CoolWWWsearch.olehelp

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pkfalu92, Feb 6, 2011.

  1. pkfalu92

    pkfalu92 Private E-2

    I have read various other threads and downloaded several scanners, but none seem to be able to remove this virus.

    I read the "Vista malware removal/cleaning procedure" and followed it word for word.
    I rebooted and voila! It's back again, ready for round 4.

    At this point, I feel I need a bit of personal assistance.

    I first noticed the issue early on 2/5/2011. I logged in, ready to play Aika, and was planning on logging into msn. I tried logging into msn but got a pop up message saying my "key ports" weren't connected. I thought it was a problem with msn, so I went to their site, but was unable to connect to that either. So I downloaded skype and went on a voice call, assuming that it was entirely MSN.
    Then I tried logging into Aika. Well, it kept popping up with all kinds of errors. It would either say it could not connect to the update server OR it said the version was updated, but when I got into the login screen it would not log me in, and instead froze.

    I know I am connected to my internet, since I was able to do my daily perusing of my forums/checking facebook. Regardless, I re-set both my modem and my WLAN router, and just to be safe, plugged the ethernet cord right into my computer (Routers sometimes do strange things...)

    It still refused to work.

    I thought it might be a port blocked, so I tried going to portforward.com, but again I came up with a 101 error. I had a bad feeling at this point, and tried connecting with my ipad: again the site didn't work. The ipad is connected to our wi-fi.
    I tried with my phone (not using the same internet- phone uses 3G) and to my surprise, the site works.

    I then run avast and spybot. Avast with a quick scan picks up nothing, but spybot does.
    CoolWWWsearch.0lehelp pops up. I try "repairing" it, and reboot, but that doesn't fix it.
    I run a full scan with avast, find it, quarantine it, but again, it's back!

    I then perused through various sites looking for a fix that I could understand- I'm no techie and complicated, hard to understand guides are...hard to understand.
    This one was easy to understand and I followed every last step, only to reboot at the end and find that the virus is back.

    Attached are the logs. I've spent around 12 hours today trying to fix this. I'd appreciate help as fast as you can get to me.

    Thank you.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why is it that you have two antivirus installed? You need to get rid of one immediately before continuing.

    • avast! Free Antivirus
    • Norton Internet Security

    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer

    Uninstall outdated Java.

    • Java(TM) 6 Update 17
    • Java(TM) 6 Update 16

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    • R3 - URLSearchHook: (no name) - - (no file)
    • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    • O15 - Trusted Zone: http://software.kuaiche.com

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    X6va001
    X6va003 
    File::
    c:\users\Michelle\AppData\Local\Temp\001D06B.tmp
    c:\users\Michelle\AppData\Local\Temp\00383EE.tmp
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va001]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va003]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{A9DB8F31-C852-4A14-8E79-6764BD89638A}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now, and what problems may remain.
     
  3. pkfalu92

    pkfalu92 Private E-2

    I tried the CW shredder after doing all of that and the virus appears to be gone, however!
    I still get errors when trying to visit certain sites, login to msn, and login to the MMORPG aika.

    Thank you for all your help so far. I hope you could give me some advice on how to get aika and msn working again. Thank you.

    I ran the program getlogs.bat but it did not create a .zip file. :/ But there is a file called filelogs.txt

    Is that the one needed?
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, what you attached is of no use, so, please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this
     
    Last edited by a moderator: Feb 6, 2011
  5. pkfalu92

    pkfalu92 Private E-2

    I ran C:\MGtools\GetLogs.bat,and no .zip file was created in my C:\

    In fact, there is no such file anywhere on my computer. >.< Am I doing something wrong?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You attached C:\MGlogs.zip to your first message. Either this 1st copy should still be there or the new copy. The only way it would not be there now is if you deleted it. Are you sure that you are looking in the root folder ( C:\ ) and not looking inside of the C:\MGtools folder.

    When you run GetLogs.bat do you see lot's of info appearing in the black command prompt window for 5 to 10 minutes or does the command prompt window just appear and then quickly disappear.
     
  7. pkfalu92

    pkfalu92 Private E-2

    I had to run mgtools to get it, the .bat thing didn't work, no matter how many times I ran it. Maybe it needs to be run in administrator mode?

    It would go through the whole cmd prompt thing for about 20 minutes, then no zip file would appear.

    I have it now.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does for Vista and Win 7. Kestrel13! needs to update her boilerplate messages. ;)
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Done.

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.
    Not topic for the malware forum.

    What issues remain?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds