V9 being the homepage, and setting it to google doesn't work, ran a scan with Windows Defender [win 8 version] and there is nothing detected, Google Chrome is fine though), and i can't really uninstall Internet Explorer which could possibly help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    YOur last logs did not show this. They showed the below settings
    Have you tried a simple Reset of Internet Explorer settings? Click Tools, Internet Options and select the Advanced tab. See the Reset button. Make sure all protection is off before trying to change your settings. Protection could even be blocking your simple home page change.

    If that does not seem to work, try the below:

    1 - Open IE Explore
    2 – Click “Tools->Internet Options”, Open “Internet Options” panel
    3 – Click “General” tab
    4 – Delete V9 homepage link and set a new homepage link
    5 – Click “Settings” button in the “Search” area, open “Manage Add-ons” panel
    6 – Remove V9, then close “Manage Add-ons” panel
    7 – Click “Apply” or “OK” on “Internet Opens” panel to save the changes
     
  11. DarkWolfXV

    DarkWolfXV Private E-2

    V9 is not listed there in manage add-ons, the qvo6 thing was listed and is gone now (deleted it), but V9 is not, i guess its not a big problem since i dont use IE often, but i'd like it to be fixed.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So in IE, v9 is only showing as the home page???

    And you cannot change it? Is it grayed out?

    Is all protection ( including UA ) disabled when you try to change it? Protection programs can block changes like this.
     
  13. DarkWolfXV

    DarkWolfXV Private E-2

    Yes, its is. I tried everything and after setting homepage to google, then trying various other sites its still V9. I wont be at home for a week so i wont probably reply for the time.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's try the below when you get back.



    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double-click OTL.exe to run. (if running Vista, Win7, or Win8 use right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      drives
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
    Also put a copy of the below file into a ZIP file and attach it here.
    C:\Users\Maciej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
     
  15. DarkWolfXV

    DarkWolfXV Private E-2

    Here it is.
     
  16. DarkWolfXV

    DarkWolfXV Private E-2

    Oh excuse me something did not work properly, here is the attachment again.
     

    Attached Files:

    • OTL.Txt
      File size:
      184 KB
      Views:
      2
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=WDCXWD10EZEX-22RKKA0_WD-WCC1S034539045390&ts=1368973015
    IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=prs&from=prs&uid=WDCXWD10EZEX-22RKKA0_WD-WCC1S034539045390&ts=1368973015
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
    IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=prs&from=prs&uid=WDCXWD10EZEX-22RKKA0_WD-WCC1S034539045390&ts=3211314
    O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:5C321E34
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  18. DarkWolfXV

    DarkWolfXV Private E-2

    The problem is still there, V9 wont go.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume that you are running IE from a link file. The link may be where they have inserted the V( stuff. Delete the below link file:

    C:\Users\Maciej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

    Now exit and restart Internet Explore. If you still have the problem, tell me exactly how you are starting up IE.
     
  20. DarkWolfXV

    DarkWolfXV Private E-2

    I deleted what you told me to, and now i cant find IE in apps anywhere. Tried downloading it but computer says i have got it already. It kind of solves my problem since now there is no IE to be infected. I ran IE when i had it on normal desktop mode (I have Win8) in the toolbar thing where you have turn off the computer button etc.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The poorly thought out changes to Windows 8 can be quite annoying. Makes it very difficult to run things that were so easy in the past.​

    Press the Windows Logo Key and hold it while also pressing the 'r' key. This is the hotkey to bring up the Run box. In the Run box, type iexplore.exe and click OK. ​

    Did IE run okay? Any signs of V9?


    Below is just an FYI link that may be of interest:

    http://www.addictivetips.com/windows-tips/where-is-startup-folder-how-to-edit-startup-items-in-windows-8/
     
  22. DarkWolfXV

    DarkWolfXV Private E-2

    Yes! Thank you, it is now working wonderfully. Also thank you for the startup folder advice.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay then let's repeat final instructions.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds