Qoologic infection...

Discussion in 'Malware Help (A Specialist Will Reply)' started by cathmomma, May 30, 2006.

  1. cathmomma

    cathmomma Private E-2

    HI,
    I need help in getting rid of qoologic on my computer. I have followed your directions ,running spybot, adaware etc. I also ran suggested programs in the
    qoologic folder.Everything claims to delete the infection, but it keeps replicating, so I know I am missing some files that should be deleted Here is the info on my computer...

    OS Name Microsoft Windows XP Home Edition
    Version 5.1.2600 Service Pack 1 Build 2600
    OS Manufacturer Microsoft Corporation
    System Manufacturer Dell Computer Corporation
    System Model DIM4400
    System Type X86-based PC
    Processor x86 Family 15 Model 1 Stepping 2 GenuineIntel ~1594 Mhz
    BIOS Version/Date Intel Corp. A03, 1/8/2002
    SMBIOS Version 2.3
    Windows Directory C:\WINDOWS
    System Directory C:\WINDOWS\System32
    total Physical Memory 768.00 MB
    Available Physical Memory 339.68 MB
    Total Virtual Memory 1.83 GB
    Available Virtual Memory 1.07 GB
    Page File Space 1.08 GB

    I was unable to run online scans in safe mode, but ran them normally.I am attaching logs in this and next posts. I was able to run everything else in safe mode except for Black light.
    Thanks in advance for your help....
     
  2. cathmomma

    cathmomma Private E-2

    I'm so sorry, I forgot to upload my attachments with the first post...(I am such a twit sometimes...)
     

    Attached Files:

  3. cathmomma

    cathmomma Private E-2

    More logs
     

    Attached Files:

  4. cathmomma

    cathmomma Private E-2

    yet more scan results...:eek:
    I think that's everything, but if you need anything else. let me know....
     

    Attached Files:

  5. cathmomma

    cathmomma Private E-2

    Never mind, I think I cleared it up myself...I just went through all the logs and reports, and used killbox on anything and everything that even looked like a virus...:) I am attaching my latest hjt log, I think it is clean....Thank you anyways....
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes your Qoologic infection appears to be gone.

    However CWShredder should not be running as a service:
    O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\tmf\Desktop\cwshredder.exe (file missing)

    It should be stopped and disabled. There is now reason for this to be running and I'm not sure how you even got it to run like this. It is not part of their program and it does not even require an install. It is just a free standing application that you run when desired.
     
  7. cathmomma

    cathmomma Private E-2

    Hi,
    I don't know what I did to have it run as a service either lol, but I ran hjt again,checked the cwshredder box and clicked fix. Now I checked the services and cwshredder is "disabled". Then I ran it, and it seems to be working fine, so I guess there's nothing to worry about....Thank you for taking the time to review my log and write back, I appreciate it very much.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds