Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Think I have VX2/Qoologic


  • Please log in to reply
3 replies to this topic

#1 jsbt

jsbt

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:34 AM

Posted 31 August 2005 - 02:40 PM

Hi there,

After months of tussling with this thing, I have finally come to you, the experts. Or some of the experts, anyway. :thumbsup: Forgive me if this is complicated, I just want to try and give you everything I know, however stupid or silly.

Around March of this year, I ran afoul of what I now believe was at least a VX2/Qoologic virus - I'm not quite sure how that works, as I am only barely techliterate, but it seems to meet all the criteria of what I'm dealing with and some of my spyware killers have ID'ed VX2 before. I ran a battery of programs on this stuff - Spybot, AdAware, HijackThis, Counterspy, Microsoft AntiSpyware - both in Safe Mode and regular, with some good results with the bulk of the trouble. All that's been left, for months now, is some annoying BHOs and intermittent annoying popups. But it is still really annoying.

Recently, I buckled down and decided to ID the problem once and for all, which is what led to me to discover that I think it's the VX2. This then led me to DL Ewido and Killbox (unused so far) - I used Ewido, which found a passel of 'infected' DLL files - I already knew some to be infected or fake, files like 'geeba.dll' and so on that kept respawning or refusing to delete. I was a little rash the first time I used Ewido and let it delete ALL the 'bad' dlls, and so the next time I rebooted I (after a few hours) had big problems with RUNDLL and such (including files like msfv32.dll, com.dll and ps.dll, which seemed to be part of the original OS) which led to a total meltdown. Everything seems okay after a reboot and that's not likely to repeat now, but the virus remains, doing its obnoxious thing.

A half-hour ago I ran HJT again and was shocked to see no evidence of a BHO for the first time in months, and no popups - and then the popups came back after about thirty minutes. So, I dunno what to do here. Forgive me, I wasn't sure whether to post about my problem in here or in the HJT folder, and I will be happy to put my latest (and older) HJT logs in there if asked.

Many thanks for any help. Sorry to go on so long, I just wanted to be as complete as possible. I am running system guards with ZoneLabs, Ewido and Counterspy at the moment.

BC AdBot (Login to Remove)

 


#2 jgweed

jgweed

  • Members
  • 28,473 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Chicago, Il.
  • Local time:11:34 AM

Posted 31 August 2005 - 03:57 PM

I would suggest your posting a new HJT log, and preface the post with the information you provided in the post here. Here are the instructions covering the HJT process:

http://www.bleepingcomputer.com/forums/How...s-Log-t956.html

Regards,
John
Whereof one cannot speak, thereof one should be silent.

#3 jsbt

jsbt
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:11:34 AM

Posted 01 September 2005 - 01:52 AM

Done - put the msg over there plus my HJT log in the HJT folder. My poor post is already on page 3, but I hope someone will address it.

#4 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Members
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the "Logic Free Zone", in Md, USA
  • Local time:12:34 PM

Posted 01 September 2005 - 12:35 PM

Hi JSBT,

The HJT Team Techs view a different listing of the logs by time as posted.
It's not the same general forum list that you see, so the page you see
your log on has nothing to do with responses.

Please be patient there are always a lot of logs in the queue.
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users