Avast WEBforum

Other => Viruses and worms => Topic started by: AlbertoGibert on October 21, 2013, 08:17:58 PM

Title: Start.qone8.com
Post by: AlbertoGibert on October 21, 2013, 08:17:58 PM
Al descargar Java versión 7 recomendado por ustedes y redirigido desde su página web, se ha instalado un programa espía que Avast no detecta el qone.com, o bien -- start.qone8.com -- que suplanta el navegador (todos) y la página de inicio que se cambia a start.qone.com en mi caso, pero hay otros nombres circulando. Lo he desinstalado desde panel de control, eliminar programas, pero es imposible.
Ayuda por favor. Gracias.
Title: Re: Start.qone8.com
Post by: Secondmineboy on October 21, 2013, 08:22:33 PM
Hello,

please post in english here if possible.

Follow this guide and attach the logs: http://forum.avast.com/index.php?topic=53253.0

When done malware removers will be notified and will help you to clean this up.
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 21, 2013, 08:32:10 PM
By installing java version 7 recommended from Avast. has downloaded a spyware program that supplants and replaces all browsers start page for start.qone8.com, looking so much like Google.com.

I tried manually desintalarlo but impossible. I have removed from elimination programs control panel, and is no longer, but still works to open any browser
Title: Re: Start.qone8.com
Post by: Secondmineboy on October 21, 2013, 08:36:53 PM
Actually there is malware on this site: http://www.avgthreatlabs.com/website-safety-reports/domain/qone8.com/
Blacklisted on Sucuri: http://sitecheck.sucuri.net/scanner/?scan=http%3A%2F%2Fstart.qone8.com
So this is malware.

Please follow the instructions above and a malware remover will help you to clean this up.
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 21, 2013, 08:48:59 PM
Yes, this is invasive , this is malawere. :(  The solution is paying, and I am paying for Avast.
Title: Re: Start.qone8.com
Post by: Secondmineboy on October 21, 2013, 08:51:22 PM
The solution is not paying.

NO Antivirus provides 100% protection. Not even Kaspersky or Bitdefender.

Malware removers will help you to get rid of this, for free. When logs are attached.
Title: Re: Start.qone8.com
Post by: essexboy on October 21, 2013, 08:51:43 PM
I can remove it for you ..  Where did you get the update ?

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
Secondary link (http://www.itxassociates.com/OT-Tools/OTL.exe)
(https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif)

netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir "%systemdrive%\*" /S /A:L /C
CREATERESTOREPOINT


Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 21, 2013, 09:22:04 PM
http://malwarefixes.com/remove-start-qone8-com-redirect/
Title: Re: Start.qone8.com
Post by: Secondmineboy on October 21, 2013, 09:24:07 PM
Please follow the steps from Essexboy, he knows what he is doing.
Title: Re: Start.qone8.com
Post by: essexboy on October 21, 2013, 09:29:38 PM
That link is using a sledgehammer to crack a nut and will probably not work
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 21, 2013, 10:03:31 PM
okay, thanks :)
Title: Re: Start.qone8.com
Post by: woland58 on October 22, 2013, 12:15:10 PM
have the same problem that AlbertoGilbert got.
I have done everything that essexboy suggested (run otl.exe etc.)
I am supposed to attach here the contents of the otl.txt and the extras.txt or what else?
thanks for your help




I can remove it for you ..  Where did you get the update ?

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
Secondary link (http://www.itxassociates.com/OT-Tools/OTL.exe)
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
(https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif)

  • Select All Users
  • Select LOP and Purity
  • Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir "%systemdrive%\*" /S /A:L /C
CREATERESTOREPOINT


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Attach  both logs
Title: Re: Start.qone8.com
Post by: essexboy on October 22, 2013, 03:59:22 PM
@woland58 if you start your own thread I will pick you up there
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 07:29:39 PM
Well, I ran the program OTL by old version and I have the report notes blok. Now what do I do?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 07:34:33 PM
Well, I ran the "OTL by old version" and I have the report in notepad. Now what do I do?
Title: Re: Start.qone8.com
Post by: essexboy on October 24, 2013, 08:38:28 PM
Could you attach the report please
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 08:58:20 PM
"OTL by old version" and I have the report in notepad.

