Problems with Qoologic and other malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Burning_Monkey, Jun 27, 2006.

  1. Burning_Monkey

    Burning_Monkey MajorGeek

    As per requested in the FAQ pages, I have attached the log files for FindQool, RKTool, and winPFind. I have also included the HiJackThis log file just in case. Any help would be appreciated and thank you in advance.

    Please let me know if the log files are not readable and I will upload them individually.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log is from Safe Mode.

    Welcome to MajorGeeks.com!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (
    these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. Burning_Monkey

    Burning_Monkey MajorGeek

    Sorry about that.

    I will go through the supplied steps and see if that helps. And post the logs in the correct way.
     
  4. Burning_Monkey

    Burning_Monkey MajorGeek

    OK.

    Went through the suggested steps and still am having problems. Attached are the requested log files, all done in the requested way as listed in the FAQ posted above. Please let me know if there is anything else that I need to do.

    Thank you for your assistance.

    Sorry about the double post.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The procedure I had you run won't clean a Qoologic infection. I needed the logs to find all the files associated with the infection.

    Download
    - Pocket Killbox
    - Regitrar Lite 2.0 Use a Major Geeks Mirror not the Author's Site. (May not need use this tool)

    Empty your SAV CE Quarantine Folder
    Empty your Recycle Bin
    Empty your Internet Cache

    From Add or Remove Programs in the Control Panel; uninstall everthing from Viewpoint.

    Follow the directions for SurfSideKick Removal.

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin

    And Click OK.

    REBOOT to Normal Mode.

    Foloow the directions for Using GetRunKey.

    Post fresh logs from FindQool, WinPFind, HijackThis and runkey.txt.
     
    Last edited by a moderator: Jun 28, 2006
  6. Burning_Monkey

    Burning_Monkey MajorGeek

    Well, thank you for all that help. I really appreciate it. As you requested I have attached a new HijackThis log, FindQool log, WinPFind log, and the runkey.txt files.

    Once again, I greatly appreciate the help with these problems.
     

    Attached Files:

  7. Burning_Monkey

    Burning_Monkey MajorGeek

    I don't know if this is related in any way, but now if I try to run a SAV scan in normal mode I get an error stating that the scan engine couldn't start. Error code 0x20000058

    It seems that almost all traces of the malware are gone though. If I could just get SAV to work right, I would call this just about done.
     
  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Reboot to Safe Mode.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Reboot to Normal Mode.

    Post a fresh HijackThis log.
     
  9. Burning_Monkey

    Burning_Monkey MajorGeek

    I appreciate all the help so far.

    Here is the new HijackThis log and hopefully we can get this wrapped up.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds