This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't remove Qoologic

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm using a family PC, I was informed that we had started to get a rediculous amount of pop-ups. It took me all of yesterday to figure out it was 'Look2Me', so I went online, searched a few forums, discovered how to delete it, and I did so. But I'm still stuck with Qoologic, which gives me about 5-10 minutes of freedom, then bombards me with ~10 pop-ups! >:( (there's also a program called Duce6.exe running when I check task-manager. I don't know what it is, but it looks suspicious to me…)

I spent all last night, and today morning trying to fix it, and finally decided to put a hijocklog here.

Programs I've run without success have included

Ad-Aware SE
Spybot S&D
Ewido anti-spyware (detects Qoologic, but has an error while quarantining)
Brute Force Unistaller

Please help, this frustration is getting the best of me, and I do not want to resort to pulling out my hair with my bare hands. I like my hair…


——————————————————————



Logfile of HijackThis v1.99.1
Scan saved at 2:36:52 PM, on 8/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dnpqpv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\twhup.exe
C:\WINDOWS\System32\twhup.exe
C:\WINDOWS\System32\twhup.exe
C:\WINDOWS\win320841-3313643.exe
C:\WINDOWS\sys031364341-33.exe
C:\WINDOWS\win32091-33136434.exe
C:\WINDOWS\sys0231364341-3.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Qoofix & Ewido\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\twhup.exe
F2 - REG:system.ini: UserInit=userinit.exe,ernyacl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [rftwkhsA] C:\WINDOWS\rftwkhsA.exe
O4 - HKLM\..\Run: [cetiot] C:\WINDOWS\System32\dnpqpv.exe reg_run
O4 - HKLM\..\Run: [jyc47198] RUNDLL32.EXE w4389d25.dll,n 00347195000000034389d25
O4 - HKLM\..\Run: [win320841-3313643] C:\WINDOWS\win320841-3313643.exe
O4 - HKLM\..\Run: [sys031364341-33] C:\WINDOWS\sys031364341-33.exe
O4 - HKLM\..\Run: [win32091-33136434] C:\WINDOWS\win32091-33136434.exe
O4 - HKLM\..\Run: [sys0231364341-3] C:\WINDOWS\sys0231364341-3.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKCU\..\Run: [rikk] C:\PROGRA~1\COMMON~1\rikk\rikkm.exe
O4 - HKCU\..\Run: [ybbjq] C:\WINDOWS\System32\dnpqpv.exe reg_run
O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"
O4 - HKCU\..\Run: [Jlqfdm] C:\Documents and Settings\Owner\Application Data\?racle\l?ass.exe
O4 - Global Startup: vucrv.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.adsextend.net
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.adsextend.net (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150352906453
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8467C057-CE3A-4957-A5D5-D50B1DDD4CDD}: NameServer = 205.171.3.65,205.171.2.65
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Qoofix & Ewido\ewido anti-spyware 4.0\guard.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI