Adware-Qoologic (Trojan Downloader)

G

Guest

I have not one clue about computers, and I highly rely upon Windows Defender
to detect and remove any infections my computer may have. It has done a
great job up until I recently. I know have been infected by Adware-Qoologic.
Windows Defender is able to detect the adware and knows what it is but it
can't get rid of it.

I select to remove Qoologic through Windows Defender. After I reboot my
computer as suggested, the adware comes right back. In fact, it never left.
I have read several of post on different sites but none of it really makes
much sense to me.

Does anyone have and suggestions? Has anyone gone through the same problem
that has some kind of idea what I should do?
 
G

Guest

Hello Amie,

Have a look at this article.It may be relevant to your problem.

Subject: audphp.exe = qoologic
5/5/2006 5:18 PM PST
By: adams667
In: signatures

Subject: Detected trojan.startup.nameshift.fl
11/4/2005 1:34 PM PST
By: Marcus Smaby
In: signatures

Subject: Trojan.Startup.NameShifter.d3do Trojan
From: "Medders" <[email protected]>
9/20/2005 11:22:00 AM
In General forum

http://www.atribune.org/content/view/28/1/

For the benefit of the community reading this post, please rate the pºst.

I hope this post is helpful.

Let us know how it works ºut.

Еиçеl
 
G

Guest

Greetings. Pardon me for butting in on the conversation..... I've been
experiencing the same problem with Qoologic Adware (argh!). I followed your
link and used the Look2Me-Destroyer. After completion, I scanned again with
Windows Defender.

Now the darn Qoologic shows up as being detected by both scanning and
real-time protection. It seems that the L2M software doesn't really work.
Any new suggestions?

Oh, an interesting note. Everytime I reboot my computer, it tries to bring
up in IE, but never succeeds, the following:

http://iesettingsupdate/

I'm guessing that it is linked to the Adware, but don't really know.

Any suggestions would be greatly appreciated.

Regards,

Marci
 
G

Guest

Hello Marci,

Download the following and run a thorough scan in safe mºde:

NOTE: Make certain to update every app before booting into Safe Mode since
you WILL NOT have access to the Internet from Safe Mºde.

http://cwshredder.net/cwshredder/cwschronicles.html

http://www.atribune.org/content/view/28/1/

Ad-Aware - http://www.lavasoftusa.com
http://www.bleepingcomputer.com/forums/tutorial48.html

Spybot S&D - http://www.safer-networking.org/
http://net-integration.net/index.html

http://www.bleepingcomputer.com/forums/tutorial43.html

http://www.download.com/Destroy-spyware-using-Spybot/1200-2023-5144545.html?tag=txt
Make certain to not to select any of the pernament protection for Spybot, as
this can interfere with WD Real-tme Protectiºn.

-and- -or-

This is a AndyManchesta or Ron Kinner case beacuse I cannot find any good
advice within any forum without using HijackThis and to be carefully guided.
Get HijackThis.exe from
http://tomcoyote.org/hjt/hjt199//HijackThis.exe
http://computercops.biz/HijackThis.html

Save it to C:\hjt (new folder) then Open it and select Scan and Save Log.
Note where you saved the log then send it to him as an attachment. Put
Hijack in the subject so he'll know it's not spªm.

Alternatively you can post it on the Dell Forum ªt:

http://forums.us.dell.com/supportforums/board?board.id=si_hijack

Put Ron in the subject so he will see it. You do not need to have a Dell to
post but you will need to register.

Ron Kinner at rkinner(AT)att.net (Replace (AT) With @)
Microsoft MVP 2004 & 2005

AndyManchesta(AT)hotmail.co.uk (Replace (AT) With @)
AndyManchesta at andyorange334(AT)hotmail.com (Replace (AT) With @)
AndyManchesta(AT)hotmail.com (Replace (AT) With @)
Feel free to mention that I sent you.
Еиçеl

For the benefit of the community reading this post, please rate the pºst.

I hope this post is helpful.

Еиçеl
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top