Okay. In Explorer are appearing one direction without permission: http://www.javainstall.org that replacing the page I’m seeing, and warns me that I have to update Java because the computer is unsafe. Within this page displayed by surprise out another window, within small, that says “accept”.
I put in security - restricted sites and it will not leave for now. It’s all very strange.
That site is blocked by Avast so I am surprised you are able to go there
So … I am surprised too
Metallica has posted a removal guide here … could you run this … Ensure that MBAM is updated http://www.geekstogo.com/forum/topic/334820-removal-instructions-for-qone8/
I send the registration of Malwarebytes Anti -Malware . Detects a file that should quarantine , or delete , internet does not work . No browser. I had to restore that file.
One question please. When i open google.com or google.es appears an extensión every time diferent:
https://www.google.es/?gws_rd=cr&ei=6xSBUvSCNoGXtAbgnIG4Cg
https://www.google.es/?gws_rd=cr&ei=SBWBUsnOJ8PdtAboloDYBA
https://www.google.es/?gws_rd=cr&ei=0hWBUpe1CcWatQbT4YGwBw
Etc … Is it normal ???
Second and third link are a bit different if you look in the top right corner on the GMail text.
So you had to restore the qone8 registry entry ?
Yes. I had to do it and reboot it did not work any browser. I had no internet connection. Very strange.
Yes as it was just the search scope that was removed so it should have no effect on the connection…
Is it still present when you try a google search ?
I will test again. Yes, after restoring the file, it still appears as before, as a new tab to restore the last session in all browsers. Something also strange is that Google page does not display normally shown without doodles.
And another thing to note is that once you deleted the file, start.qone8.com, trying to be opened as a new tab anyway, but went into a loop, which made the display of the error: Connection Problems, can not be show this page. That also happened with the rest of tabs opened except for the “https”
I can not make a screenshot of the antimalware program, but I can open the file location (presumably infected) and displayed:
{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}
-ProgID
In Malwarebytes appears:
Distributor: PUP.Optional.qone8
Category: Registry Key
Elements: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}
OK I will try and craft a reg fix to replace that with a dummy
Ok. Thanks and good night.
OK lets try this
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:Reg
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
@="Bing"
"URL"="http://www.google.com/search?q={searchTerms}&FORM=IE8SRC"
"DisplayName"="@ieframe.dll,-12512"
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Here you are …
Did that remove it ?
No … http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
OK lets now remove the clsid and then reset the network
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:Reg
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
:Files
ipconfig /flushdns /c
ipconfig /release /c
ipconfig /renew /c
netsh winsock reset /c
netsh advfirewall reset /c
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Continues to appear …there is no way …
http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS
Could you run MBAM one more time please
Yes of course, do no detect any malware now, but continues …
http://start.qone8.com/?type=sc&ts=1381697851&from=tugs&uid=TOSHIBAXMK6465GSXN_Z0LCS14DSXXZ0LCS14DS