Trek Blue Error Nuker-removed...or not??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by weatherqueen, Nov 7, 2005.

  1. weatherqueen

    weatherqueen Private E-2

    After running Spybot today, it showed "Trek Blue Error Nuker" as a problem. I "googled" it and found out others had problems with it still showing up even after fixing it with Spybot.. I fixed it with Spybot and rebooted. Ran Spybot again but it didn't show up again as it has for others. Didn't show up with Adaware or anything else.
    How can I find out if it was REALLY fixed since others are saying Spybot didn't fix it for them?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If SpyBot said it fixed it successfully then I would be willing to bet it really removed it.

    Was it files or registry entries?
     
  3. weatherqueen

    weatherqueen Private E-2

    Alright I'm willing to show my ignorance because you always seem to be patient with those of us learning as we go, so the answer is...I don't know, but I think registry entries.
    How can I tell?
    Thank you in advance oh Great Computer God and Fixer of All ignorant Computer Geek Foul Ups-
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, do you know what it detected, registry entries, files? If so can you get me a log from Spybot?

    Also, check in the backups and see if you can find some information there about what it found.
     
  5. weatherqueen

    weatherqueen Private E-2

    Okay, I did a little playing around and learned a lot more about what I can do with Spybot other than "scan and fix". Didn't know about the logs or reports. Just never had to use it before.
    I have attached what I think you're looking for.
    Thanks so much for your time-
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Doesn't show anything, I would be willing to bet it's gone. I've never seen a case where SpyBot claimed it fixed something and really did not.

    Download CWShredder 2.18, save to your desktop and double click to run. Let me know if this finds anything.
     
  7. weatherqueen

    weatherqueen Private E-2

    ran CWShredder and it says found 1 variant:CWS.Qttasks. I googled it and the onfo I found was conflicting and confusing except for info on CWShredder site. It stated as follows:

    "CWS.Qttasks
    Variant 21: CWS.Qttasks
    Approx date first sighted: November 23, 2003
    Symptoms: IE pages being changed to start-space.com
    Cleverness: 2/10
    Manual removal difficulty: Involves some Registry editing
    Mimicking the legit 'QuickTime Task' autorun entry in the Registry (which is in the HKLM hive), this variant loaded at startup and changed only the Start Page to start-space.com"
    I haven't had any problems with pages being changed to space.com, though.
    Your opinion/advice...
    Thanks-
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    (Don't run it yet)

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file cwsfix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)
    Double-click on the cwsfix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge, click YES!


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\WINDOWS\system32\qttasks.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES.

    • If you get an error message about Pending Operations, just reboot your computer manually.

    After you have rebooted, let me know how things are running.
     
  9. weatherqueen

    weatherqueen Private E-2

    Did everything you said to do...Haven't noticed any negative reactions so far.
    Thanks for all your help and I will let you know if I have any problems.
    Take care-
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  11. weatherqueen

    weatherqueen Private E-2

    This is what I have: the whole Norton package (AntiVirus\Internet Security, and I use their firewall), Ad-Aware, Spybot, Spyware Blaster, Microsoft AntiSpyware, BHODemon, stinger and CCleaner. I update and run weekly.
    With your help in solving my problem I have added cwshredder and KillBox.
    Because I'm a geek neophyte I have to work extra hard at keeping my pc clean...and even harder to clean it after I have screwed it up!!!!! (^_^)
    I've read all the stuff here and tried to live by it but I have to admit, I don't realize I don't understand something until I screw something up and have to fix it and then I realize..."aha, that's what they were talking about".
    So until I become a real geek, I'm just a goober!
    Take care and thanks again-
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds