Qhosts.apd question and removal?

Discussion in 'Malware Help (A Specialist Will Reply)' started by questionz, Mar 21, 2005.

  1. questionz

    questionz Private E-2

    i previously posted without following the directions of the board and i apologize. hopefully this will make up for my lack of preparation.

    when i start my computer, i receive the following message from my mcaffee security center:
    "trojan has been detected and cleaned. The file "C:\windows\system32\drivers\etc\hosts" was infected by the "Qhosts.apd" trojan and has been cleaned. it then proceeds to ask me to scan for other viruses and nothing else shows up. Why does this continue to tell me this everytime i start my computer if there isnt a problem anymore? Below is all of my information.

    Operating system - windows xp home edition
    memory - 320 MB (SDRAM)
    CPU - Intel pemtium IIIE 1000 MHz
    Hard Drive - 28615 MB (24,338 MB free)

    if u need any other information or a log from hijack this, please reply.

    thank you very much for any help
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume you are talking about this thread:
    http://forums.majorgeeks.com/showthread.php?t=58391

    You should have waited for a response.

    But here is the process to follow:
    To help us to best help you, please follow the steps below closely and in the order given and do not skip anything. If you have any difficulty, please post back letting us know what steps you have completed, what you found while doing the scans if anything along with details about any problems you may have encountered in completing the steps. The more details you can provide the better. Don't be afraid to ask for additional help if you don't understand something!

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. questionz

    questionz Private E-2

    i have run all of the scans and nothing was really found.

    attached is my logfile from hijack this.

    thanks for any information
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I look at the rest of the problems in your log please do the following to fix a bug SpyBot's Ignore Products defaults settings:

    I want you to run SpyBot and get into the Advanced mode by selecting Mode and then
    Advanced mode. Then select Settings and the in the left column select Ignore Products.
    In the right window pane make sure the All products tab is selected. Then in that
    window, right click your mouse and choose "Deselect all". Now in the left pane click
    at the top on SpyBot S&D and then choose Search for Updates. Download any updates
    required. Now click Check for Problems. Fix any that are found.

    Let me know if it finds and fixes anything. If it does fix anything (in particular new.net), post a new HJT log.
     
  5. questionz

    questionz Private E-2

    i ran spybot and you were right. new.net came up but it said it was having a problem deleting it because it could possibly still be in memory and asked me to restart my computeer and run it again. it also deleted one entry of "mediaplex".

    i will post my log once i delete this new.net
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay if necessary re-run Spybot in safe mode.
     
  7. questionz

    questionz Private E-2

    i ran spybot again and it was able to remove the three cases of new.net


    but

    as the comp started up, i received the message from mcaffee again that my comp was infected with a file. could it b possible that all of the changes had not taken affect yet because i had just ran the spybot? does the computer have to restart again before that notice goes away? anyway, here is my logfile attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Patience! That's because we are not done yet. I need to get the new log after fixing the previous stuff with Spybot. I'll be back with a fix in a minute. Try to hang around and maybe we can finish this off right now.
     
  9. questionz

    questionz Private E-2

    sorry bout that....and im not tryin to rush anything i just wanted to give you the heads up about the following even though you are probably already aware of it.

    i clicked on tools and went to internet options and the following came up:

    "this operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator."

    if this is usual, dont mind my post. i just wanted to give you the heads up in case you needed to know this.

    thanks again for everything
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Let's address what we can see first. Then tell me if you still have the same problem you just mentioned about security settings.

    Do you use DIGstream? I would recommend not loading it at startup. Just run it when you want to use it. But that decision is yours.
    C:\Program Files\DIGStream\digstream.exe

    Is the aimtoolbar search setting something that you put it? If not, make sure you add them to the list below of items to fix.
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\Winzip32.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Winzip Archiver] Winzip32.exe
    O4 - HKLM\..\RunServices: [Winzip Archiver] Winzip32.exe
    O4 - Startup: PowerReg Scheduler.exe

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\Winzip32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. questionz

    questionz Private E-2

    great news!

    i re booted the comp in normal mode and the warning from mcafee did not come up!

    also, my internet options are working too but you probably knew they would.

    one last thing before i post my log...

    at the bottom of my browser it says the following:

    "WYSIWYG Editor initialized for Internet Explorer in 0.19 seconds."

    is this anythin i should be concerned about.

    thanks
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks clean now but you never answered my questions about DIGStream and also these two lines:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    The message for IE related to WYSIWYG Editor initialized for Internet Explorer in 0.19 seconds is normal!
     
  13. questionz

    questionz Private E-2

    i deleted the toolbar a couple minutes ago and i also uninstalled digstream


    am i all set do you think?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not yet! Your clean but to help you stay that way, you need to follow all the steps in the below link (or their equivalents):

    How to Protect yourself from malware!

    After installing one of the firewalls listed there, you must disable the firewall that is built-in to WinXP SP2 to avoid conflicts. The one in SP2 is not good enough. That's why we need to replace it.
     
  15. questionz

    questionz Private E-2

    how do i go about doin the disable?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. questionz

    questionz Private E-2

    okay i have downloaded the first firewall from your list and i have turned off windows firewall.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But complete all the steps! At least the ones not completed yet. And make sure you check out FireFox.
     
  19. questionz

    questionz Private E-2

    i have done all of the following and i will install firefox tomorrow....its gettin late and i gotta work in the morning...hey, i appreciate all of your help greatly...keep up the good work and thanks again...just leave me a message if i need to do anything else...


    thanks alot
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! After completing all those steps you should be finished. But remember that none of these things protect perfectly. Security start with you. Watch what you click on (be careful when to click Yes or No) and be careful where you surf.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds