First experience with Malware-Qoologic

Discussion in 'Malware Help (A Specialist Will Reply)' started by samthunder, Jun 19, 2006.

  1. samthunder

    samthunder Private First Class

    I've run all kinds of anti-spyware and anti-virus on my PC (thanks in large part to suggestions here) but I suspect that this trojan is blocking a lot of my removal and cleaning efforts. I'm following the special removal procedures, here are the logs requested.

    If you notice any other problems, which I'm sure there will be :mad: please chime in. Keep in mind I'm not very techno-savvy, so speak slowly please.


    Sam
     
    Last edited: Jun 21, 2006
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Due to the nature of the Qoologic infection and also the fact that it looks like you have other malware problems, you will need to run our standard cleaning steps given below before we can get you all fixed up. Yes, this is going to take a bunch more work on your part but the goal is to make sure we clean ALL malware from your PC.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. samthunder

    samthunder Private First Class

    Ok, I'm back. I painstakingly ran through the Run and ReadMe First steps (have also already done the specific virus removal for Qoologic) but I'm still infectious. I had to cheat on two steps, I can't install Hijack this the absolute correct way because my PC is unusable in normal boot mode (It seemed to install and run fine in Safe mode so hopefully my logfile is still usable). I also can't use CounterSpy due to this, and I don't have Windows XP SP2 (I know I need to upgrade).

    I also have an error log from the a2 antivirus. It seemed to occur exactly when I tried to delete the trojan file. I'll post this as an attachment on a second post if requested. I have the full version of Spyware Doctor and PC-Tools antivirus but Spyware doctor finds, detects, and cleans, then automatically restarts, only to find the same problems again. PC-Tool AV hasn't loaded properly since I bought it.

    Other than that I've run all kinds of cleaning scans for both trojans and spyware as per suggested on this site, but the Qoologic is the main persistent one. PandaScan found and deleted it, as did BitDefender, but it just keeps popping up. Here are my logfiles, and I apologize in advance if I'm still missing some point of etiquette, I understand the necessity of standardization so that your valuable time isn't wasted, just let me know if I screw something up.

    Appreciate the patience and guidance,
    Sam
     

    Attached Files:

    Last edited: Jun 21, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What removal steps for Qoologic. There is no written removal procedural. There is only a detection procedure that is used to locate hiidden files. And speaking of that. Why did you edit your logs out or your first message. Now the FIndQool log that we need to workup a fix is gone.

    If you purchased this and it does not fix problems that it finds and you cannot install another piece, you should be complaining to PC-Tools and telling than that you want your money back or an application that actually works. Unless people get on software companies to actually start fixing something more complex than cookies and everyday trivial malware, their products are never going to be even as useful as the free tools that we use to remove this stuff. If we can work up procedures to remove this malware, why can't they?

    You did not pay attention to Step 3 of the READ ME. Read it again. You have PC Tools antivirus and Antivir installed. You must not have mutliple antivirus applications installed. This could be part of your problems with PC Tools.

    Please run this Virtumonde aka Trojan Vundo Removal and attach the requested log.

    Also please repost a new FIndQool log to replace the one that was deleted. Make sure you get a new report since running the READ ME could have changed some things.
     
    Last edited: Jun 21, 2006
  5. samthunder

    samthunder Private First Class

     

    Attached Files:

    Last edited: Jun 21, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But again it is not a removal procedure and you complained about
    What I was merely stating is the obvious and that is you are still infected because nothing was removed yet. It was only a scan.

    Your very first message included a log from FindQool that you since deleted. See the date you edited the thread (2 days after inital post). You had already posted the log. That is what I was referring to and I was wondering why you edited the message to delete the log.

    The READ ME does not say anything about installing AntiVir and it also specifically states in step 3 to only have one antivirus installed. It does not matter whether one is broken or not. Installing more than one can cause problems for any antivirus application. Uninstall PC-Tools antivirus NOW!

    It could be causing a problem. We'll see. It could become necessary to perform manual cleaning steps if VundoFix does not run properly.

    I'll be working up a fix for you to try as soon as possible tomorrow. But right now I need some sleep.
     
    Last edited: Jun 22, 2006
  7. samthunder

    samthunder Private First Class

    I appreciate the help, let me know if you come up with anything.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\Program Files\??crosoft.NET\mshta.exe
    C:\WINDOWS\ms0632871883292006.exe
    C:\WINDOWS\system32\arpa.dll
    C:\WINDOWS\system32\hgggded.dll
    C:\WINDOWS\system32\dcggs.dat
    C:\WINDOWS\system32\xerdhr.exe
    C:\WINDOWS\system32\onihh.exe
    C:\WINDOWS\system32\elqdyaf.dll
    C:\WINDOWS\system32\yjpkrwt.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\plden.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes. (You may not see these! If not, just continue.)
    C:\Program Files\outlook\outlook.exe
    C:\WINDOWS\FNTS~1\javaw.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\onihh.exe
    F2 - REG:system.ini: UserInit=userinit.exe,yjpkrwt.exe
    O2 - BHO: (no name) - {AEB204FC-ECCB-4EE2-9B64-D1D21240EBC1} - C:\WINDOWS\System32\jkklj.dll (file missing)
    O4 - Global Startup: strings.exe
    O20 - AppInit_DLLs: arpa.dll C:\WINDOWS\System32\arpa.dll
    O20 - Winlogon Notify: jkklj - C:\WINDOWS\System32\jkklj.dll (file missing)

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):
    C:\Documents and Settings\Samn\Local Settings\Temp <--- delete all files in this Temp folder
    c:\windows\system32\1024 <--- the whole folder
    C:\WINDOWS\ms0632871883292006.exe
    C:\WINDOWS\system32\arpa.dll
    C:\WINDOWS\system32\hgggded.dll
    C:\WINDOWS\system32\dcggs.dat
    C:\WINDOWS\system32\xerdhr.exe
    C:\WINDOWS\system32\onihh.exe
    C:\WINDOWS\system32\elqdyaf.dll
    C:\WINDOWS\system32\yjpkrwt.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\plden.exe

    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new log from FindQool

    Also tell me how things are working!
     
