Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - Review these logs posted in the Security & Safety forums; Today when I started browsing I got the following pop-up over and over: "Your PC is infected by trojan win32/Qoologic It's dangerous for your system (Critical files can be lost!) ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-29-2007
DrD's Avatar
DrD DrD is offline
Bronze Member
 
Join Date: Dec 2007
Posts: 10
PC Experience: Experienced
DrD - See this Members User comments on their Profile page
Default Review these logs

Today when I started browsing I got the following pop-up over and over:

"Your PC is infected by trojan win32/Qoologic

It's dangerous for your system (Critical files can be lost!)
Click OK to download the antispyware programs to clean
your system (Recommended)!"

I believe that my son may have allowed an install of an active-x to try to view a video on the internet last night - then got the pop-up and just shut down the computer -

I closed the pop-up and tried to scan with Norton security (free install on this computer) - found only some cookies which were removed (they come back all the time)

Pop ups would not stop appearing - found this site and followed the instructions - attaching the logs - note that AVG found lots of stuff, but no log file was created - I may have repaired before saving the log

So far after rebooting from the CCleaner step I have seen no further pop ups.

Did this clean the sytem? If not, what is the next step.

Thanks

David


  #2  
Old 12-30-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 2,534
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: Review these logs

You are using an outdated version of HijackThis. Please uninstall from Add/Remove programs, and delete your current version.

Please download HijackThis to your desktop.. http://www.trendsecure.com/portal/en...HJTInstall.exe
Alternate link
http://download.bleepingcomputer.com...HJTInstall.exe
This program will help us determine if there are any spyware/malware on your computer. Double-click on the file you just downloaded.
Click on the "Unzip" button to install. It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Upon install, HijackThis should open for you.
Should it not open, navigate to C:\Program Files\Trend Micro\HijackThis and double click on HijackThis.exe
1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Post the hijackthis.log file here. Do not fix anything in HijackThis since they may be harmless.
===================================
Download SDFix from here and save it to your desktop.

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
In Safe Mode, right click the SDFix.zip folder and choose Extract All,
Open the extracted folder and double click RunThis.bat to start the script.
Type Y to begin the script.
It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum.

=========================================
This will help to identify malware on your system.
Please download Combofix from any of these locations:
Here
or
Here
Save ComboFix to the desktop and please ensure that you disable realtime security/virus programs that monitors your PC while CF is running.
1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Copy and Paste the contents of that log in your next reply with a new hijackthis log. Do not use Code or html unless asked for.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
Caution...Never run and remove files using ComboFix without being supervised by a security analyst.


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #3  
Old 12-30-2007
DrD's Avatar
DrD DrD is offline
Bronze Member
 
Join Date: Dec 2007
Posts: 10
PC Experience: Experienced
DrD - See this Members User comments on their Profile page
Default Updated HJT logs - and more questions - thanks

Thanks for the reply Pancake - Here is an updated HJT log -

I have not taken the other steps recommended because after doing the initial steps previously described, the outward indications of the malware have completely disappeared -

I know this does not necessarily mean I am clean, but am concerned about loading more and more things.

Can you determine from the HJT log if I need further work on this issue?

Thanks in advance for your reply

David


  #4  
Old 12-30-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 2,534
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: Review these logs

Ok.Its not a wise choice but it is your decision.My personal knowledge of this virus is that it still leaves active files on your system and would advice continuing on with the cleanup


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #5  
Old 12-31-2007
ih8bills's Avatar
Tech Team Leader
My PC
 
Join Date: Feb 2006
Location: coastal Rhode Island
Posts: 4,129
PC Experience: More Stubborn than any PC
ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page
Default Re: Updated HJT logs - and more questions - thanks

Originally Posted by DrD View Post
Thanks for the reply Pancake - Here is an updated HJT log -

I have not taken the other steps recommended because after doing the initial steps previously described, the outward indications of the malware have completely disappeared -

I know this does not necessarily mean I am clean, but am concerned about loading more and more things.

Can you determine from the HJT log if I need further work on this issue?

Thanks in advance for your reply

David
Dr.D--that is a nasty little bug--

I second that you should follow up on cleanup... Pancake is very good-- he will remove all traces without further problems.
If you'll notice ... the ASAP and Unite links at the bottom of his posts-- these are respected Certifications in Malware removal circles.

Just My 2 Cents worth.


__________________


Without music, life would be a mistake
Friedrich Nietzsche

Last edited by ih8bills; 12-31-2007 at 01:45 AM.
  #6  
Old 01-03-2008
DrD's Avatar
DrD DrD is offline
Bronze Member
 
Join Date: Dec 2007
Posts: 10
PC Experience: Experienced
DrD - See this Members User comments on their Profile page
Default Problem running script

I downloaded and extracted SDFix and rebooted in safe mode. When I try to execute the RunThis.bat I get a very quick blue background window popping up and then disappearing.

I know a bit about scripting and .bat files, so I made a copy and edited the script to print some test text when exiting and pause for input. It looks like the beginning part of the script is jumping right to exit.

Could this be because I am running Vista, and the OS checks at the start of the script are failing?

Thanks in advance



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Resolved] Please review HJT logs elvin815 [Fixed] Hijackthis! Logs 13 05-18-2006 01:02 AM
[Resolved] Please review HijackThis logs... elvin815 [Fixed] Hijackthis! Logs 1 05-07-2006 11:01 AM
where did you get trained to read HJT logs? coltm4carbine The Lounge 3 09-22-2005 09:40 PM
[Tech News] MPAA sifts through tracker logs for lawsuit ammo merlin The Lounge 2 08-29-2005 09:32 PM
HiJack This! Logs Go One Forum Up! Thank You! Spaceman3750 Spyware / AdWare 0 08-02-2005 08:53 PM


All times are GMT +1. The time now is 10:55 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top