Title: Re: Start.qone8.com
Post by: essexboy on October 24, 2013, 09:21:04 PM
On completion of this let me know if it has gone

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2002}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=133&systemid=2&apn_uid=4555234650224002&apn_dtid=IME002&o=APN10641&apn_ptnrs=AG2&q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=1083&systemid=1&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&gct=ds&appid=133&systemid=2&apn_dtid=IME002&apn_ptnrs=AG2&apn_uid=4555234650224002&o=APN10641&q="
FF - prefs.js..browser.search.order.1: "Search Results"
[2013/07/24 17:21:18 | 000,269,092 | ---- | M] () (No name found) -- C:\Users\Alberto\AppData\Roaming\mozilla\firefox\profiles\dj1h1zez.default\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi
[2012/04/07 16:58:54 | 000,002,353 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2013/10/13 22:57:33 | 000,000,664 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\qone8.xml
[2013/05/26 18:09:03 | 000,002,646 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-1571150509-1092675849-722137386-1000..\Run: [iLivid] C:\Users\Alberto\AppData\Local\iLivid\iLivid.exe (Bandoo Media Inc.)
O16:64bit: - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Reg Error: Key error.)
[2013/10/23 23:38:17 | 000,000,000 | ---D | C] -- C:\Users\Alberto\AppData\Local\iLivid
[2013/10/13 22:58:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyPC Backup
[2013/10/13 22:58:07 | 000,000,000 | ---D | C] -- C:\ProgramData\eSafe
[2013/10/13 22:57:31 | 000,000,000 | ---D | C] -- C:\Users\Alberto\AppData\Local\Lollipop
[2013/10/23 23:40:47 | 000,001,052 | ---- | M] () -- C:\Users\Alberto\Desktop\iLivid.lnk
[2013/10/23 23:40:47 | 000,001,060 | ---- | C] () -- C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
[2013/10/23 23:40:47 | 000,001,052 | ---- | C] () -- C:\Users\Alberto\Desktop\iLivid.lnk

:Files
C:\PROGRA~2\IMESHA~1\MediaBar

:Commands
[resethosts]
[emptytemp]
[Reboot]
THEN

Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 10:47:12 PM
Still appears: start.qone8.com  ...

I post the contents
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 10:48:08 PM
And the JRT
Title: Re: Start.qone8.com
Post by: essexboy on October 24, 2013, 11:19:15 PM
Which browser is it appearing in ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 11:28:47 PM
Explorer.
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 24, 2013, 11:30:22 PM
And Firefox too ..   :-[
Title: Re: Start.qone8.com
Post by: essexboy on October 25, 2013, 02:52:21 PM
Could you manually reset the IE and FF home page..  Does that stick ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=1083&systemid=1&sr=0&q={searchTerms}
[2013/10/24 21:00:00 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\RegTask.job

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 12:56:22 PM
yes, of course. I modified each time the page from ... Tools .. Internet options ... to google.com, and also from safety put it in restricted sites the direction start.qone8.com
This problem qone8.com, comes from the java.com website  which recommends upgrading Avast Internet Security

I send you the report in a few minuts .... BTW Chome too .. :(
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 01:28:28 PM
without success ...  :(
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 01:44:44 PM
I post the log OTL.
Title: Re: Start.qone8.com
Post by: essexboy on October 29, 2013, 03:54:04 PM
Could you download shortcut cleaner from here to your desktop
http://www.bleepingcomputer.com/download/shortcut-cleaner/

Run the programme and if Avast queries it add it to the exceptions
On completion a log will be produced on the desktop
Please post that
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 07:02:20 PM
Posting  sc-cleaner ..
Title: Re: Start.qone8.com
Post by: essexboy on October 29, 2013, 07:17:27 PM
This one is playing hard to get

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=1083&systemid=1&sr=0&q={searchTerms}
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.useDBForOrder: true
[2013/10/22 16:24:29 | 000,002,193 | ---- | M] () -- C:\Users\Alberto\AppData\Roaming\mozilla\firefox\profiles\dj1h1zez.default\searchplugins\geotool.xml

:Files
C:\Users\Alberto\AppData\Local\Temp\_MEI38842

:Commands
[resethosts]
[emptytemp]
[Reboot]
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1  (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://forums.whatthetech.com/How_Disable_your_Security_Programs_t96260.html&pid=494216#entry494216)
(http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png)

(http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png)

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 08:40:50 PM
Right, I send report that came out in the notebook.
But I do not know how to disable Avast Internet Security to continue.
Should I disable Windows Defender?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 08:53:11 PM
oh .. Sorry; the OTL report ..
Title: Re: Start.qone8.com
Post by: essexboy on October 29, 2013, 09:20:11 PM
Right click the Avast icon and select shield control > Disable until reboot
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 10:02:45 PM
Well, continued all the same. By opening any browser opens a tab:
http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
For the rest it seems there is no other problem, but still not solve the problema  :(

Sending report ...
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 29, 2013, 10:22:42 PM
When I open a new tab, I get a security alert: You are about to leave a secure connection to the Internet. It is possible that other people see the information you send.
Do you want to continue?
 (  ) Do not show me this warning.
Title: Re: Start.qone8.com
Post by: essexboy on October 29, 2013, 11:39:23 PM
OK we will need to reset all browsers now.  I will need to see how firefox and chrome do this

For IE

Go control panel > internet options > advanced and click reset
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 30, 2013, 07:20:59 PM
Please a question before: I will lose all the links that I keep in IE "Favorites"?
Thanks ... I wait for answer ...
Title: Re: Start.qone8.com
Post by: essexboy on October 30, 2013, 07:24:18 PM
No favourites will not be affected as it just resets the workings of IE

If you want to be doubly sure you can export favourites first

This can be done via the favourites menu in IE

Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 30, 2013, 08:51:38 PM
Without success ..  :( ... Continuing appearing:
http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
Title: Re: Start.qone8.com
Post by: essexboy on October 30, 2013, 10:04:54 PM
Within Firefox and Chrome are you able to reset the search engine ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 30, 2013, 10:50:56 PM
The search engine is google in all three browsers. It was the first thing I did before consulting. However to open any browser appears as a new tab:
start.qone8.com ...
Title: Re: Start.qone8.com
Post by: essexboy on October 30, 2013, 11:09:51 PM
I just noticed that I did not get an all user OTL scan

Could you re-run the scan and ensure that all users is selected please
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 31, 2013, 12:13:24 AM
I have to paste any script ?
And how I selected all users ??
Thanks.
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 31, 2013, 12:36:42 AM
Good I ve pasted: BASESERVICES
%SYSTEMDRIVE%\*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir "%systemdrive%\*" /S /A:L /C

I sellect all and post the OTL
Title: Re: Start.qone8.com
Post by: essexboy on October 31, 2013, 04:20:07 PM
This is the most obstinate version that I have come across.. Normally one maybe two fixes kill this

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKU\S-1-5-21-1571150509-1092675849-722137386-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1571150509-1092675849-722137386-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.useDBForOrder: ""
O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.

:Files
C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
C:\Users\Alberto\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 31, 2013, 07:26:36 PM
Very funny to me that this is the most obstinate version that you have come across. Goddd  :(

I post the log with selecting all users: Its right?
Title: Re: Start.qone8.com
Post by: essexboy on October 31, 2013, 07:30:20 PM
Are you still getting it coming as your main search engine ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 31, 2013, 07:49:12 PM
Yes .....
Comes opening a new tab in all browsers because keeping open the last session.
When not saved the last session appears as the first tab, though Google the search engine that II have set.
Title: Re: Start.qone8.com
Post by: essexboy on October 31, 2013, 08:21:59 PM
OK in IE could you visit here http://windows.microsoft.com/en-gb/windows-vista/change-or-choose-a-search-provider-in-internet-explorer  get a new search provider (i.e. Bing) this will not be for long
Make this your main search engine
Then delete the Google search engine
Does it still appear
Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 31, 2013, 10:04:07 PM
Yes, still appears it : http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS

How to restore the search engine Google please?
Title: Re: Start.qone8.com
Post by: essexboy on October 31, 2013, 11:01:59 PM
To restore Google follow the same process as used to get bing

Could you check in internet options that you have only one home page set

Title: Re: Start.qone8.com
Post by: AlbertoGibert on October 31, 2013, 11:11:38 PM
Yes, I have only one home page set : http://www.google.com/
Title: Re: Start.qone8.com
Post by: essexboy on November 01, 2013, 03:02:36 PM
These type of programmes really annoy me - especially when they find new ways to hide

For 32bit systems, please download SystemLook from one of the links below and save it to your Desktop.
 
Download Mirror #1 (http://jpshortstuff.247fixes.com/SystemLook.exe)
Download Mirror #2 (http://images.malwareremoval.com/jpshortstuff/SystemLook.exe)

 
For 64bit systems, download SystemLook from here (http://jpshortstuff.247fixes.com/SystemLook_x64.exe).
 
 
Code: [Select]
:regfind
start.qone8.com
start.qone8
qone8

 
Note: The log can also be found on your Desktop entitled SystemLook.txt
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 01, 2013, 08:40:24 PM
Here you are ...
Title: Re: Start.qone8.com
Post by: essexboy on November 01, 2013, 08:54:08 PM
After this fix could you re-run system look please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:Reg
[-HKEY_USERS\S-1-5-21-1571150509-1092675849-722137386-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\qone8.com]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\qone8.com]
[HKEY_USERS\S-1-5-21-1571150509-1092675849-722137386-1000\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
"LastKey"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit]
"LastKey"=-

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 01, 2013, 10:30:47 PM
Still appears: http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS

Posting ...
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 01, 2013, 10:33:00 PM
And the system look
Title: Re: Start.qone8.com
Post by: essexboy on November 01, 2013, 10:35:03 PM
OK I will have to do a bit more research on where this could be generated
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 01, 2013, 10:41:09 PM
Rigth, thanks. I will wait.
Title: Re: Start.qone8.com
Post by: essexboy on November 05, 2013, 07:04:10 PM
Still searching with no real answer yet

Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 05, 2013, 11:23:04 PM
Okay. In Explorer are appearing one direction without permission: http://www.javainstall.org that replacing the page I'm seeing, and warns me that I have to update Java because the computer is unsafe. Within this page displayed by surprise out another window, within small, that says "accept".
I put in security - restricted sites and it will not leave for now. It's all very strange.  :(   
Title: Re: Start.qone8.com
Post by: essexboy on November 06, 2013, 03:06:18 PM
That site is blocked by Avast so I am surprised you are able to go there

Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 06, 2013, 06:13:24 PM
So .. I am surprised too  :(
Title: Re: Start.qone8.com
Post by: essexboy on November 09, 2013, 02:57:21 PM
Metallica has posted a removal guide here .. could you run this ..  Ensure that MBAM is updated http://www.geekstogo.com/forum/topic/334820-removal-instructions-for-qone8/
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 11, 2013, 06:42:13 PM
I send the registration of Malwarebytes Anti -Malware . Detects a file that should quarantine , or delete , internet does not work . No browser. I had to restore that file.

One question please. When i open google.com or google.es appears an extensión every time diferent:
https://www.google.es/?gws_rd=cr&ei=6xSBUvSCNoGXtAbgnIG4Cg
https://www.google.es/?gws_rd=cr&ei=SBWBUsnOJ8PdtAboloDYBA
https://www.google.es/?gws_rd=cr&ei=0hWBUpe1CcWatQbT4YGwBw
Etc ... Is it normal ???????
Title: Re: Start.qone8.com
Post by: Secondmineboy on November 11, 2013, 06:44:25 PM
Second and third link are a bit different if you look in the top right corner on the GMail text.
Title: Re: Start.qone8.com
Post by: essexboy on November 11, 2013, 07:40:12 PM
So you had to restore the qone8 registry entry ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 11, 2013, 07:55:17 PM
Yes. I had to do it and reboot it did not work any browser. I had no internet connection. Very strange.
Title: Re: Start.qone8.com
Post by: essexboy on November 11, 2013, 08:50:03 PM
Yes as it was just the search scope that was removed so it should have no effect on the connection.. 

Is it still present when you try a google search ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 11, 2013, 10:25:54 PM
I will test again. Yes, after restoring the file, it still appears as before, as a new tab to restore the last session in all browsers. Something also strange is that Google page does not display normally shown without doodles.

And another thing to note is that once you deleted the file, start.qone8.com, trying to be opened as a new tab anyway, but went into a loop, which made the display of the error: Connection Problems, can not be show this page. That also happened with the rest of tabs opened except for the "https"

I can not make a screenshot of the antimalware program, but I can open the file location (presumably infected) and displayed:
{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}
-ProgID

In Malwarebytes appears:
Distributor: PUP.Optional.qone8
Category: Registry Key
Elements: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}
Title: Re: Start.qone8.com
Post by: essexboy on November 11, 2013, 11:21:07 PM
OK I will try and craft a reg fix to replace that with a dummy
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 11, 2013, 11:46:33 PM
Ok. Thanks and good night.
Title: Re: Start.qone8.com
Post by: essexboy on November 12, 2013, 04:17:40 PM
OK lets try this :)

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:Reg
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
@="Bing"
"URL"="http://www.google.com/search?q={searchTerms}&FORM=IE8SRC"
"DisplayName"="@ieframe.dll,-12512"

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 13, 2013, 09:59:26 PM
Here you are ...
Title: Re: Start.qone8.com
Post by: essexboy on November 13, 2013, 10:12:41 PM
Did that remove it ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 13, 2013, 10:49:38 PM
No .... http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS

Title: Re: Start.qone8.com
Post by: essexboy on November 13, 2013, 11:09:53 PM
OK lets now remove the clsid and then reset the network

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:Reg
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]

:Files
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c
netsh winsock reset /c
netsh advfirewall reset /c

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 13, 2013, 11:53:30 PM

Continues to appear ...there is no way ...

http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
Title: Re: Start.qone8.com
Post by: essexboy on November 14, 2013, 03:00:24 PM
Could you run MBAM one more time please
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 14, 2013, 10:07:56 PM
Yes of course, do no detect any malware now, but continues ..
http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
Title: Re: Start.qone8.com
Post by: essexboy on November 14, 2013, 11:13:24 PM
OK I will have to go back to the drawing board on this...  Are you running spybot by any chance ?
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 15, 2013, 11:58:45 PM
spybot ?  I Not quite understand what you mean .. I have Avast, and also Malwarebytes trial Versión.
Hummm two anti malware?  Is it good?
Title: Re: Start.qone8.com
Post by: essexboy on November 16, 2013, 01:13:05 PM
OK go to control panel > internet option
Select the new tab button...  What is in the box
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 16, 2013, 07:42:03 PM
Done! But nothing was sorted ....
Continues http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 17, 2013, 10:45:53 PM
What is in the box ? it was a question ? : about:Tabs
Title: Re: Start.qone8.com
Post by: essexboy on November 17, 2013, 10:52:52 PM
Yes as that is where the second tab opens to

Still no further on this yet..  This is curious as normally it goes fairly quietly
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 20, 2013, 10:09:56 AM
Well, now what ?

I have to reformat the hard drive? .. Or will you seek a solution?
Title: Re: Start.qone8.com
Post by: essexboy on November 20, 2013, 03:24:14 PM
A reformat in this case would be a faster solution, as none of my contacts have yet been able to see where this is originating.  All are as baffled as I 
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 20, 2013, 09:21:32 PM
Well, for now I will wait because I have a lot of information not stored in backup, and many photos and files. If you have any ideas in the coming days, I will be thankful.
Nor is it for now, It produces any problem apart from appearing every time I open any browser except Avast SafeZone.
Title: Re: Start.qone8.com
Post by: essexboy on November 25, 2013, 08:28:32 PM
Could you run this programme please

Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 25, 2013, 10:36:44 PM
Copy and paste FRST: 
The following error or errors occurred while posting this message:
The message exceeds the maximum allowed length (10000 characters).

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-11-2013 01
Ran by Alberto (administrator) on ALBERTO-TOSH on 25-11-2013 22:17:35
Running from C:\Users\Alberto\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Spanish Modern Sort
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

I send you the attachments:
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 25, 2013, 10:37:35 PM
And the Addition ...

Title: Re: Start.qone8.com
Post by: essexboy on November 25, 2013, 10:44:20 PM
Download the attached fixlist.txt to the same location as FRST
Run FRST and press fix
On completion a log will popup please post that

Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 25, 2013, 11:09:24 PM
The log :
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 25, 2013, 11:21:46 PM
And still appears:  http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
Title: Re: Start.qone8.com
Post by: essexboy on November 25, 2013, 11:25:35 PM
Yep Chrome is a pain in the posterior..  The page is in the restore on start settings and according to Google they are easy to reset

Could you follow the steps here and let me know the result

https://support.google.com/chrome/answer/3296214
Title: Re: Start.qone8.com
Post by: AlbertoGibert on November 26, 2013, 01:46:38 AM
Well, I followed the instructions, but still appearing. So far I have not noticed anything worse in engine performance team, 'running well, but is a real nuisance to have to mess around with is Qone8 besides not knowing if it is sending information to sites that do not know.
Still...  in all browsers
http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS

I will try to uninstall Chrome  ....
Title: Re: Start.qone8.com
Post by: mchain on November 26, 2013, 08:47:22 AM
WOT blocks access to start.gone8:  See picture below.

https://www.mywot.com/en/scorecard/start.qone8.com?utm_source=addon&utm_content=warn-viewsc (https://www.mywot.com/en/scorecard/start.qone8.com?utm_source=addon&utm_content=warn-viewsc)
Title: Re: Start.qone8.com
Post by: essexboy on November 26, 2013, 04:12:56 PM
AdwCleaner has been updated now to try and tackle this so it would be worth a shot

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode onto your desktop.
Title: Re: Start.qone8.com
Post by: AlbertoGibert on December 03, 2013, 02:40:17 PM
I have to disable Avast in the process?
Avast blocks downloading Adw

Avast:

Infección Bloqueada

URL:
http://download.bleepingcomputer.com/dl/d9cc85d596e6...

Infección:
Win32:Dropper-gen [Drp]
Title: Re: Start.qone8.com
Post by: essexboy on December 03, 2013, 03:49:03 PM
OK I will report that as an FP
Title: Re: Start.qone8.com
Post by: AlbertoGibert on December 03, 2013, 06:44:41 PM
Yessssssssss !!!!!
start.Qone8.com has disappeared I think.
Thank you very much.
Posting  Attachments ..
Title: Re: Start.qone8.com
Post by: essexboy on December 03, 2013, 07:27:30 PM
Quote
Acceso directo Desinfectado : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Acceso directo Desinfectado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Acceso directo Desinfectado : C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Acceso directo Desinfectado : C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Acceso directo Desinfectado : C:\Users\Alberto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Acceso directo Desinfectado : C:\Users\Alberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Acceso directo Desinfectado : C:\Users\Alberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Acceso directo Desinfectado : C:\Users\Alberto\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
That is where it was hiding .. Yet I am sure we searched that area earlier

If it is still gone tomorrow let me know and I will tidy up
Title: Re: Start.qone8.com
Post by: AlbertoGibert on December 03, 2013, 10:13:44 PM
Yes I will.  and thank you for everything.

By the moment to reboot, and open the  browser (any), not the tab opens with start.qone8.com  :)

And yes, I remember that I removed all the shortcuts on the tool bar, but I think they were duplicated on the desktop and I did not realize I did not think about that at the time ....
Title: Re: Start.qone8.com
Post by: essexboy on December 03, 2013, 11:21:26 PM
No problem just glad it is gone :)
Title: Re: Start.qone8.com
Post by: davidbalaban on December 16, 2013, 12:31:36 PM
I do not usually use any additional software to clean things, just read forums and remove everything manually. Qone8 is relatively easy to remove manually: http://soft2secure.com/knowledgebase/qone8-com-virus