  9. samthunder

    samthunder Private First Class

    Thanks for the help, but I still have a couple problems I think. Everything went fine until I hit the "fix" button for the HijackThis! entries. I'll attach the error message. I had all browsers closed etc...

    Also, when I went into Windows Explorer to manually search for and delete files, the Temp folder still had a LOT of entries in it, and I manually selected them all and right-clicked to choose delete, but the Explorer froze. Can I re-use Killbox to delete the temp folder, or just delete the whole folder? (Windows will make a new one right?)

    I'm off to watch the Switzerland game, but I appreciate the help you've given, looks like I'm nearly there.....
     

    Attached Files:

  10. samthunder

    samthunder Private First Class

    I finished off the rest of the instructions (I deleted the whole Temp folder to work around the problem I had above) and this is the first time I've been able to use my PC in normal boot mode! So at least we're making progress. Here are the requested logs. I still got a message about a virus detected from Avira Antivirus: "C:\progra~1\crosof~1.net\mshta.exe" which is detected as TR/Dldr.PurityScan.CQ.1 but I was able to delete it with the program (with the Qoologic it would always keep re-appearing every five seconds even if I deleted it).

    Anyways, here are the requested logs, let me know what kind of shape I'm in. Thanks!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about the error message. The fixed worked anyway.

    NO!!!!! Do not delete the Temp folder Windows will not let you anyway since a couple files will always be in use by the OS. You need to delete them a few at a time. Sort the folder by date and try deleting everything that is not from today or yesterday first. That should work.

    You have picked up some new malware. Procedure to follow in next message.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\PROGRA~1\CROSOF~1.NET\mshta.exe
    C:\WINDOWS\ICROSO~1.NET\MCONFI~1.EXE

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: (no name) - _{51F40E7F-C69F-E46F-999F-91FC2C82B6C4} - (no file)
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [wvvuhp] C:\WINDOWS\System32\xerdhr.exe reg_run
    O4 - HKCU\..\Run: [87fd8b45.exe] C:\Documents and Settings\Samn\Local Settings\Application Data\87fd8b45.exe
    O4 - HKCU\..\Run: [Ouua] "C:\PROGRA~1\CROSOF~1.NET\mshta.exe" -vt yazb
    O4 - HKCU\..\Run: [Aejlkla] C:\WINDOWS\ICROSO~1.NET\MCONFI~1.EXE
    O4 - HKCU\..\Run: [tscvi] C:\WINDOWS\System32\xerdhr.exe reg_run

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\System32\xerdhr.exe
    C:\Documents and Settings\Samn\Local Settings\Application Data\87fd8b45.exe
    C:\Program Files\CROSOF~1.NET\mshta.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  13. samthunder

    samthunder Private First Class

    You asked how things are working now, and overall they're working 150% better! Thank you very much for the help thus far. I am hesitant to start celebrating till you tell me its ok though. Here's the logfile from my most recent HijackThis! scan.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the only remaining issue is a non-malware issue.

    You appear to be running two antivirus applications (PC Tools AV and Antivir). Per step 3 of the READ ME, you must only install one antivirus application. Uninstall one of them.

    Are PC Tool AV and SpywareDoctor paid versions?
     
  15. samthunder

    samthunder Private First Class

    Hmm, I swear that I used "Add/Remove Programs" to get rid of PC Tools Antivirus since it didn't seem to be working properly. Spyware Doctor and PC Tool Antivirus are paid versions, so I should probably remove Avira Antivirus and re-install PC Tool Antivirus to make sure it works properly now. After I do that should I do the system restore reset procedure?

    Update: I am not showing PC Tools AV in my "Add Remove Program" window.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have HJT fix the below line:


    O4 - HKCU\..\Run: [PCTAVApp] "E:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN

    Then delete the E:\Program Files\PC Tools AntiVirus folder if found!

    If you really want to retry PC Tools AV, uninstall Antivir, REBOOT, and then after reboot, reinstall PC Tools Antivirus. If it does not work, uninstall it, reboot, and then reinstall Antivir!


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  17. samthunder

    samthunder Private First Class

    Yeah I re-installed the anti-virus from PC tools, seeing as how I already paid for it. If I had known I could get such good help from here I would have stuck to the Avira (since it was free) but I was panicked and bought the first thing that seemed reputable and claimed to be able to fix my problem :mad: . Thanks for the help, I'll definitely be coming back to the site for some hardware fixes.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    So can I assume everything is working okay now?
     
  19. samthunder

    samthunder Private First Class

    As far as Malware is concerned, everything is working great. I may be stopping back in various other forums to fix a few other minor issues now that I know where to ask. I've had a few PC maintenance issues on my to-do list forever. Again, thanks for the help.

    Sam
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds