Big problems with CoolWWWsearch

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Deathtopopups, Dec 22, 2004.

  1. Deathtopopups

    Deathtopopups Private E-2

    Hello!

    I've read several forums on this topic, tried and tried, but to no avail of getting rid of it.

    I've ran Ad-aware which is saying it isn't finding anything anymore, but spybot is getting the same ones that come back after rebooting, these are:

    ----

    IGetNet 1 Entries
    Common hijacker 2 Entries
    CoolWWWSearch.Bootconf 1 Entries
    CoolWWWSearch.Loadbat 1 Entries
    CoolWWWSearch.Msconfd 1 Entries
    CoolWWWSearch.Oslogo 1 Entries
    CoolWWWSearch.Tapicfg 1 Entries
    CoolWWWSearch.XmImimefilter 1 Entries

    ---


    I've also ran an updated version of CWShredder, when it gets to the second item on the list it is trying to delete it freezes and I get and error message and it closes.

    I've been getting more and more pop ups are time goes on, and I'm also now getting a winlogon error message after start up.

    As I searched through other forums, I came across this person's problem(http://forums.techguy.org/showthread.php?t=304499&page=1&pp=15) and it looks nearly the same as mine, but I'm getting lost in the steps and need a little more assistance.

    I've tried nearly everything I can, and everything seems to be coming back on start up, the coolwwwsearch on Spybot, changed homepage (sometimes to about:blank) but usually a different one, several pop ups and winlogon error message.

    Any help is appreciated, Thanks!
     
  2. Deathtopopups

    Deathtopopups Private E-2

    also, I've been getting a pop up that has been going to a blank page, I haven't had it recently, but it was along the lines of www.a-d-w-a-r-e.com/yyy
     
  3. PhilliePhan

    PhilliePhan Guest

    Hi Deathtopopups,

    Sounds like you have the really nasty baddie that's been going around lately. We will likely need to undertake a special process to remove it. But, before we do, here is the standard speech:
    Generally, it is a good idea to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    There are only a few of us Volunteers who regularly offer advice in this forum. Running through the above Tutorial will remove a lot of stuff that would otherwise clog a HijackThis Log and save us valuable time.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’ve been pretty busy with work lately, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  4. Deathtopopups

    Deathtopopups Private E-2

    Alright! Everything done now...


    The online scans worked fine:

    Trend's scan didn't pick up anything
    Symantec's picked up one file -> C:\spb.exe is infected with W32.spybot.worm

    ------

    I have been having a problem with the ad-aware plug-in VX2, I downloaded and installed it, and it isn't showing up after I click on the "Plug-ins" button in Ad-aware after opening, so I'm not sure if it scanned with it or not.. After the scan, again, it detected nothing.

    -----

    When I run spybot I continue getting the same detections from earlier, and when I click "fix selected problems" it fixes IGetNet and Common Hijacker, and won't fix the CoolWWWSearchs, I don't even get a message saying some problems may be fixed on start up from Spybot.

    -----

    I ran CWShredder and it is still freezing after getting to the second item on the list it is scanning for.

    -----

    About:Buster worked fine, I don't need the post the log file from it do I?

    -----

    My HijackThis file is attached as well.


    Thanks with the help so far!
     

    Attached Files:

  5. Deathtopopups

    Deathtopopups Private E-2

  6. Deathtopopups

    Deathtopopups Private E-2

    Ack! Big mistake on my part... I have been using HijackThis version 1.98.2, I've re-downloaded and got a new log file, and it is attached. Still appreciating help though, but disregard the last hijackthis log!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're running it from the ZIP file. That's a no no! Locate it where Phillie specified.
     
  8. Deathtopopups

    Deathtopopups Private E-2

    Ooer, my mistake there too! Ok, everything should be fine now.. Log is attached!
     

    Attached Files:

  9. PhilliePhan

    PhilliePhan Guest

    Hi D2P,

    HijackThis is still a problem - Hang in there :) Once we get it situated properly, we can go after the baddies in your log. This is Important, so let me know if you have trouble with the instructions below.

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To EXTRACT HijackThis:
    Now, RightClick your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder (C:\Program Files\HijackThis)and click Next.

    Now run HJT from there and attach that log.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.

    PP :)
     
  10. Deathtopopups

    Deathtopopups Private E-2

    heh, ok I followed all the instructions and extracted it to its own folder and ran a new scan and saved the log... and it's attached, Heh, sorry to screw that up so bad.
     

    Attached Files:

  11. PhilliePhan

    PhilliePhan Guest

    Don't worry about it! Things will, however, get more complicated. So, anytime you have a question - Ask it!

    Removing all of the baddies will take a number of steps. We will save the worst for last.

    Now, on to your malware!

    I saw ARES earlier - You should Uninstall and dump it as it leads to headaches.

    Now, please download this tool: LSP - Fix

    Please run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the calsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move calsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Now, Reboot and then scan with HijackThis and attach that log and we’ll move on to some of the others.

    PP :)
     
  12. Deathtopopups

    Deathtopopups Private E-2

    ok, ran LSP and removed what you said... Now here is the new HijackThis file
     

    Attached Files:

  13. PhilliePhan

    PhilliePhan Guest

    Hi D2P,

    When you scan and fix with HijackThis, you need to make sure All browsers and other unnecessary programs are closed. They could interfere with the fix.


    Please print out these instructions so that you can operate with All Browser Windows CLOSED.

    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Now, look in Task Manager (Ctrl-Alt-Del) for the following running process and, if you it, try to END it if possible:

    bqzhj.exe

    Now scan with HijackThis and Check the Boxes for the following:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch

    O4 - HKLM\..\Run: [C:\WINDOWS\bqzhj.exe] C:\WINDOWS\bqzhj.exe

    O4 - HKLM\..\Run: [SStb.exe] SStb.exe



    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode and navigate to and DELETE the following if they should remain:

    C:\WINDOWS\bqzhj.exe

    SStb.exe ---> You may need to run a search of your computer for this one using Windows Explorer. It will probably be in either the C:\Windows or C:\Windows\System32 directory

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    Reboot to Normal Windows and Scan with HijackThis and attach that log. I know the 01 entries will come back. We'll work on those next!

    PP :)
     
  14. Deathtopopups

    Deathtopopups Private E-2

    Alright... Sorry that took so long, my computer is going down... It's now starting the phase where it randomly turns off, I followed the instructions, and now here is the new log!
     

    Attached Files:

  15. PhilliePhan

    PhilliePhan Guest

    Okay! We are ready to take on the last one. It will take a couple of steps.

    To Start, please download the following tools and have them handy:

    Generic Detection Tool

    http://www.downloads.subratam.org/DllCompare.exe

    http://www.downloads.subratam.org/VX2Finder.exe

    http://www.downloads.subratam.org/KillBox.zip



    NOW:


    Unzip (Extract - as with HJT) the Generic Detection Tool to a safe folder of your choice and run "findit.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Please attach that Log.

    ALSO:

    RUN DLL Compare – Click Run Locate.com then click the Compare button. Follow the prompts and allow time for it to complete and make a log. Please attach that Log as well.

    It's getting a bit late for me, so we'll have to pick this up again Thursday night. Go ahead and attach the logs and I'll check back when I get a chance.

    PP :)
     
  16. Deathtopopups

    Deathtopopups Private E-2

    Check and Check! Logs are posted.
     

    Attached Files:

  17. PhilliePhan

    PhilliePhan Guest

    I always forget to mention to not reboot after sending the logs as the baddies change. If you have since rebooted, please attach fresh logs and then do not reboot until I check back. I will post the next step this evening when I have more time!

    PP :)
     
  18. Deathtopopups

    Deathtopopups Private E-2

    Alright, hopefully the sudden fatal system error shut offs aren't going to get more frequent, but I'll try and keep this going as long as I can and the logs attached are the most current since the last reboot.
     

    Attached Files:

  19. PhilliePhan

    PhilliePhan Guest

    Hi D2P,

    On to the next step:

    Make sure you are COMPLETELY DISCONNECTED from the Internet when you do this. Probably a good idea to Print Out these instructions.


    Before you start, look in C:\WINDOWS\SYSTEM32 for guard.tmp and make sure that the correct path is C:\WINDOWS\SYSTEM32\guard.tmp – Viewing of hidden files as per the tutorial may be needed. This needs to be verified so that you can enter the correct path below. If you do not find this, please continue with the other instructions.

    Be very careful to select the correct settings on Pocket KillBox. Note to REPLACE and not Delete on reboot.


    Off we go:

    Now, run Pocket Killbox.
    Select the option to Replace on Reboot.

    Now, Copy and Paste C:\WINDOWS\System32\G622LG~1.DLL
    into the box and Check the option to Use Dummy. Now, Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Next, Copy and Paste C:\WINDOWS\SYSTEM32\dnl4013qe.dll
    into the box and Check the option to Use Dummy. Now, Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Next, Copy and Paste C:\WINDOWS\SYSTEM32\enj0l11m1.dll
    into the box and Check the option to Use Dummy. Now, Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    You get the idea – Now, continue the process for the rest:

    C:\WINDOWS\SYSTEM32\ennul1591.dll
    C:\WINDOWS\SYSTEM32\g0jo0a13ed.dll
    C:\WINDOWS\SYSTEM32\g622lgfo162c.dll
    C:\WINDOWS\SYSTEM32\g8lm0i31e8.dll
    C:\WINDOWS\SYSTEM32\jt8207loe.dll
    C:\WINDOWS\SYSTEM32\mv22l9fo1.dll
    C:\WINDOWS\SYSTEM32\mzwdat10.dll
    C:\WINDOWS\SYSTEM32\oqbcbcp.dll
    C:\WINDOWS\SYSTEM32\r6r60g9se6.dll


    Once you reach the end of the above list, Copy and Paste C:\WINDOWS\SYSTEM32\guard.tmp into the box – If it exists, it will show up in Blue. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally.


    After your machine reboots, run DLL Compare again and make sure the log is clean. If it is not clean, REPEAT the above process on ALL new entries created On or After 12-23-04.

    Also, look again for C:\WINNT\SYSTEM32\guard.tmp and, if it remains, fire up KillBox and Delete it using Standard File Kill option.

    Once the DLL Compare Log is Clean, attach a copy and then run Findit.bat again and attach that fresh log as well and we’ll move on to the next step!

    Best Luck :)
    PP
     
  20. Deathtopopups

    Deathtopopups Private E-2

    Alright, the only thing that I couldn't do was find the guard.tmp file, but everything is ok!

    The logs you specified are attached.
     

    Attached Files:

  21. PhilliePhan

    PhilliePhan Guest

    Hi D2P,

    On to Step 2:

    Run Pocket KillBox and Copy and Paste the Following into the box: C:\RECYCLER\Desktop.ini - Click Red X to delete it using Standard File Kill.

    NOW:
    Open VX2Finder and use the UserAgent$ Button to remove the UserAgent from the registry.

    Then, Click the Restore Policy Button. Your machine should want to reboot – Let it do so.

    NEXT:
    Using START > RUN > regedit, please open the registry editor and navigate to the following:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SideBySide

    Backup this key by clicking File, Export and then enter a File name and save it somewhere you can find it (if needed). Do the Export before doing the following:
    RightClick on the above registry key (the SideBySide one - make sure the bottom of the regedit window shows the full reg key as shown above in bold) and select DELETE.

    Now, attach a fresh Findit.bat Log and a fresh HijackThis Log and we'll clean up the remnants!

    I'll check back when time permits.

    PP :)
     
  22. Deathtopopups

    Deathtopopups Private E-2

    The UserAgent$ button in VX2 Finder wasn't clickable, should I continue on and click the restore policy? Or skip this step completely?
     
  23. PhilliePhan

    PhilliePhan Guest

    We've seen this before.

    Please continue on with the instructions.

    PP :)
     
  24. Deathtopopups

    Deathtopopups Private E-2

    alright, this is what you asked for!
     

    Attached Files:

  25. PhilliePhan

    PhilliePhan Guest

    Hi D2P,

    All that is left is to fix these entries with HijackThis:

    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch


    Make sure ALL browser windows are CLOSED when you click FIX.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    All should be clean - How are things working now?

    PP :)
     
  26. Deathtopopups

    Deathtopopups Private E-2

    Alright, everything is done! We'll wait about an hour and I'll put another update in, but so far everything is looking dandy, should I run a spybot, ad-aware, cwshredder, or about:buster for the final precautions?
     
  27. PhilliePhan

    PhilliePhan Guest

    Hi D2P,

    You should wait a bit, make sure thing are running OK and then turn System Restore back on (Figured it was off per the tutorial). If it is on now, turn it off and then back on to start anew.

    You should also take a look at Chaslang's recommendations HERE:How to protect yourself from malware!

    I definitely recommend that you continue to use the following tools from the Cleanup Tutorial:
    Ad-Aware SE Personal

    SpyBot-Search & Destroy - Remember to use the "Immunize" feature

    SpywareBlaster

    These are all FREE! Just remember to Internet Update them regurlarly! They, along with a good Anti-Virus and Firewall & keeping your Windows up-to-date will do wonders in helping to keep Malware off your computer!

    Best :)
    PP
     
  28. Deathtopopups

    Deathtopopups Private E-2

    I already run the programs from the thread from Sgt. Sweetie, when those didn't fix the problem is the point I became concerned and asked for assistance.

    So far, an hour later, everything working great, system restore is now back on, and after reading Chaslang's malware protection I have a couple things from there I need to download.

    All in all, everything is fine I do believe. Thanks for all the help PP, I'm glad there are people like you and Chaslang on our side!
     
  29. PhilliePhan

    PhilliePhan Guest

    You're welcome! We are happy to help :)

    You should definitely keep the anti-spyware tools updated and in use! Scan regularly!

    Happy Holiday Computing :)

    PP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds