How do I get rid of CoolWebSearch trojan?

Discussion in 'Malware Help (A Specialist Will Reply)' started by daemonchild, Aug 11, 2005.

  1. daemonchild

    daemonchild Private E-2

    O/S: Win XP on PC

    According to Norton, have the trojan.smartsearch.M
    AdAware lists it as a variant of CoolWebSearch.
    Installed TrendMicro to get rid of it and that didn't work.
    Spybot detects it as well.

    All four programs delete it, then when IE 6.0 is reopened, it comes back.

    Ideas?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. daemonchild

    daemonchild Private E-2

    Okay, I read the tutorial after I posted...was in a rush (sorry about that)...would a system restore fix the problem?

    i.e. Instead of running through all of those steps. This is a work computer and time is an issue.
     
    Last edited: Aug 11, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may or may not fix the problem. You need to restore to a time frame when the PC was clean (not always easy to know). Don't forget restoring to an older date restores the registry to that point in time which means anything you installed or tweaked that is saved in the registry after that date is lost too. I'm not trying to talk you out of it, I'm just informing you of possible other consequences. Choosing a restore point could also bring back old problems that may have been cleaned in the past. The choice is yours.
     
  5. daemonchild

    daemonchild Private E-2

    Hello,

    We followed the antivirus/spyware direction to the letter and have performed about 4 or 5 times now. Every time, we clean the trojan off the box in safe mode - we then clean additional files off the box in regular mode - even tried deleting them through Hijack this! - and it decides to repopulate.

    Can't do a system restore (even though we knew a safe point) because the only sysrestore that's available is from today, which has the trojan attached to it. AdAware also showed a possible hijack attempt.

    After looking at the Hijack! this file (attached), what would my options be? Would we have to reformat the hard drive?

    Thanks for all of your hard work,

    Monica
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are a long way from having to worry about formatting.

    You have a SE.DLL type hijacker (another form of about:blank).

    Please download this file: SpSeHjfix109

    Unzip it to your desktop or to a folder.

    Boot into Safe Mode

    Start SpSeHjfix, click on " Desinfecton starten" (the other button means close) then it will reboot and finish the cleaning.

    Run SpSeHjfix one more time.

    Reboot in Normal mode.

    Run HijackThis again and post a new log. Also post the log from SpSeHjfix, the log should be on your desktop or the same folder as SpSeHjfix. And finally tell me how things are working.
     
  7. daemonchild

    daemonchild Private E-2

    Hi,

    Ran that program - log file did not download onto desktop so I do not have that to post.

    How's the computer running? I ran that program, and the minute I booted back up to "normal" mode automatic win update came up and I was able to change the IE home page with no problem.

    I posted the new hijackthis! file and did not delete anything from the list.

    Glad to hear we don't have to reformat...

    M
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log will be wherever you installed the program. Did you install it to your Desktop?

    Did you extract the executable file from the SpSeHjfix109 zip file and then run it? Did you actually see it run okay?

    Have HJT fix the below lines (but close ALL browsers before clicking Fix):


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/space.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/space.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    F3 - REG:win.ini: load=??? ?

    No reboot and post a new HJT log.
     
    Last edited: Aug 15, 2005
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If the se.dll lines come back after doing what I said in my previous message then follow the steps below.

    Download: "StartDreck", from here: http://www.niksoft.at/download/startdreck.htm
    Look to the bottom of that page and click the Download link. It should give your StartDreck217.zip

    Unzip to its own folder and start the program,
    Press 'Config'
    Press 'Unmark All'
    Check the following boxes only:
    Registry -> Run Keys
    System/drivers> Running processes
    Press 'Ok'
    Press 'Save' and select the location to save the log file
    (default is the same folder as the application)

    Please attach the log in this thread.
     
  10. daemonchild

    daemonchild Private E-2

    The reason why I didn't post the SE file is because for whatever reason it did not post separate from the original program--it posted within the program. I ran hijack this! just now and fixed the registry entries, they did not repopulate. (Which is the reason why I didn't bother posting it atm, however I will try to see if it does it again tomorrow after a reboot.

    Getting this box to work again, is very appreciated!

    Monica
     
  11. daemonchild

    daemonchild Private E-2

    Okay? I take that back...maybe we're "not there yet"...opened IE after all of that and about:blank came up in the address search bar. Tried changing the home page in properties, reloaded and nothing. Closed the browser, opens to the correct home page. Tried, oh, 2 or 3 times after that and can't make it do it again.

    Logfile posted below.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds