help removing coolwwwsearch

Discussion in 'Malware Help (A Specialist Will Reply)' started by rgkleidman, Feb 4, 2005.

  1. rgkleidman

    rgkleidman Private E-2

    I can't seem to get rid of coolwwwsearch
    I have followed all of the instructions on the posting here and then some. I booted into safe mode and enabled the show hidden files and disabled system restore. I have run ad-aware, spybot, sysclean as well as trend micros online scanner, the cws shredder, ccleaner, norton anti-virus and I also ran a-squared.
    The shredder finds and removes the cws boot config. A-squared always locks up and dies in the same place c\windows\ServicePackFiles\i386\.
    I have found and removed various trojans and spywares but in the end spybot always shows that all the cws junk has come back.

    Symptoms: IE will open (I usually use firefox) and take me to sites selling spyware removal tools and other advertisements. Various icons for casinons, amazon, spyware cleaners are placed on my desktop.

    Infection source: I was looking for a version of divxplayer that did not have adware. I looked for and found what a thought was a benign version called divxlite. This is what installed all this malware.

    I'm running windows xp pro with all of the patches and service pack 2. I have 3 spyware scanners on my machine as well as norton anti-virus. I update and run scans regularly but nothing seems to help.

    If I need to scrub my c drive and reinstall the os that's o.k but I'd like to know if there is another way to beat this.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. TheOldThug

    TheOldThug First Sergeant

    Welcome :eek:

    I see Chas beat me to it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I caught you napping! ;)
     
  5. rgkleidman

    rgkleidman Private E-2

    Here is the log file. I shut off everything I could except cybersitter since that would involve an uninstall and resinstall
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run all the steps in the READ ME FIRST as required. You never ran the online scanners. Is there a reason for that? Was anything else skipped?

    You have several problems including a nasty VX2 problem and a Narrator trojan. I'll get back to you with the starting steps.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must stop using msconfig to control what programs are being loaded at boot up. Please run msconfig and select normal startup. You don't need to reboot right now if prompted to do so. Wait until later.

    Please download the following tools and save them where you will be able to find them. I save stuff like this to a C:\downloads\Spyware-Stuff folder and I put each in their own subfolder. It makes it easy to find. Make sure you download them from the links below:

    L2MeFix Tool

    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox

    LSP - Fix


    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing


    First Step:

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Second Step:

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Extract all the files from the Generic Detection Tool into its own folder.
    Then run find.bat. Post the log it creates back here as an attachment (do it later when we reconnect).

    Third Step:
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Fourth Step:
    Get a new HJT log.

    Now reconnect and come back here and post as attachments the l2mfix log the find.bat log (normally already named output.txt) and the new HJT log (this will require two posts as only two attachments can be made in a message).Based on those logs, we will determine the next steps. Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
    Last edited: Feb 4, 2005
  8. rgkleidman

    rgkleidman Private E-2

    First of all thanks for all of your help.

    I have changed msconfig back to normal start up and will reboot when you tell me to do so. I went this route because there were some annoying things I couldn't get rid of at start up that I will ask you about when we are all done.

    I ran the LSP-Fix and there was no aklsp.dll This may reflect some other actions I took prior to submitting my problem to you.

    I will upload my logs but I wanted to mention another oddity. In my base station management tool for my home network I found some entries that I don't remember adding for port forwarding: iC5060 on port 5060 and msmsgs on inbound ports 5593, 3556 and inbound 7079 and 1283. Could these be related to any of my issues? If not, how did these get there and what are they?
     

    Attached Files:

  9. rgkleidman

    rgkleidman Private E-2

    One more thing, I did run the online scanners. The trend micro-scanners found 3 versions of the same trojan that it could not clean and I deleted them. I can't recall but I may have run the scanners in safe-mode.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log still does not show any indication that the online scans were run. If you ran the Symantec and Trendmicro online scans there would be O16 entries for both of them.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Step 1:

    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log later when the remaining steps are completed.

    Again, don't run any other files in the L2MFix folder.

    Step 2:

    Run "find.bat" from the Generic Detection Tool again!

    Okay after doing the above DO NOT REBOOT. Now reconnect to the internet and come back here and post and attach the find.bat log along with the L2MeFix Log.

    You have other problems two along with a Narrotor trojan and some Qooligic problems. We will get to them later.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's worry about those later after fixing all the problems I can see (there are a bunch).

    Question: Do you use C:\Program Files\Messenger\msmsgs.exe
    That's Windows Messenger. It's not the same thing as MSN Messenger. If you do not use it. Try running this: Uninstall Messenger

    That may take care of some of those inbound items.
     
  13. rgkleidman

    rgkleidman Private E-2

    The generic detection tool did not produce a log file that I was able to find. The window open and shut quite rapidly and I was unable to read the message there.
    Do you want me to re-run the on-line scanners?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No don't run anything else but what I ask.

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\ykqkrq.exe
    C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
    C:\WINDOWS\system32\vmss\vmss.exe
    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ntechin] C:\WINDOWS\system32\n20050308.exe
    O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [vmss] C:\WINDOWS\system32\vmss\vmss.exe

    After clicking Fix, exit HJT.

    Now copy and paste the information in the below quote box to notepad. Save it to your Desktop as type "all files" and name it fixrun.reg. Doubleclick it and grant it permission to merge in the registry entries.
    We have some files that we need to delete using Killbox. Following is a list of files and the how to delete will be explained further down.
    C:\WINDOWS\system32\gpipoi.dll
    C:\WINDOWS\system32\pqxqwx.exe
    C:\WINDOWS\system32\zasabs.dll
    C:\WINDOWS\system32\qvgvbg.dat
    C:\WINDOWS\system32\n20050308.exe
    C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
    C:\WINDOWS\system32\vmss\vmss.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ynfntf.exe

    and C:\WINDOWS\system32\ykqkrq.exe

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINDOWS\system32\ykqkrq.exe (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\system32\gpipoi.dll



    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINDOWS\system32\ykqkrq.exe into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally. If you get an error message about "Pending operations", just reboot manually.

    Please note any error messages that you see during reboot and copy down the exact full message if you do get any. This could occur due to us removing this malware as it attempts to reload itself. Post those error messages when you come back to post the logs.

    After reboot:
    1) Run Windows Explorer and delete the below two folders:
    C:\WINDOWS\system32\wsxsvc
    C:\WINDOWS\system32\vmss

    2) Try to run the Generic Tool again (make sure you wait long enough for it to complete). Post the log from the Generic Tool's find.bat program and also post a new HJT log.
     
  15. rgkleidman

    rgkleidman Private E-2

    There were no error messages on the reboot.
    A couple of oddities. I had to reinstall the findit tool. There are two other files that unzip with the .bat file that were no longer present in the folder. After I ran the tool this time the same two files disappeared.

    On boot-up norton auto-protect does not load. I have to do that manually. Does this indicate another problem?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! All of the fixes did not take We are going to do some steps over with some slight changes in options on Killbox.

    Now copy and paste the information in the below quote box to notepad. Save it to your Desktop as type "all files" and name it fixnarrator.reg. Doubleclick it and grant it permission to merge in the registry entries.
    Here are the files that we need to delete using Killbox.
    C:\WINDOWS\system32\gpipoi.dll
    C:\WINDOWS\system32\pqxqwx.exe
    C:\WINDOWS\system32\zasabs.dll
    C:\WINDOWS\system32\qvgvbg.dat
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ynfntf.exe

    and C:\WINDOWS\system32\ykqkrq.exe

    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Delete on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINDOWS\system32\ykqkrq.exe (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\system32\gpipoi.dll

    1) Now, Copy and Paste fullpathfile into the box
    2) Now, Click the Red X and Yes to the confirmation message.
    3) A message will ask if you want to reboot now – Click NO.
    4) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINDOWS\system32\ykqkrq.exe into the box. Make sure you still have Delete on Reboot selected. Then click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot Normally. If you get an error message about "Pending operations", just reboot manually but tell me if you are getting this message.

    Please note any error messages that you see during reboot and copy down the exact full message if you do get any. This could occur due to us removing this malware as it attempts to reload itself. Post those error messages when you come back to post the logs.
     
  17. rgkleidman

    rgkleidman Private E-2

    There were no messages of any kind during shut down or reboot.
    Although you weren't explicit I assume you wanted the same logs as last time.
     

    Attached Files:

    Last edited: Feb 6, 2005
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looking better!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch

    After clicking Fix, exit HJT.

    Run Pocket KillBox and Copy and Paste the Following into the box: C:\RECYCLER\Desktop.ini - Click Red X to delete it using Standard File Kill.

    NOW:

    Open VX2Finder and Click on the "Find Vx2.Betterinternet" button.

    Then click on these buttons in the right pane unless they are "greyed" out:

    - UserAgent$ Button to remove the UserAgent from the registry
    - Guardian.reg
    - Restore Policy

    Exit and reboot.

    Post another hopefully final HJT log.
     
  19. rgkleidman

    rgkleidman Private E-2

    Two oddities: there was no Desktop.ini file. I did empty the recycle bin shortly before I started the procedure and I purged the Norton protected files this morning.
    Norton Auto-Protect still does not load on boot-up
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is now clean. Check you options for the AutoProtect and see if it has a setting wrong. I do see it being loaded in the O4 section of your log but it does not seem to be running.
     
  21. rgkleidman

    rgkleidman Private E-2

    Thanks again for your help Dr C.

    Auto protect does seem to be set correctly. There is one account where it does not load but it seems to on the others. I know the account where it does not load has in the past not been an administrative account but it is now.

    Some other questions:
    What do I do next?

    Your preventing malware infections posting lists some free anti-virus softwares. Should I chuck Norton and go with one of those?

    Do I need an additional firewall? My router has a firewall and I use the windows default firewall. With these two in place I did a Nessus scan of my IP address and it wasn't able to see very much. I used to use Zone Alarm. The free version would eventually lock up and be a real pain to remove.

    You told me not to use selective start-up. There are seveal pieces of software that don't come with options in their own preferences to prevent them from loading: quicktime, roxio, windows messenger, and one more I can't remember now. What is the correct way to keep them from loading? Is there a way to get rid of windows messenger?

    Every once in a while I write articles for a local community magazine for people who are new to the world of computers. Ironically, I just completed one on spyware. I plugged your site. If you'd like I can upload you a copy.

    I am a minor geek. I do some simple windows administration at work and I know more than the average bear. How do I start to learn to become a major geek like you guys? I would like to understand the tools you used to clean my machine and I would like to be able to help others like you guys helped me out.

    Last but not least is there some way to make a donation to the site?
     
  22. Blaine

    Blaine Private E-2

    You can support the site by clicking the ad banners from time to time that are on the site... I think there is a donate option somewhere but I can't find it anymore, pretty sure I used it once in the past although I might be wrong.
    You can remove messenger, there is a post in the software forum about it. I'm paste the link but can't figure out how to set my mozilla config options to do so hehe. Just use the search button up above next to new posts and search "messenger remove" and you'll find it. I don't know the answer to the rest of your questions but I'd love to know how these guys become the major geeks they are... I'm more of a gee, almost to a minor geek I think lol.

    Anyhow, hope that helps you out a bit with two questions.

    Blaine
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    If you like Norton and feel comfortable with it and most important have a paid subscription where you get constant updates, then you can keep it. If you do not get updates then you need to subscribe or uninstall and use one of the other free AV's I list.

    Yes you need to use a software firewall in addition to your router's but the one in Windows is not very good. Disable the one in Windows and try Sygate's.

    The item from Quicktime never needs to be loaded. You can just have HJT fix that entry and it will no longer load at Startup. That does not stop Quiktime from working.

    What items from Roxio don't you want to load? Do you ever need them?

    Do you use Windows Messenger? Most people never use it and you can uninstall it if you do not. Uninstall Messenger

    Yes! Post it! Is it in file you can attach, like a Word Document?

    Lot's of reading and studying to do. There are lots of aspects to know about your PC not just malware. Read the Software, Hardware, Networking, and Spyware Forum threads. Search the internet. Ask questions and take notes. Save good links for reference.

    You can buy a Majorgeek's teashirt and send your friends here.
     
    Last edited: Feb 8, 2005
  24. rgkleidman

    rgkleidman Private E-2

    I will follow your other suggestions on firewalls etc.

    What I meant by what do I do next was should I run spybot, ad-aware, and pest patrol followed by any scanners. Or am I more or less clean and just need to do regular updating and sweeping.

    A t-shirt purchase will be coming soon. My wife the meteorologist wants one too but we may give it to the teen we helped raise who drives around looking for unsecured networks that he can secure for a modest fee. I have already sent others to the site and with the bosses approval will be sending around a note to my co-workers to check the prevening infection posting.

    Thanks again Dr. C and you too Blaine.

    O.K. I'm uploading the article. It was written for an audience containing a fair proportion of people who might be technophobes (the Orthodox Jewish community of Baltimore). This might also account for some references that don't make sense. Better to blame this than my poor writing style. My first article was about filtering internet access for families. Speaking of which do you know of any way to password protect the ability to boot into safe mode?

    Last but not least I love your signature file Dr. C and have started spreading the joke around although I will not steal it as my own signature file.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy to see you are writing something to help others avoid some of the problems related to malware.

    Some comments on your article. Take it as constructive/educational criticism.
    Not always! And not always very clear about what they will be doing. They really try to hide it from you in many cases.

    Plug Majorgeeks from now on. We have all the downloads available and we verify that they are clean and worth using unlike many other sites.

    It's Ad-Aware SE. Ad-Aware is old and not what you want.

    Technically that is not completely true. There emphasis is virus/trojan but they do detect various forms of spyware. You can even see it in the names that give to some items. They even precede it with Adware.xxxxx (where xxxxx is the name of the spware).

    One item you should have mentioned that is even more important than spyware blockers or scanners is a firewall. No PC should be connected to the Internet without one.

    Good job! Keep educating the novices and maybe we will have a fighting chance.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds