Saturday, October 15, 2005

LQfix Information Page

The information in Virtual Grub Street's computer postings is the result of thousands of web searches. It can not, however, possibly be complete. The subject is vast and constantly changing. Moreover, vendor uninstall tools and other freeware removal tools do not necessarily remove all of an infection from your computer. Vendor uninstall tools, for instance, may silently leave cookies or other tracking software installed. It is suggestible to follow up a removal with one or more adware scans and/or to do an inspection using a HijackThis log. The information on the page is not guaranteed correct and any use you may choose to make of it is entirely at your own risk.






*


Intro. The LQfix removal tool was created by a 30 year old Belgian woman who goes by the handle "miekiemoes". [M]iekiemos has long been a regular participant in numerous web forums.

The name "LQfix" refers to the fact that the tool removes the signature registry entry "HKCU\Software\LQ" as a key step of its process. It is not clear that any infection that does not include this entry can be removed by this tool.

Versions. There are two versions of LQfix that have been made available by free download since September 27, 2005. The first is refered to by the name "LQfix.exe". It is the full LQfix removal program. A new limited one-click batch-process version, for targetted use, is refered to as "LQfix.bat". LQfix.bat is only available via the zip file download "LQfix.zip".

File Size. LQfix.exe 2.1: 656KB; LQbat: 10KB.

File Type. LQbat: MS-Dos.

Most recent update. LQfix.exe 2.1; 10/22/05; LQbat: 10/12/05.

vs. PokaPoka76.exe. Versions of LQfix prior to 10/22/05 alone can not remove pokapoka76.exe file. It is not clear whether the new version can or not. Previous versions of LQfix can, however, definitely remove PokaPoka76.exe in combination with the Ewido Security Suite's trialware trojan remover. A example Ewido scan report, relating to pokapoka76 removal should read as follows:


[####] C:\WINNT\etb\nt_hide76.dll -> Trojan.EliteBar.a : Cleaned with
backup

[####] C:\WINNT\etb\pokapoka76.exe -> Trojan.EliteBar.a : Cleaned with
backup

*


C:\Documents and Settings\gward\Local Settings\Temp\1246052_2340_2308_1816_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup

C:\Documents and Settings\gward\Local
Settings\Temp\131564_3584_2888_548_76.41.tmp -> Trojan.EliteBar.a : Cleaned
with backup

*


C:\Documents and Settings\gward\Local
Settings\Temp\262588_2208_3968_2508_76.41.tmp -> Trojan.EliteBar.a : Cleaned
with backup

C:\Documents and Settings\gward\Local
Settings\Temp\66126_2832_2504_3884_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup

C: \Documents and Settings\gward\Local
Settings\Temp\66262_2340_2308_3020_76.41.tmp -> Trojan.EliteBar.a : Cleaned with backup

*

C:\Documents and Settings\gward\Local Settings\Temp\k_AA09.tmp ->
Trojan.EliteBar.a : Cleaned with backup



Typically, both tools are employed in Safe Mode in order to remove this infection. Ewido is run first, to remove the actual files associated with Trojan.EliteBar.a (PokaPoka76), followed by LQfix, to remove the other files associated with the infection.

Downloads. LQfix.exe can be downloaded from the following locations:


The last site listed is miekiemoes's own page.


The following example instructions for LQfix.exe (the version prior to 2.1) appear at the Geeks to Go forum:


  • Double-Click LQfix.exe and click Next > Next > Install.
  • Leave the default settings, if you change them, the fix will Fail!
  • You need an active internetconnection, so make sure your you're not blocking any connection now.
  • Now make sure the "Launch LQfix" box is checked. Click the Finish button, after clicking the Finish button the fix will start.
  • Follow the on-screen prompts.
  • Your system will reboot afterwards. Please be patient after the reboot, there is a script running in the background that needs to complete.

The tool must be run in Safe Mode.


LQfix.bat (LQfix.zip) can be downloaded from the following locations:


LQfix.bat is deployed by opening the LQfix folder and clicking on "LQfix.bat".




Other VGS Freeware/Trialware Information Pages:



Also see:


No comments: