Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Members New Posts Donate Unanswered Posts Site Spy Search


Reply
 
Thread Tools
  #1  
Old 30-04-2008, 01:06 PM
Dave Hybrid's Avatar
CJ Administrator
Intel Nvidia
Dave Hybrid is online now
 
Join Date: Apr 2006
Last Online: Today 09:36 AM
Age: 26
Posts: 7,098
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default MSN Email Spam Virus - kqoka.exe

This needs specialist help so evilfantasy, over here mate!

My dad has got a MSN virus that send 100's of emails from his PC a second, can see the avast scanner picking them up.

Internet speed is also non existant.

Have tried everything from virus scans to HJT.

A file called kqoka.exe seems the cause.

Let me know where to start mate, thanks.
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Want your system info in your signature?

Last edited by Dave Hybrid : 30-04-2008 at 01:08 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 30-04-2008, 06:36 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:24 AM
Posts: 4,512
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default MSN Email Spam Virus - kqoka.exe

Try this first.

Download MsnVirRem.exe to your desktop from one of the following mirrors.
  • First close any other programs you have running as this will require a reboot
  • Double click MsnVirRem.exe to run it
  • Once open, click the button labeled Search and Destroy
    • Your computer will now be scanned for Infected Files
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the REBOOT Button.
  • After the Reboot, you WILL receive file not found errors (usually 4) please acknowledge them and continue.
  • A Message should popup fromMsnVirRemif not, double click the program again and it will finish
Please Post the contents of C:\msnvirrem.log along with a fresh HijackThis log

----------

Also post a Hijackthis log.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 30-04-2008, 09:01 PM
Dave Hybrid's Avatar
CJ Administrator
Intel Nvidia
Dave Hybrid is online now
 
Join Date: Apr 2006
Last Online: Today 09:36 AM
Age: 26
Posts: 7,098
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default MSN Email Spam Virus - kqoka.exe

Managed to sort this now mate, had to delete the file in the system32 folder as well as deleting the entry's in hijackthis.

Thanks all the same fella.
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 30-04-2008, 09:07 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:24 AM
Posts: 4,512
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default MSN Email Spam Virus - kqoka.exe

Dave, it would be good to run the tool as well as SDFix. I have seen this virus found in up to 10 different locations from file folders to system files as well as windows folders. It's a pretty crafty bugger.

Download SDFix.exe and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard).
  • Finally add the contents of the Report.txt in your next post.
You don't need to post any logs, I know you are a fair hand at malware removal when you need to be
__________________
.
.

Last edited by evilfantasy : 30-04-2008 at 09:07 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 30-04-2008, 10:05 PM
Dave Hybrid's Avatar
CJ Administrator
Intel Nvidia
Dave Hybrid is online now
 
Join Date: Apr 2006
Last Online: Today 09:36 AM
Age: 26
Posts: 7,098
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default MSN Email Spam Virus - kqoka.exe

ok mate, will do, thank you!
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 01-05-2008, 09:04 AM
philthomas's Avatar
CJ Donator
AMD Nvidia
philthomas is offline
 
Join Date: Nov 2007
Last Online: Yesterday 11:57 PM
Posts: 1,512
iTrader: (0)
philthomas will become famous soon enoughphilthomas will become famous soon enoughphilthomas will become famous soon enoughphilthomas will become famous soon enough
Default MSN Email Spam Virus - kqoka.exe

Is this the Desktop you flogged to your Dad Dave ? ......
I dunno ..... thought you might at least of cleared all the spyware, before giving it to him
__________________

My System: Home Build

CPU(s):
AMD 64 x 2 Dual Core 5200+ 2.60GHz
Motherboard:
Asus M2V Rev 1.
RAM:
4gb
Graphics Card(s):
NVIDIA GeForce 7300 GS
Sound Card:
5.1 Reatek On-Board
Hard Drive(s):
250 gb SATA & 400gb SATA
Optical Drive(s):
Pioneer 110 x 2
Case / PSU:
Stock / 550w Silent
Cooling:
Stock
Network / Internet:
10/100 Nic / 20MB Virgin Cable
Monitor(s):
19" TFT
Operating System(s):
Vista Ultimate x32 & XP Pro x32 Dual Bt.

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 01-05-2008, 09:16 AM
Dave Hybrid's Avatar
CJ Administrator
Intel Nvidia
Dave Hybrid is online now
 
Join Date: Apr 2006
Last Online: Today 09:36 AM
Age: 26
Posts: 7,098
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default MSN Email Spam Virus - kqoka.exe

Na it's his old one, mine is squeaky clean.
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Need Help---Email damaged by virus Rookssailor Virus, Spyware & Security 39 14-02-2008 08:20 PM
Weird email virus? or not? Dave Hybrid Virus, Spyware & Security 19 11-08-2007 08:30 PM
AOL / AIM Email Assistence Please - Email Display Meisje J 26 Email, VoIP & IM Discussion 1 19-03-2007 09:11 PM
Is my Yahoo e-mail site and e-mails virus, spam, epaysystems Email, VoIP & IM Discussion 2 18-03-2007 02:38 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.