Need help getting rid of CoolWWWSearch

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fromafar3, Dec 30, 2004.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure system restore is disabled.

    Try downloading, installing and running TDS This is Trojan Defence Suite. Run it from a safe mode boot.

    Open TDS3's Scan comtrol and enable every option, then scan "All logical drives. This is a very deep scan and will take some time. When the scan is complete and providing you have a description of the malware in the bottom report console you should be able to right click on the result and select Delete or find the files properties etc.

    It may not find that EXE but it could find others, like some DLL files.
     
  2. fromafar3

    fromafar3 Private E-2

    Do you want me to post the results of the scan when it's done or just let you know once it's complete?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes. Also see my other requested item to run (finditnt2000xp.zip)
     
  5. fromafar3

    fromafar3 Private E-2

    Happy New Year, Dr. C!

    Here is the log file from running TDS-3, it's called scr0.txt.
    Here is the log file from running Find-it-nt-2k-xp, it's called output.txt.

    I'm calling it a night. I'll check back again tommorrow. Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy and paste the information in the below quote box to notepad. Save it to your Desktop as type "all files" and name it fixvx2.reg. Doubleclick it and grant it permission to merge in the registry entries.

    We have some more files that we need to delete using Killbox. They are all in the c:\winnt\system32 folder:

    C:\WINNT\system32\ieppni.dll
    C:\WINNT\system32\lcuuql.dll
    C:\WINNT\system32\lhuual.exe
    C:\WINNT\system32\wpuukw.dat
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\khggik.exe

    and C:\WINNT\system32\vwuugv.exe

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINNT\system32\vwuugv.exe
    (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINNT\system32\ieppni.dll


    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINNT\system32\vwuugv.exe into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally.

    After reboot post another log from this new find.bat program and also post a new HJT log.
     
    Last edited: Jan 1, 2005
  7. fromafar3

    fromafar3 Private E-2

    The entry you gave me merged into the registry file.

    I ran Killbox for all the entries as you asked. Just prior to rebooting I confirmed that I could NOT see khggik.exe in the startup folder and after rebooting now I CAN see it. Now when I boot up I get an error (as expected)

    16 Bit MS-DOS Subsystem
    C:\DOCUM~1\ALLUSE~1\STARTM~1\Programs\Startup\khggik.exe The NTDVM CPU has encountered an illegal instruction CD:0536 IP:ffe2 OP:fe ff 1e 09 06 Choose 'Close' to terminiate the application. Close or Ignore
    At which I choose Close.

    I have included the Find it log and the latest HJT log.
    Thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the file (C:\WINNT\system32\vwuugv.exe) we have been trying to remove from your HJT log is gone. Is it still gone?

    Does that error related to khggik.exe occur at each boot?
    Let's try something, go to the below Startup and remove the entry for trying to start that file:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\khggik.exe
     
  9. fromafar3

    fromafar3 Private E-2

    Yes, the vwuugv.exe is still gone and Yes, the error message from khggik.exe occurs on every boot.

    I'm guessing that khggik.exe is the one that makes sure vwuugv.exe is where it should be (because we removed it before). And I just have this fear that there is going to be some other file that makes sure that khggik.exe is where IT should be and if we delete it we are going to end up back where we started from. Oh well, all we can do is keep peeling back the layers...

    Before I delete C:\Documents and Settings\All Users\Start Menu\Programs\Startup\khggik.exe should I use HJT to remove the 04 entry or can that be removed afterward? (see new log)
     

    Attached Files:

  10. fromafar3

    fromafar3 Private E-2

    I am unable to delete C:\Documents and Settings\All Users\Start Menu\Programs\Startup\khggik.exe. The error message is:
    Cannot delete khggik: It is in use by another person or program. Close any programs that might be using this file and try again.

    Using HJT I checked the Open process manager and that file was not running (nor in Task Manager). I tried to fix the 04 Global Startup:khggik.exe entry and got the following message:

    Unable to delete the file 04 Global Startup:khggik.exe. The file may be in use. Use Task Manager to shutdown the program and run HijackThis again to delete the file.

    Do you want me to use Pocket Killbox to 'Delete on Reboot"?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you go back and look at your HJT logs, you will see this file (C:\Documents and Settings\All Users\Start Menu\Programs\Startup\khggik.exe) only showed up after we killed all that hidden garbage. It finally made the loading of the process visible.

    Try using Killbox. If that does not work, see if you can run msconfig and disable it from loading during startup and then maybe it can be remove/fixed using HJT.

    Safe mode boot may be another option to try.
     
    Last edited: Jan 2, 2005
  12. fromafar3

    fromafar3 Private E-2

    I was able to remove it using Killbox. I've rebooted twice, checking with HJT, to see if it was going to show back up again and so far it hasn't.

    I've attached one last (hopefully) HJT log.

    I'm assuming I can remove "O1 - Hosts: 203.161.127.141 www.dcsresearch.com" that came from running TDS last night. Is there anything else that should be removed?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I was going to tell you to have HJT fix that line. It is not a problem but there is no need to have it in your hosts file.

    Your log looks good. How is everything working now?

    Maybe we are finish other than me saying, check this out: How to Protect yourself from malware!
     
  14. fromafar3

    fromafar3 Private E-2

    Thank you very much for your help. My problem seems to be solved and I've taken all the steps recommended to try and prevent more problems. I really appreciate all the time you took!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy we have this all worked out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds