win32.fraudload.edt/coolwwwsearch

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nandz, Nov 15, 2010.

  1. nandz

    nandz Private E-2

    Spybot shows that both win32.fraudload and coolwwwsearch have been found on my computer. Both firefox and chrome will no longer work. I have followed the steps in the readme first section. Is there a log I can post that will help you help me? Thanks in advance!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have done the Read and Run First instructions you should attach these logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip --> from running the C:\MGTools.exe.
     
  3. nandz

    nandz Private E-2

    sorry for the delay. Here are the logs.
     

    Attached Files:

  4. nandz

    nandz Private E-2

    also, rootrepeal log
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like the scans took care of the malware as I am not seeing any issues other than the fact that you have two AV programs installed:
    Norton Internet Security
    McAfee SecurityCenter

    Uninstall one of them.

    Now tell me what issues you are having, if any.
     
  6. nandz

    nandz Private E-2

    Two things:

    1. I have no instance of Norton anywhere on my computer. I can uninstall McAfee, however, I am hesitant to do that because I received a free version from my previous employer and no longer have access to it if I uninstall it. Norton does not show up in my add/remove programs list.

    Is there any reason why I should need McAfee or Norton with all these free malware programs.

    2. Chrome is working again. Firefox is not. I can't get this program to open, nor can I get it to uninstall. Can I manually remove it?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both Norton and McAfee are showing in your add/remove list. Look in the MGLogs.zip in the newfiles log and at the end will be your add/remove list. If you can not find it, do not uninstall McAfee. You can change to a different AV program if you wish, but you would need to remove any AV software that is still installed first.

    We can try removing FireFox, but this is probably better addressed in the software forum.

    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:

    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.

    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot. ( If it won't uninstall, try using CCLeaner to uninstall it.)
    After reboot, delete the below folders:

    C:\Documents and Settings\UserAccount\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
  8. nandz

    nandz Private E-2

    Again, thanks for your help. I went ahead and manually deleted the entire firefox folder out of my program files in explorer and reinstalled it. This seemed to work fine, in fact, my bookmarks are even still there.

    As for Norton, I am not sure what to do. I can't find a single file named "norton" anywhere on my computer. I'm not sure how I can uninstall a program that I can't find.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if this file exists> C:\Program Files\Norton Internet Security

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  10. nandz

    nandz Private E-2

    C:\programfiles\Norton does not exist.

    I searched the disk drive for "Norton," Only one file popped up: Norton.cmd found in C:\system.sav\util

    Is it important that I toggle the system restore (option 6). I haven't done anything with system restore at this point.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't recall seeing any virus' in your system restore folders so it is not important to toggle it. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds