CoolWWWSearch & Smitfraud-C

Discussion in 'Malware Help (A Specialist Will Reply)' started by Carrott, Oct 5, 2005.

  1. Carrott

    Carrott Private E-2

    Hi - Can someone please help me. Running my antivirus/spyware programs - Adaware, Spybot, Ewido, Bullguard. Everything came up clean except Spybot has found the following that it can not delete. How do I get rid of them.

    CoolWWWSearch.BadZoneMap
    CoolWWWSearch.Leftovers
    CoolWWWSearch.Mupdate
    CoolWWWSearch.Toolband
    Smitfraud-C
     
  2. Carrott

    Carrott Private E-2

    OOPS!!! Wait before you reply. I just found the 'READ THIS FIRST' article. Let me run this stuff and then I'll post again.

    Sorry and Thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing ALL of the READ ME FIRST, if you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:


    Downloading, Installing, and Running HijackThis
     
  4. Carrott

    Carrott Private E-2

    OK - I have ran everything per "Read Me First".

    Ran in Safe Mode:
    Bitdefender - Clean scan
    RavAntivirus - Clean scan
    McAfee Avert Stinger - Clean scan
    CCleaner - Successful
    AdAware SE - Clean Scan
    Spybot - still comes up with CoolWWWSearch.BadZoneMap, CoolWWWSearch.Leftovers, CoolWWWSearch.Mupdate, CoolWWWSearch.Toolband, Smitfraud-C
    CWShredder - Clean Scan
    Kill2Me - Clean Scan

    Normal Mode:
    Trojan - clean scan

    Also, I noticed in Explorer c:\Program Files\180SearchAssistant and c:\Program Files\Wildtangent (aren't these virus?)

    and

    This machine running really slow and quirky. :(

    HJT log attached.

    Thank you so much for your help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look for them in Add/Remove programs and uninstall them if found. Also delete those folders (may need to be in safe mode to delete).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O15 - Trusted Zone: http://acs.pandasoftware.com
    O15 - Trusted Zone: http://activescan.pandasoftware.com
    O15 - Trusted Zone: http://www.pandasoftware.com
    O15 - Trusted Zone: http://www.pandasoftware.es

    After clicking Fix, exit HJT.
    I think you problem with Spybot reporting SmitFraud is a bunch of registry keys (part of Domains) not being in the Restricted Zone. Let's try the below.

    download DelDomains and unzip it to your desktop.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.
    Afterwards run Spybot and make sure you re-Immunize immediately. Then run a full system scan. If you get any reported problems, attach the log from Spybot.
     
  6. Carrott

    Carrott Private E-2

    :D Well spybot came up CLEAN. I'm just curious, did the DelDomains also correct the CoolWWWSearch?

    Also, HJT along with other programs have been acting really sluggish and just now when I ran HJT it worked beautifully (very quick instead of taking forever). Did DelDomains do that?

    I have attached the HJT log just in case you need it.

    I have one more question for this comp. When I boot up I get a message that the modem driver needs to be updated. Well, when I try to update through device manager wizard, it tells me that it can't find the software. Of course, I don't have a clue which one of these 100 CDs is the right one and none of the say the name of my modem "Creative Modem Blaster V.92 PCI DI5652". Just let me know if I should take this to a different forum.

    I can't thank you enough for your help. You are a blessing from heaven.

    God Bless You
    Janet
     

    Attached Files:

  7. Carrott

    Carrott Private E-2

    Sorry, I forgot to ask one more question. I have a removable hard drive that I use for weekly backups (entire system). I use the backup that comes with windows. I'm not sure if that back up has all the trash on it we just removed or not. If I just simply delete the backups would that take care of that backup hard drive as far as cleaning it? Sorry to be a pest. Thanks again. :)
     
  8. Carrott

    Carrott Private E-2

    :( Well, I have a brand new problem. This computer keeps loosing connection to internet. I get "page cannot be displayed". If I restart computer then internet will work again. I don't know if it has anything to do with it, but we had to recently put dial-up on our comps because Hurricane Rita had our electricity and internet off. I have already removed the dial-up connection and uninstalled their booster program. Do you think it changed some sort of settings in IE? We are back on cable internet now. Thanks and God Bless.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your new HJT log is clean!

    Deldomains removed all item that were in your Trusted and Restricted Zones. This resolved what Spybot was having problems with and also may have caused the speed improvement.

    Modem driver issues belong in the Hardware Forum.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Depending upon when you got infected and when you have done backups, they could be infected. If you do not need what is in them, delete them and start from scratch.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying with your connection back on cable, you are periodically having problems loading pages. This does not necessarily mean you are not connected to the internet. You could try other things (like pinging or using another browser) to see if you are still connected.
    How often does it happen? Does it happen on any website? Check to make sure your cable modem's LEDs show connectivity. See your manual.
     
    Last edited: Oct 7, 2005
  12. Carrott

    Carrott Private E-2

    Well, I guess I worded that wrong. We are back on cable internet. I have four computers networked and at least once a day this one will not load internet pages (from any website). I know I still have internet connection because the other computers on the network have connection. Thanks.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When it gets in this state:
    1) Can you ping your router
    2) Can you ping other PCs on your network
    3) Can you ping an IP address on the internet (like: ping 66.102.7.147 which will ping google.com)
    4) Try using IP addresses rather than URLs. So for example use 66.102.7.147 instead of www.google.com now see if it connects.
     
  14. Carrott

    Carrott Private E-2

    Thanks
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but let me know the answers to those questions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds