can you help me get rid of ewizard?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CBASS, Apr 11, 2005.

  1. CBASS

    CBASS Private E-2

    Hello,

    I've been plagued by coolwebsearch for some time now, but it hasn't ever caused a tremendous problem...I'd just apply the shredder every few days.

    Well, all of a sudden it's gotten nasty...if my PC is not plugged up to the internet, something starts opening explorer windows to wizard.cc...and will open them until the PC shuts down; if the PC is connected to the internet, I just windows informing me that my PC has spyware....thanks

    I've tried system restores, various cleaning programs...you name it...can't get rid of the damned thing

    here is my log file

    Edit by chaslang: Unrequested, old version, inline log removed

    thanks guys...any help is appreciated
     
    Last edited by a moderator: Apr 12, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow forum guidelines and read the sticky threads. We have specific guidelines about posting HijackThis logs. Also your HijackThis is way out of date. Please follow the steps below completely.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. CBASS

    CBASS Private E-2

    well, I've tried all day to get rid of the problem and it won't go away

    I followed the instructions...same result. If my PC is connected to the internet, I get the about:blank screen whenever I try to use Internet Explorer. I can run CWShredder and AdAware beforehand and at start up...same thing. Hidden.dll always comes back, as does a slew of other CoolWeb files, etc.

    The main problem is that when my PC is not connected to the internet, after a few minutes of startup, IE windows start opening until the system shuts down.

    Anyway, I've attached my hijack this log. If you guys can help, I'd appreciate it. This problem has really gotten ridiculous.

    Oh, and symantec's site doesn't seem to want to do online scans anymore. Similarly, the Housecall page isn't helpful when I can't use my IExplorer and my Mozilla has been "loading java applet" for over 30 mins with no results.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please go to the below link and download the tool for Windows 95/98/ME

    SpSeHjfix109.zip

    Extract it from the ZIP file and run it. Then reboot your PC and post a new HJT log.
     
  5. mote

    mote Private E-2

    Hi, I got the same problem with ewizard.cc pop up.
    Every five minutes, dont' know what to do. I need some help.
    I attach you my HijackThis v1.99.1 log.

    Edit by chaslang: Log removed
     
    Last edited by a moderator: Apr 13, 2005
  6. CBASS

    CBASS Private E-2

    okay, I did what you recommended

    here's my new log file
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post in your own thread. Also do not post HJT logs unless requested, do not post them inline, and do not post incomplete logs.

    Run the same steps give in message number two in this thread before staring a thread and make sure you indicate that you have run the READ ME FIRST. Then run the same tool suggested here.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok! So tell me what happened!

    Also you did not post your log.
     
  9. CBASS

    CBASS Private E-2

    hmm...I'll try again

    it <seems> to be running fine now

    <crosses fingers>

    funny...now IExplorer won't work, which is fine...I just deleted the icon and use firefox now

    amazing how corrupt those programs can make IExplorer

    hell, as long as that stuff's gone, an XP and RAM upgrade may keep the ole laptop running for another couple of years
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some problems!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes. (Note you may note find them running. Just continue.)
    C:\WINDOWS\Application Data\oocs.exe
    C:\WINDOWS\SYSTEM\nvl.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
    O4 - HKCU\..\Run: [Uate] C:\WINDOWS\Application Data\oocs.exe
    O4 - HKCU\..\Run: [Eeef] C:\WINDOWS\SYSTEM\nvl.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\Application Data\oocs.exe
    O4 - HKCU\..\Run: [Eeef] C:\WINDOWS\SYSTEM\nvl.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to www.yahoo.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to www.yahoo.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. CBASS

    CBASS Private E-2

    okay...according to my PC I've cleared up 35% of my resources

    anywhooo, here's the file
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. Is everything working OK now? You should make sure you have complete all the steps in the below link (especially installing a firewall).

    How to Protect yourself from malware!
     
  13. CBASS

    CBASS Private E-2

    seems to be

    thank you very much...I can't believe how nasty spyware has become over the last couple of years!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Yes it is nasty and constantly changing. That's why this forum is so ridiculously busy.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds