Recommended Driver Scanner

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] popups, slow down, and qoolaid

[Fixed] Hijackthis! Logs - [Fixed] popups, slow down, and qoolaid posted in the Security & Safety forums; my pc got slammed with alot of adware spyware and viruses. how do i get rid of them because my mcafee doesnt detect anything is wrong. waste of $50....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 03-21-2006
Bronze Member
My PC
 
Join Date: Mar 2006
Location: WI
Posts: 15
makospawn - See this Members User comments on their Profile page
Default [Fixed] popups, slow down, and qoolaid

my pc got slammed with alot of adware spyware and viruses. how do i get rid of them because my mcafee doesnt detect anything is wrong. waste of $50.


  #2  
Old 03-22-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there Makospawn , welcome to PCHF.

If you follow the instructions in the "Prework" link (below in my sig) and post the two resulting log files then i'll have a look what needs to be done to get youre pc running smooth again.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 03-22-2006
Bronze Member
My PC
 
Join Date: Mar 2006
Location: WI
Posts: 15
makospawn - See this Members User comments on their Profile page
Default logs info

attached are the logs
Attached Files
File Type: txt Scan report_20060321.txt.txt (1.4 KB, 2 views)
File Type: log hijackthis.log (6.8 KB, 2 views)


  #4  
Old 03-22-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

In this case don't blame Mcafee , i dont think any normal AV can remove these buggers you have on there. But we'll get it clean.


First please download and run this tool:

http://securityresponse.symantec.com...r/FxDtcmtb.exe


Then boot in safemode (hit f8 when booting up) and fix these with hijackthis:
(if still present)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\qfwew.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,caeihwb. exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard4.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad4.exe
O4 - HKLM\..\Run: [newname] C:\windows\newname4.exe
O4 - HKLM\..\Run: [amkrwp] C:\WINDOWS\system32\bvgawr.exe reg_run
O4 - HKCU\..\Run: [wjrsx] C:\WINDOWS\system32\bvgawr.exe reg_run
O4 - Global Startup: sdrbd.exe
Then delete the files above in bold , and do a manuall search for these files:

caeihwb.exe
sdrbd.exe

Delete all you find , and after that run Ccleaner again.

Reboot to regular mode and please do a Panda active scan here:

http://www.pandasoftware.com/products/activescan

and save the log from it.


Please Download RKFiles.zip

Create a new folder C:\Antispyware\RKFiles
Extract the contents of RKFiles.zip into the new folder you just created.

Next, Create a new Folder on Desktop. Name that Folder QOOLOGIC
Please download Findqoologic into the new Folder, and then unzip it into the new Folder.

Now restart to safe mode again.

Open the C:\Antispyware\RKFiles folder
Double click on RKFILES.BAT
Give it time to run. this may take a while.
Save the text file it creates.
It should save by default to C:\Log.txt

Next, open the QOOLOGIC Folder and Locate and double-click the Find-Qoologic.bat file to run it.
Wait until a text file opens, post it in a reply to your thread after doing the rest of what follows here.
It'll take a while to run a full scan so please be patient.

When done please post a new hjt log , the Panda log , the Findqoologic log and the RKfiles log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 03-22-2006
Bronze Member
My PC
 
Join Date: Mar 2006
Location: WI
Posts: 15
makospawn - See this Members User comments on their Profile page
Default more logs

more logs attached.
Attached Files
File Type: txt hijackthis22.txt (4.9 KB, 1 views)
File Type: txt Activescan.txt (4.3 KB, 1 views)
File Type: txt report.txt (1.2 KB, 1 views)
File Type: txt log.txt (670 Bytes, 1 views)


  #6  
Old 03-22-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Download Pocket Killbox:
http://www.atribune.org/downloads/KillBox.exe

Boot in safemode , start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)

Copy this list into the windows clipboard:


C:\WINDOWS\SYSTEM32\BVGAWR.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\sdrbd.exe
C:\WINDOWS\keyboard41.dat
C:\WINDOWS\R3JlZ29yeSBELiBHdWVudGhlcg
C:\WINDOWS\system32\gsudj.dat
C:\WINDOWS\system32\qfwew.exe
C:\WINDOWS\BQCLVV.DAT


Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
BE SURE TO HIT F8 AGAIN WHILE BOOTING UP TO BOOT IN SAFEMODE AGAIN!


copy the text in the quote below, and paste it into a blank notepad window.
Save it as Qoologic.reg and in the "save as" type box choose "all files".

Code:
REGEDIT4
[-HKEY_CLASSES_ROOT\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}] 
[-HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebNexus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9E248641-0E24-4DDB-9A1F-705087832AD6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amkrwp"=-
Double click on the regfile you just made and allow it to merge with the registry.
After that fix these 2 entry's with hjt:

F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\qfwew.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,caeihwb. exe
Manually search for and delete this file:

caeihwb.exe , and run ccleaner again.

Then reboot to regular mode and post a new hjt log made in regular mode , and a new Findqoologic log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #7  
Old 03-22-2006
Bronze Member
My PC
 
Join Date: Mar 2006
Location: WI
Posts: 15
makospawn - See this Members User comments on their Profile page
Default logs

sorry about the PM, here's the logs
Attached Files
File Type: txt report2.txt (1.0 KB, 1 views)
File Type: txt hijackthis33.txt (6.0 KB, 1 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 10:44 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top