Qoologic/Winsync Help Needed!!!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Leezza, Dec 23, 2005.

  1. Leezza

    Leezza Private E-2

    Hi,

    Ok....been trying to rid this spyware off my son's computer for days....we've had it gone, but it keeps coming back, so today I started all over and have done the following:

    Safe Mode:
    Adware SE - Finds Nothing
    CC Cleaner - Ran and deleted Junk
    MS Antispyware - Finds Nothing
    Spybot Search & Destroy - Found Qoologic - in Windows System 32 folder the file is named -- oikocw.exe (which is the one that comes back over and over), also found a Registry Key ending in Run Winsync...) in both case it "fixed" both these problem?

    Ran BiteDefender in Safe Mode and it found some WxBug.exe files in AIM files, but wasn't able to fix it. (I have that log saved as a text file and can attach if needed).

    Tried running Panda online in Safe and it would not work.

    Rebooted into Normal and tried Panda again...still won't work, keep getting an error message that it cann't run, something about ActiveX, although I allow the Active X....tried it 3 times no luck.

    We have recently deleted Norton Internet Security off the system and are now running Avast and Zone Alarm, as some of your forums have suggested. Norton was such a memory hog.

    Also, have been running: MS AntiSpy, Adware SE, Spyware Blaster etc., for months and it never stopped this crazy thing. I believe it's been on here for a long time.

    Was not an issue until now, because it seems to conflict with iTunes...can't run iTunes with this Malware/Spyware, which is a huge problem as my son is getting an iPod for Christmas.....!!

    I have attached the HiJack Log and hope you can help me to rid this system of this "bug" for good, hopefully before Christmas!! :)

    Thank You!
     

    Attached Files:

  2. Leezza

    Leezza Private E-2

    It's Back.....that darn thing...so here is another HiJack Log showing the culprit file in that Sytems 32 folder again!

    UGH!!!!:mad:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After getting the WinPfind log attached, continue to get these logs and attach them.

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post the logs as attachments
     
  5. Leezza

    Leezza Private E-2

    Ok....Here are the logs: WinPFind and Qoologic....
    Please note: The Qoologic tool, may not be running right, I get a lot of error type messages then keep hitting ignore and it finally finishes, the log is creates is attached.

    About the Rk Tool....I then booted into Safe Mode and ran the RKfiles.bat...a DOS windows opens:

    System32/cmd.exe
    then it say
    1. file(s) copied
    1. file(s) copied
    1. file(s) copied
    then Please wait until the DOS window closes....post the contents of C:log.tx...then it says:
    Checking System Folder.......

    you see a "flashing" _ prompt and nothing else seems to happen....I waited several minutes and nothing. So I closed it and tried again, but the same. I did post that log too, but there isn't anything there. Should this take a long time? Am I not waiting long enough? I'll certainly try again, but just wanted to be sure I'm doing this correctly.

    ....Anyway for now, here is what I have!
     

    Attached Files:

  6. Leezza

    Leezza Private E-2

    Update:

    Ran the RK tool again.....It finally worked :)

    The log is attached.

    :eek:
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Providing exact error messages (word for word) is a lot more useful to us.

    But the error message you were getting could be important especially if it is something about autoexec.nt

    Please do not reboot or power down you PC unless we request you to do so. Otherwise this infection could keep renaming itself.
     
    Last edited: Dec 23, 2005
  8. Leezza

    Leezza Private E-2

    Sorry about that...I just ran it again and in the background (DOS) screen there is a message about "cannot do something because it is being used by another process"....it repeats but it's hard to get the exact wording because it happen really quickly.

    Then a screen pop-up that says 16-Bit DOS....and has the error message you seemed to mention: inlcuding the Autoexec.nt error, it then wants you to then either hit Ignore or Close the program...Which is what we've done.

    Hope that helps some!

    In the meantime we WILL NOT boot the system at all.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try the below!

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (if you do not see this exact oikocw.exe filename, look for another O4 line with [winsync] on it and fix that line):
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\oikocw.exe reg_run

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (Some may not be found. Let me know what you do and don't find.)
    C:\WINDOWS\eiunin2.exe
    C:\WINDOWS\icont.exe
    C:\WINDOWS\vokvz.dll
    C:\WINDOWS\system32\kelkw.dll
    C:\WINDOWS\system32\oikocw.exe (if you do not see this exact oikocw.exe filename, look for the one in the O4 line with [winsync] on it and delete that file)
    C:\WINDOWS\RMAgentOutput.dll
    C:\WINDOWS\Temp\start5\install.DAT <---- in fact it would be best if you delete the whole start5 folder.
    C:\WINDOWS\Temp\start5\log1.txt
    C:\WINDOWS\Temp\start5\msg.exe
    C:\WINDOWS\Temp\start5\Start.exe
    C:\WINDOWS\Temp\start5\data\img.bmp
    C:\WINDOWS\Temp\start5\data\read.txt
    C:\Documents and Settings\Mom\Local Settings\Temp\EINSTALL\INSTALL.EXE
    C:\Documents and Settings\All Users\Local Settings\Temp\EINSTALL\INSTALL.EXE
    C:\Documents and Settings\Mom\Desktop\jump.url
    C:\Documents and Settings\All Users\Desktop\jump.url

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is,
    uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this
    folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. Leezza

    Leezza Private E-2

    Ok....Did everything this is what happened.

    did the Registy edit....all went Ok.

    did the Hijack and deleted the 04 line that was there, the winsync one just exactly as it has been.

    Then booted into Safe Mode

    Deleted these files:
    Windows\eiuin2.exe
    windows\icot.exe
    windows\vokvz.dll
    windows\system32\kelkw.dll
    windows\system32/oikosw.exe (it was there)
    windows\RMAgentOutput.dll

    Then could not find ANY of the other files.

    Nothing in the windows\temp\start 5 existed - No Start5 files AT ALL
    Documents and Settings\Mom\LocalSettings\Temp\EINSTALl\INSTALL. EXE (no file found)
    Documents and Settings\All Users\Local Settings\Temp\EINSTALL\INSTALL.EXE (no file found)
    and also checked the other user on the system, but not in his folders either.
    Documents and Settings\Mom\Desktop\jump.url (not found)
    Documents and Settings\All Users\Desktop\jump.url (not found)

    Tried even searching for any Start5 files/folders and none were found.

    Then ran CCleanr and deleted all the Prefetch files and ran CClear again.

    Then rand the XP Fix and that went OK.

    Finally ran a new HiJack log, which is attached, but I can already see we're in trouble as the darn thing is BACK already! UGH!

    Popups already and MsAntiSpy blocked the miserable file from loading into the startup registry right away, so I knew there was trouble.

    Can I cry now!!!! :eek:
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below file visible:

    C:\WINDOWS\system32\oikocw.exe
     
  13. Leezza

    Leezza Private E-2

    Currently, It is not visible. It was visible during Safe Mode though.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Disable ALL of MS Antispyware's Realtime protection.

    Then run HJT and fix the O4 line.
    Then reboot and see if a new log is clean.
     
  15. Leezza

    Leezza Private E-2

    Did exactly as you said....Disabled the MSAnitspy stuff, then did the HiJack and again asked it to fix that same (04) line, had it fix it closed the program --- all browsers were closed -- Then re-booted and ran HiJack again and it's back yet again.

    The latest log is attached.

    One question, I'm doing these latest things you asked in Normal Mode, is that correct and/or should I also try to have HiJack this fix it in Safe Mode???
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Unless we tell you otherwise, always assume normal mode. There are times when certain steps may be run in safe mode but you will always be told when. Like in message 9 where said boot in safe mode before deleting the files.

    Get me a new Rkfiles and WinPfind log. Either there is something recreating this key or it is not getting properly removed due to something blocking it (like MS Antispyware or another similar program).
     
  17. Leezza

    Leezza Private E-2

    Here are the logs you asked for!
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run and enter regedit and click OK! Navigate to the below registry key and see if you can find WinSync

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Let me know!
     
  19. Leezza

    Leezza Private E-2

    Nope, not in there.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure! WinPfind shows:


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    winsync C:\WINDOWS\system32\oikocw.exe reg_run
     
  21. Leezza

    Leezza Private E-2

  22. PhilliePhan

    PhilliePhan Guest

    Don't forget to delete this associated Startup Entry showing in the PFind log:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\qhiq.exe

    Happy Christmas :)
    PP
     
  23. Leezza

    Leezza Private E-2

    Er.. When? i was just looking through the registry for the file, do you want me to delete that right now? And specifical in safe or normal mode?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks PP! I gotta change my screen resolution! With the wrap around, I did not see it.

    Leezza,

    Just look for the file and delete it. If you cannot, then boot to safe mode and delete it.

    Afterwards check the HJT log again and see if the O4 line is gone. If not, fix it and see if it stays fixed.
     
  25. Leezza

    Leezza Private E-2

    Mhmm... I deleted qhiq in Safe Mode. I looked at oikocw.exe in safe mode too, amd it was there, but I didnt touch it. I booted into normal mode after, checked HJT, and its still there.:rolleyes:
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean the file is there? Or do you mean the HJT line?
    Either way, delete the file or fix the line. Then reboot and get a new HJT log and see if it is gone. If not, we will need a need WinPfind log to go with the HJT log.
     
  27. Leezza

    Leezza Private E-2

    Its still here... anyways, here are the logs. :eek:
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because you did not get the below deleted:

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\qhiq.exe

    Let's use a different approach.

    Disable MS Antispyware again!

    Please download: Pocket KillBox

    Extract Pocket Killbox to its own folder but do not run it yet. We will need it later.

    Run HJT and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\oikocw.exe reg_run

    After clicking Fix, exit HJT.

    Now run Pocket Killbox.

    Now, Copy and Paste C:\WINDOWS\system32\oikocw.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\Documents and Settings\All Users\Start Menu\Programs\Startup\qhiq.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    If you get an error message about Pending Operations, just reboot your PC yourself but either way please boot into safe mode. And while in safe mode do nothing but the below:

    - Run Windows Explorer and double check for the below files and delete if found (some of these are double checks to make sure they are gone):
    C:\WINDOWS\system32\oikocw.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\qhiq.exe


    Now reboot (whether you find them or not) into normal mode.

    Now get a new HJT log and attach it here. And tell me how these steps went and how things are working.
     
  29. Leezza

    Leezza Private E-2

    :) Its not in the HJT log!! There was no errors with KillBox, etc. If this has finally fixed it, THANK YOU.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  31. Leezza

    Leezza Private E-2

    Re: Qoologic/Winsync Help Needed -- Still Gone!!!!

    Happy Christmas Eve and a Very Merry Christmas!

    Our special thanks for helping us with this spyware -- it was a real challenge and I'm hoping my son will be far more careful on the internet from now on!

    PS: I had to give up early last night, so it was actually my son who was working with toward the end to finally rid his system of the spyware....He did good! And it's still gone.

    Again, have a Wonderful Holiday Season!​


    Lisa and Alex

    :) :)
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Qoologic/Winsync Help Needed -- Still Gone!!!!

    You're welcome. Enjoy the holidays malware free! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds