coolWWWsearch.WCADW

Discussion in 'Malware Help (A Specialist Will Reply)' started by reddog19, Oct 28, 2006.

  1. reddog19

    reddog19 Private E-2

    Hope you can help, heres the problem.
    A security warning started popping up on my desktop screen at regular intervals. Clicking on the associated link takes you to 2-antispyware.com.
    If I run spybot it finds and fixes coolWWWsearch.WCADW. Howevever when the security warning reappears, so does coolWWWsearch.WCADW. Its also there when I reboot.
    I've followed your instructions as follows:
    0 to 3 all completed
    4. I can't update microsoft defender... Error code 0x80070424
    5.(a) When I run Ccleaner there is always a small deletion made
    (b)When I get to on-line scans I can't log onto internet in "safe mode with network support" So I reboot in normal mode, run spybot to get rid of coolWWWsearch and even then, when I try to run Bitdefender I get an error in loading. Similarly Panda on-line scan does not complete.
    Please help if you can.
     

    Attached Files:

  2. reddog19

    reddog19 Private E-2

    Here are some more files.
    Screen.txt shows what pops up on my desktop
    Thanks for your help
     
  3. reddog19

    reddog19 Private E-2

    I just re-booted and ran cwshredder. Nothing found. But when I ran Spybot it once again found and removed coolWWWsearch.WCADW.
    I also downloaded Spyware Doctor 4.0 and I can't get the updates, "try again later". It only found 3 tracking cookies (low risk)
    I feel this inability to get updates for various programs or to run on-line scanners must be part of the problem.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this a company owned PC?

    Did you install the below:
    http://www.wavesys.com/products/ets.html

    Procedures that we may need to use inorder to remove ALL of you malware problems will more than likely break the above programs installation thus requiring a reinstall and reconfiguration.

    Let me know the answer to the above and how you want to proceed.

    Some of your problems are relate to a worm. WORM/Warezov.DQ It has place a few DLLs into your AppInit_DLLs registry key and these can sometimes be difficult to remove and it may require a blanking out (erasing) of your AppInit_DLLs registry key which just happens to be a place that WaveSys installed one of their DLLS.
     
    Last edited: Oct 29, 2006
  5. reddog19

    reddog19 Private E-2

    Thanks for you reply Chaslang.
    The computer is not a company computer but is wirelessly networked to several other home computers.
    The subject computer is a Dell latitude D820 about 2 months old. I don't even know what http://www.wavesys does so I don't care if we wipe it out.
    A windows WinXP recovery partition was factory pre-installed and I also have the drivers and Winxp (for new computers only) on CD
    Since my last post I have managed to solve the problem of not being able to update Windows and run Bitdefender.
    I have also removed AVG and replaced it with Avast 4.0.
    I went through Read & Run again all in safe mode with networking:
    CCleaner
    Malicious software : nil
    Spybot: nil
    Defender: nil
    Bitdefender : nil
    Panda Active scan: nil
    Rebooted in normal mode and ran runkeys, shownew and hjt BEFORE I ran Spybot again to remove coolWWWsearch.
    I should also mention that I'm getting about:blank in IE7, which from what I've been reading is associated with coolWWWsearch.
    Any help you can give would be greatly appreciated. I've attached 3 reports.
    Thanks
     

    Attached Files:

  6. reddog19

    reddog19 Private E-2

    Further to my last post, I've looked on the computer and the software "Embassy Security Suite" by wavesys was pre-installed by Dell. It appears to be mainly used when you have a fingerprint reader installed (I don't)
    Also the antivirus software I installed was Avast 4.7. I just ran another scan with it and it detected Win32 CTX and I moved the file to the vault.
    Thanks in advance for your help
     
  7. reddog19

    reddog19 Private E-2

    I have tracked the problem to this file
    C:\Windows\System32\fhzhbffzxd.exe
    If I delete this file would that solve my problems?
    Spybot also just found TagAsaurus.
    Thanks for your help
     
  8. reddog19

    reddog19 Private E-2

    Hi all.
    I've used Spyware Terminator to block fhzhbffzxd.exe from running. But there is still a rogue program or process which changes my desktop appearance to "secure32.html" every 1/2hour or so.
    I haven't changed any files or settings and your help in doing so would be great.
    Thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know all about the fhzhbffzxd.exe file. It was on my to do list but I need an answer on the Embassy Security Center software first. Spyware Terminator is not a recommended application. It was on the rogue tool list for awhile too. It was delisted now but we still don't recommend it. If you only have the trial version, add it to the list of things below to uninstall! It could get in our way of doing a complete cleanup.

    Uninstall the below software:
    EMBASSY Trust Suite by Wave Systems
    EMBASSY Security Center
    J2SE Runtime Environment 5.0 Update 6
    SearchAssist

    After uninstalling these, reboot your PC. And don't worry about the fhzhbffzxd.exe process if you see it. We will be fixing it.

    After reboot install the current version of Sun Java from: Sun Java Runtime Environment

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\fhzhbffzxd.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [sys32] C:\WINDOWS\system32\fhzhbffzxd.exe
    O20 - AppInit_DLLs: wxvault.dll e1.dll deskmcd3.dll confaud.dll audstat.dll
    O20 - Winlogon Notify: audmgr - audmgr32.dll (file missing)
    O20 - Winlogon Notify: dsseds32 - C:\WINDOWS\system32\dsseds32.dll (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue. Also note that after uninstall the software at the beginning of this procedure your O20 - AppInit_DLLs line may look different. Just select it anyway.

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\fhzhbffzxd.exe
    C:\WINDOWS\system32\e1.dll
    C:\WINDOWS\system32\deskmcd3.dll
    C:\WINDOWS\system32\confaud.dll
    C:\WINDOWS\system32\audstat.dll

    Now run Ccleaner .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!
    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. reddog19

    reddog19 Private E-2

    Thanks for getting back to me chaslang.
    Since my last post my laptop really started going haywire so I uninstalled Spyware terminator, Avast 4.7 and Ashampoo. I then installed Norton systemworks 2006 which I have running on another computer. I didn't want to because I find it slows everything considerably.
    However, it did find and fix the virus "Stration A" which AVG, Avast and the on-line scanners didn't.
    The pop-up problem still exists but Norton cuts in with " fhzhbffzxd.exe is trying to change your home page......"

    When I tried to use control panel "Add/remove programs" there were only 4 programs listed so I used the tools option in Ccleaner.

    I've followed part of your instructions as follows:
    Uninstalled searchassist and spyware terminator
    Uninstalled , updated and re-installed Sun java

    When I uninstalled embassy trust suite and embassy security center using Ccleaner, no programs would load. "File windows\system32\wxvault.dll not found". I then used Norton Goback to restore to a previous state.

    The Embassy software was pre-installed by Dell.

    I didn't proceed with the rest of your instructions as I wasn't sure if they were dependent on removing the Embassy software.

    I've attached the latest HJT log and thanks for your help.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bad idea! All you had to do was complete the steps I gave you. I would dump this massive resource hog in the blink of an eye and use something better. Like AVG or Avast - but make sure they are fully updated current versions with current definitions.

    The proper and first method that should always be used to uninstall software is by going to Add/Remove programs and uninstall it from there. It may not have changed any of what resulted but this is always the safest approach. In what order did you uninstall the Embassy Software? To avoid any addition problems with it, just ignore it for now. But you must complete my steps and you must stop blocking the malware from showing up. We cannot clean what we cannot see. Unless Symantec has totally removed it (the file too), you may still have problems.



    I will be away for 9 days! Hopefully one of the other helpers here can continue to help you! Or you will have to wait until I get back!
     
  12. reddog19

    reddog19 Private E-2

    chaslang,
    I've completed your instructions.
    For some reason when I go to add/remove programs in control panel, it only shows programs starting with the leter "A". But when I change to "sort by frequency used", it shows all of them.
    The updated reports are attached,
    Thanks for you time and efforts.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm back now and trying to catch up. You need to download and use the current versions of ShowNew and GetRunKey. Both had been updated before I left for vacation. Do this now before getting the new logs I request below.

    You said you uninstalled Avast and Ashampoo but I still saw them in your previous logs. You should delete the below folders since this software is no longer installed:


    C:\Documents and Settings\michael\Application Data\Spyware Terminator
    C:\Documents and Settings\michael\Local Settings\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Spyware Terminator
    C:\Program Files\Spyware Doctor


    After doing the aboeve, please attach new logs from HJT, GetRunKey, and ShowNew and also please explain what your current malware problems are.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds