InkofDeath Posted November 3, 2010 Share Posted November 3, 2010 I've searched Google, but there's nothing on how to remove it, or anything about what it is. It's basically resetting all of my browsers to these settings: Homepage: qooqlle.com, custom google search, searches through qooqlle. Relatively annoying. In other hijacks people said to delete the help folder in Windows, yet, that's not how qooqlle is saving itself. Here's my hijack this:[hide]Logfile of Trend Micro HijackThis v2.0.4Scan saved at 3:10:57 PM, on 03/11/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: Normal Running processes:C:\Windows\system32\Dwm[Caution: Executable File]C:\Windows\Explorer[Caution: Executable File]C:\Windows\system32\taskhost[Caution: Executable File]C:\Program Files\Razer\Lycosa\razerhid[Caution: Executable File]C:\Program Files\Razer\DeathAdder\razerhid[Caution: Executable File]C:\Program Files\Razer\Lycosa\razertra[Caution: Executable File]C:\Program Files\Razer\DeathAdder\razertra[Caution: Executable File]C:\Program Files\Razer\DeathAdder\razerofa[Caution: Executable File]C:\Program Files\Mumble\mumble[Caution: Executable File]C:\Windows\system32\taskmgr[Caution: Executable File]C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Program Files\Xfire\Xfire[Caution: Executable File]C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Program Files\Spybot - Search & Destroy\SpybotSD[Caution: Executable File]C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Windows\system32\SearchFilterHost[Caution: Executable File]C:\Users\Justin\Downloads\HijackThis[Caution: Executable File] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qooqlle.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)O4 - HKLM\..\Run: [Lycosa] "C:\Program Files\Razer\Lycosa\razerhid[Caution: Executable File]"O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid[Caution: Executable File]O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray[Caution: Executable File]O4 - HKCU\..\Run: [Google Update] "C:\Users\Justin\AppData\Local\Google\Update\GoogleUpdate[Caution: Executable File]" /cO4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar[Caution: Executable File] /autoRunO4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin[Caution: Executable File] (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin[Caution: Executable File] (User 'NETWORK SERVICE')O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire[Caution: Executable File]O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL[Caution: Executable File]/3000O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{68AF11DA-E766-400B-A4F9-58D0086B8B60}: NameServer = 8.8.4.4,8.8.8.8O17 - HKLM\System\CS1\Services\Tcpip\..\{68AF11DA-E766-400B-A4F9-58D0086B8B60}: NameServer = 8.8.4.4,8.8.8.8O17 - HKLM\System\CS2\Services\Tcpip\..\{68AF11DA-E766-400B-A4F9-58D0086B8B60}: NameServer = 8.8.4.4,8.8.8.8O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dllO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx[Caution: Executable File]O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent[Caution: Executable File]O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc[Caution: Executable File]O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv[Caution: Executable File]O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des[Caution: Executable File] (file missing)O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA[Caution: Executable File]O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService[Caution: Executable File]O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service[Caution: Executable File] --End of file - 6048 bytes[/hide] You can see in the R0s and R1s what I'm talking about. Anyone got ideas? I used spybot and adaware...did not find it. Link to comment Share on other sites More sharing options...
Hegelstad Posted November 3, 2010 Share Posted November 3, 2010 download this : http://www.microsoft.com/security_essentials/ its pretty much the best free antivirus out there. Your spybots wont be able to catch this what seems to be a virus ;-) My lame drops:6 Effigys1 D Med - 1 D Dagger1 Verac's Helmet - 1 Guthan's Platebody Link to comment Share on other sites More sharing options...
Sbrideau Posted November 4, 2010 Share Posted November 4, 2010 Replace Spybot and AdAware with Malwarebytes. Spybot S&D and AdAware both used to be very good, but it's a thing of the past now. Link to comment Share on other sites More sharing options...
InkofDeath Posted November 4, 2010 Author Share Posted November 4, 2010 Yea. Fixed it. Thanks. Link to comment Share on other sites More sharing options...
Sbrideau Posted November 4, 2010 Share Posted November 4, 2010 Can you tell us which program picked it up? Link to comment Share on other sites More sharing options...
jallaballe Posted November 6, 2010 Share Posted November 6, 2010 I registered soley to respond to this thread, as i have plown trough the internet for 2 days and this is the best related google search.I cant describe how annoying it is that the threadstarter did not bring ANY helpful information in his last respond.Ive been trying Microsoft Security Essensials (wich was on the PC when it got infected), spybot, ad-aware, malewarebytes + online scans + more i cant remember.I was going to try ComboFix, but it wont run on Windows 7 64bit. THE SOLUTION FOR ME WAS COMODO INTERNET SECURITY. http://www.comodo.com/home/download/ Im sorry if my reply to this thread causes it to "become active" again, but my hope is that it will help others.Oh and may qooqlle.com and the creator of the virus burn eternally. Link to comment Share on other sites More sharing options...
ream Posted November 9, 2010 Share Posted November 9, 2010 I'm downloading comodo now to see if it works for me. *fingers crossed* Link to comment Share on other sites More sharing options...
ream Posted November 9, 2010 Share Posted November 9, 2010 Comodo hasn't worked for me. *edit* it seems as though it may have. qooqlle.com hasn't reappeared even after restart, but the internet is still going slowly. :\ Link to comment Share on other sites More sharing options...
ream Posted November 9, 2010 Share Posted November 9, 2010 i do believe the issue has been resolved. *edit* thankyou to jallaballe for suggesting Comodo it did the trick for me too (:anyone having problems with qooqlle or google custom search should try it. Logfile of Trend Micro HijackThis v2.0.4Scan saved at 4:16:50 PM, on 9/11/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16671)Boot mode: Normal Running processes:C:\Program Files\Sony\VAIO Care\VCSpt[Caution: Executable File]C:\Users\Tim\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler[Caution: Executable File]C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon[Caution: Executable File]C:\Program Files (x86)\SONY\ISB Utility\ISBMgr[Caution: Executable File]C:\Program Files (x86)\AVG\AVG10\avgtray[Caution: Executable File]C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor[Caution: Executable File]C:\Program Files\Sony\VAIO Care\listener[Caution: Executable File]C:\Users\Tim\Desktop\Virus Removal Tool\setup_9.0.0.722_05.11.2010_16-09\setup_9.0.0.722_05.11.2010_16-09[Caution: Executable File]C:\Users\Tim\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Users\Tim\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Users\Tim\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Users\Tim\Desktop\HiJackThis[Caution: Executable File]C:\Users\Tim\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File]C:\Users\Tim\AppData\Local\Google\Chrome\Application\chrome[Caution: Executable File] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony.msn.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://facebook.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit[Caution: Executable File]O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dllO2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllO2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dllO3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dllO4 - HKLM\..\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon[Caution: Executable File]O4 - HKLM\..\Run: [iSBMgr[Caution: Executable File]] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr[Caution: Executable File]"O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation[Caution: Executable File]" UNATTENDEDO4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray[Caution: Executable File]O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr[Caution: Executable File]" /backgroundO4 - HKCU\..\Run: [Google Update] "C:\Users\Tim\AppData\Local\Google\Update\GoogleUpdate[Caution: Executable File]" /cO4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin[Caution: Executable File] (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar[Caution: Executable File] /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin[Caution: Executable File] (User 'NETWORK SERVICE')O4 - Startup: setup_9.0.0.722_05.11.2010_16-09.lnkO4 - Global Startup: Bluetooth.lnkO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL[Caution: Executable File]/3000O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO17 - HKLM\System\CCS\Services\Tcpip\..\{26E8B872-1F7B-4EA2-9280-C95E47B0EC59}: NameServer = 10.0.0.138O17 - HKLM\System\CS1\Services\Tcpip\..\{26E8B872-1F7B-4EA2-9280-C95E47B0EC59}: NameServer = 10.0.0.138O17 - HKLM\System\CS2\Services\Tcpip\..\{26E8B872-1F7B-4EA2-9280-C95E47B0EC59}: NameServer = 156.154.70.22,156.154.71.22O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dllO23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\Alg[Caution: Executable File],-112 (ALG) - Unknown owner - C:\Windows\System32\alg[Caution: Executable File] (file missing)O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent[Caution: Executable File]O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc[Caution: Executable File]O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass[Caution: Executable File] (file missing)O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng[Caution: Executable File]O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc[Caution: Executable File] (file missing)O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService[Caution: Executable File]O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc[Caution: Executable File]O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass[Caution: Executable File] (file missing)O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS[Caution: Executable File]O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc[Caution: Executable File] (file missing)O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass[Caution: Executable File] (file missing)O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass[Caution: Executable File] (file missing)O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc[Caution: Executable File]O23 - Service: @%systemroot%\system32\Locator[Caution: Executable File],-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator[Caution: Executable File] (file missing)O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass[Caution: Executable File] (file missing)O23 - Service: @%SystemRoot%\system32\snmptrap[Caution: Executable File],-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap[Caution: Executable File] (file missing)O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp[Caution: Executable File]O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr[Caution: Executable File]O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms[Caution: Executable File]O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs[Caution: Executable File]O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr[Caution: Executable File]O23 - Service: @%systemroot%\system32\spoolsv[Caution: Executable File],-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv[Caution: Executable File] (file missing)O23 - Service: @%SystemRoot%\system32\sppsvc[Caution: Executable File],-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc[Caution: Executable File] (file missing)O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\ui0detect[Caution: Executable File],-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect[Caution: Executable File] (file missing)O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS[Caution: Executable File]O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager[Caution: Executable File]O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr[Caution: Executable File]O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass[Caution: Executable File] (file missing)O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw[Caution: Executable File]O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr[Caution: Executable File]O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr[Caution: Executable File]O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\vds[Caution: Executable File],-100 (vds) - Unknown owner - C:\Windows\System32\vds[Caution: Executable File] (file missing)O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService[Caution: Executable File]O23 - Service: @%systemroot%\system32\vssvc[Caution: Executable File],-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc[Caution: Executable File] (file missing)O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent[Caution: Executable File]O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc[Caution: Executable File]O23 - Service: @%SystemRoot%\system32\Wat\WatUX[Caution: Executable File],-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc[Caution: Executable File] (file missing)O23 - Service: @%systemroot%\system32\wbengine[Caution: Executable File],-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine[Caution: Executable File] (file missing)O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv[Caution: Executable File],-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv[Caution: Executable File] (file missing)O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk[Caution: Executable File],-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk[Caution: Executable File] (file missing) --End of file - 12365 bytes Link to comment Share on other sites More sharing options...
beejw1 Posted November 12, 2010 Share Posted November 12, 2010 I tried everything to delete qooqlle - adaware, spybot, malwarebytes, super, comodo even contacted my ISP but everytime I reset my homepage and then rebooted, qooqlle remained my homepage.Appear to have solved it myself now, realising this MF was in my Registry.Try This.. Click - Start Click RunType regeditClick EditClick FindType qooqlleIt should come up on the right side of the screen.Delete the pesky MF. Worked for me after downloading multi MB of anti spy and malware software. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now