Had Coolwwwsearch/Please check my log

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by choadlife, Aug 8, 2004.

  1. choadlife

    choadlife Private E-2

    I've done full scan in safe mode. Still getting problems.
    Here is my Hijack this log.
     

    Attached Files:

    Last edited by a moderator: Aug 8, 2004
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Start here:
    http://forums.majorgeeks.com/showthread.php?t=35407

    Check back with us from there, we might want to see your logfile then. Also, read the Hijack This tutorial. While I am hesitant to read your logfile before knowing what you have scanned with per out spyware removal tutorial, heres some suggestions. Please note this is not a complete analysis, just some to give you an idea. Frankly, you should close your browser, keep it closed, do the tutorial, then run Hijack this and remove.

    Remove:
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\5sluo27d16.dll
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

    Not 100% on this one, but it smells very fishy to me:
    O20 - AppInit_DLLs: xzbvcd97fb1sk.tlb
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Major,

    This line is okay!
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

    It's part of Sonic Solutions software for cd recording! I'm not sure if it needs to be loaded at startup but it is not necessarily a problem.

    Note: The O2 DLL and the O20 AppInit_DLLs lines are definitely problems and they are pains in the *ss to get rid of on some issues. We will most likely have some iterations on those. In fact, after thinking about it a little, those lines I was thinking that might be trojans, could be related to the O2 and O20 lines. These are the two other lines I'm referring too:
    C:\WINDOWS\System32\oyiwkk.exe
    O4 - HKLM\..\Run: [uagnvqlxipiv] C:\WINDOWS\System32\oyiwkk.exe

    They are going to require some steps like I was using in the below thread to fix and can be difficult especially if directions are not precisely followed:
    http://forums.majorgeeks.com/showthread.php?t=38783
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds