trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by chrisss, Dec 30, 2005.

  1. chrisss

    chrisss Private E-2

    ewindo came up clean with no infections
    here is the winpfind log.
    also here is the log for my start up folder. what has to stay enabled in the start up and which ones can be unchecked?
    also im still in safe mode and i havent rebooted yet. i turned off system restore. should i turn it back on and boot in normal mode? is there anything else i should do?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run ExplorerXP (not windows explorer) and look for this: C:\WINDOWS\qohquuytcl.exe

    It is in your Windows directory and you need to fix it and delete it. Do that now while still in safe mode.
     
  3. chrisss

    chrisss Private E-2

    i must be losing my mind. i cant find it
     
  4. chrisss

    chrisss Private E-2

    when i look in explorerxp i go to c then windows then i look for "q" but it goes from
    pss to registeredpackages
    the isnt anything that begins with q
    i did a search for qohquuytcl and nothing comes up
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and extract Pocket KillBox to its own folder some place you can find it.

    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filename into KILL BOX. Check mark the box that says "Delete on Reboot" Now click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click YES and it will reboot.

    C:\WINDOWS\qohquuytcl.exe

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot into NORMAL MODE and post a new WinPfind log and tell me how the steps went.
     
  6. chrisss

    chrisss Private E-2

    i did this
    Run Killbox.exe. Paste the below filename into KILL BOX. Check mark the box that says "Delete on Reboot" Now click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click YES and it will reboot.

    C:\WINDOWS\qohquuytcl.exe

    then i booted in normal and ran the scan. i can see the file listed in the scan but i cant find it in explorer
     

    Attached Files:

  7. chrisss

    chrisss Private E-2

    i did a search and it found

    qohquuytcl.exe c:windows 97 kb application
    it has a funny icon in front of it. it looks like 5 different colored circles connected together in a circle. (looks like a flower)

    but its not listed in explorer
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Double check the below settings to make sure each one is correctly set.

    - Right Click Start.
    - Select Explore
    - Select the Tools menu and click Folder Options.
    - Select the View Tab.
    - Under the Hidden files and folders heading select Show hidden files and folders.
    - Uncheck the Hide extensions for known file types option.
    - Uncheck the Hide protected operating system files (recommended) option.
    - Click Apply.
    -Click OK.
     
  9. chrisss

    chrisss Private E-2

    it is correctly set

    should i try to delete qohquuytcle.exe it in the search results box?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! That seems rather strange. If Search is showing the file and you have the Explorer settings correct, it should be showing there too.

    In the search window, right click on the file and select delete. Does that work?
     
  11. chrisss

    chrisss Private E-2

    when i highlight it it says that its description is
    the best offers
    created 1/2/04
     
  12. chrisss

    chrisss Private E-2

    it deleted it. ill run another search and see if it comes back. what is that icon? i never saw it before
     
  13. chrisss

    chrisss Private E-2

    it showed up in the ryc. bin. i deleted it. i ran another search and it didnt come up. will it be back if i reboot?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that is what we need to find out! But at least you know how to find it. So reboot into normal mode and let's see what happens.

    The icon must be something related to BestOffers. This is part of what you had in the very beginning (nail.exe and the renaming trojan). That is why I kept working on trying to delete all these entries. They are all related.

    I don't understand why killbox did not delete it.
     
  15. chrisss

    chrisss Private E-2

    i figured i would run kill box again to delet it on reboot. this message came up

    pendingfilerenameoperations registry data has been removed by external process!

    i havent rebooted yet
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But there was nothing to delete because you already deleted it. Just reboot the PC into normal mode and let's see what happens.
     
  17. chrisss

    chrisss Private E-2

    it didnt show up in the search .here is the log
     

    Attached Files:

  18. chrisss

    chrisss Private E-2

    here is my hijack log
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's clean! No do you see what I kept on insisting that it was there and asking to delete it? ;)

    Is everything working okay now? If so, time to proceed to the below:

    How to Protect yourself from malware!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was referring to the WinPfind log being clean! You HJT log is basically clean althought I would not allow junk like below to run on my PCs. Some people consider it mild spyware. I just believe it is a waste of resources and I'll check for updates when I want to.


    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
     
  21. chrisss

    chrisss Private E-2

    everything is running great!! yahoo!
    i read about protecting from spyware. i check my security settings they are ok.

    all i have to do is the following:
    8) Uninstall Microsoft Java and Replace with Sun Java
    is that all? should i turn on system restore?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes enable System Restore!
     
  23. chrisss

    chrisss Private E-2

    this log is for message 70. i deleted 3 files in hijack this
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks okay! If later you change your mind about needing those three items for any reason, you can just restore them from the HijackThis backups.
     
  25. chrisss

    chrisss Private E-2

    im done? that great!

    i want to thank you very much for all your time. i appreciate it!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds