I cannot get rid of CoolWebSearch, need some help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by iamPatrick, Jun 5, 2005.

  1. iamPatrick

    iamPatrick Private E-2

    I would appreciate some help with this problem. I have followed all the steps in the tutorial by Major Attitude. My computer had a few trojans and various other spyware. Everthing cleaned up great except for Coolwebsearch which continues to return. I went through all the tutorial steps, and also tried to use the tutorial found here by Chaslang. Unfortunatly it didnt apply to my system because I dont have a .dll listed in my R0 or R1 lines of my "Hijack This" log. This thing just keeps returning and I dont have the expertise to get rid of it.
    Thanks for any assistance.
     
  2. mortgageguru

    mortgageguru Private E-2

    Try downloading CWShredder from offsite link removed...


    This should help you with your issue...

    Mortgageguru
     
    Last edited by a moderator: Jun 5, 2005
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not refer people to download programs from other sites when they are available on MG's.

    CWShredder is available here: CWShredder

    Also the user has already indicated that the READ ME FIRST sticky has been followed. CWShredder is included in the sticky. You need to read our sticky threads yourself to familiarize youself with their contents.

    Also, if the problem is a true about:blank or HSA hijacker form, CWShredder will do nothing to fix it.
     
    Last edited: Jun 5, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    iamPatrick,

    Please follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. iamPatrick

    iamPatrick Private E-2

    Here is my Hijack This Logfile.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see no signs of the online scanners being run. Did you skip them? Did you skip anything else?

    You do not have an HSA or about:blank hijacker problem.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a couple of Trojan.StartPage.O problems

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home
    O2 - BHO: XMLDP Class - {60371670-81B9-4d06-9C42-4DEC1AABE62B} - C:\WINDOWS\xmllib.dll
    O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\System32\SMSSU.EXE
    O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\System32\Tmntsrv32.EXE
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\xmllib.dll
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  8. iamPatrick

    iamPatrick Private E-2

    I did not skip anything. What online scanners are you reffering to? Trendmicro?
    Everytime I run ad-aware, I get coolwebsearch. Everytime I run internet explorer I get directed to about:blank page. Also everytime I run HSRemove it comes up with 8 items and says it has removed them. Then they are back.

    Sorry I was typing this before your last reply came through.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Both Trend Micro and Symantec. They leave traces that would be seen in you HJT log. However, if you ran the Java version of Trend Micro it will not leave any trace.

    Post your Ad-aware log. It is probably just minor registry keys.
    You do not new HSremove. You do not have the hijacker. Also HSremove will always show 8 items removed, even on a clean system and even after running it many times. It is a bug that has never been fixed.

    Complete the steps in my previous post.
     
  10. iamPatrick

    iamPatrick Private E-2

    Ok,
    Yes I did scan with java because I was using FireFox. I now realize I did skip the symantec scan (sorry).

    I attempted to follow the instructions in the last post. I was unsuccesfull at killing the processes. They kept re-appearing. I went ahead with the instructions anyway, except I could not delete C:\windows\system32\smssu.exe , or C:\windows\system32\Tmntsrv32.exe. It said access denied. At that time I tried closing the processs, but they would reapear shortly after. Do we have to delete these from dos? Also here is a new Hijack This log, and my ad-aware log.
    thanks
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get the processes closed or you cannot delete the files. Try booting into safe mode and ending the processes. Select both of them at the same time with HJT and then select Kill. Then fix the O4 lines and delete the files. (don't forget the DLL) See if that works.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have a c:\windows\hosts file, delete it while booted in safe mode.

    The Ad-Aware message about C:\WINDOWS\System32\wbem\logs\wbemess.log is really a false positive. This is just a log file. There is nothing to be worried about from it. wbemess.log is on all WinXP systems.


    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixcws.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixcws.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
    This is not the about:blank or HSA form of the hijacker
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still could not delete the problem files and HJT lines in safe mode, try the below steps.

    Download Pocket KillBox and extract it to its own folder.

    IMPORTANT: Now print these instruction or copy them locally. I want you to run all of the below steps while physically disconnected from the internet. Do not reconnect until I say to do so. And do not open a browser until I say to.

    OK! Disconnect now before continuing.

    Now run killbox.

    Now, Copy and Paste C:\WINDOWS\xmllib.dll into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No!

    Now, Copy and Paste C:\WINDOWS\System32\SMSSU.EXE into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No!

    Now, Copy and Paste C:\WINDOWS\System32\Tmntsrv32.EXE into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click Yes and allow Killbox to reboot your PC.

    If you get an error message about "Pending Operations" just reboot your PC yourself.

    Now get a new HJT log.
     
  14. iamPatrick

    iamPatrick Private E-2

    It will not let me kill those two processes. When I attempt kill both at the same time in safemode, from Hijack This, it says "the selected process cannot be killed. It may have already closed, or it may be protected by windows".
    One thing I did do was to try to kill the processes and delete the files at the same time. The files actually disappear for a second then reapear with the processes on task manager.

    ...again I typed this before I saw your previous post, will get right on that,
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you do what is in both message #12 and #13
     
  16. iamPatrick

    iamPatrick Private E-2

    Ok I have performed both message #12 and #13.
    Here is a new log. I wasnt sure if you wanted me to then try to kill those 2 processes, or fix those lines in HJT after running the Pocket Killbox. I did not.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell me what happen while doing message number 13. Did killbox complain about anything? Did it actually locate the files?

    Try doing the below after booting in safe mode:

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\xmllib.dll
    then click OK. If a dialog box confirming this action appears, click OK.
    If you get an error message, tell me later and continue.

    Run the steps from message number 13 again while in safe mode. Let me know if killbox gives any error messages at all. Also does it find the files (when it finds them, you will see the file name in blue).
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also tell me if you see any of the below files:

    c:\windows\explorer32dbg.exe
    c:\windows\iexplore_dbg.exe
     
  19. iamPatrick

    iamPatrick Private E-2

    Yes when I ran it the first time everthing worked fine. It found the files and didnt give any errors. I will run it again.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also look for these and let me know if found:

    C:\Windows\Atlass.dll
    C:\Windows\System32\ALGU.exe
    C:\Windows\System32\SPOOLSV32.exe
     
    Last edited: Jun 6, 2005
  21. iamPatrick

    iamPatrick Private E-2

    Ok I tried to run "regsvr32 /u C:\WINDOWS\xmllib.dll", but it gave me an error. Not an exacutable, and no registration helper is registered for this file.

    I went through steps from message #13 again, in safe mode. (no errors)

    I do have these 2 files....
    c:\windows\explorer32dbg.exe
    c:\windows\iexplore_dbg.exe
    none of the other ones are there.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixtsp.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixtsp.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.




    Then do the steps with killbox again but add two more files to the procedure (at the top)

    Now, Copy and Paste c:\windows\explorer32dbg.exe into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No!

    Now, Copy and Paste c:\windows\iexplore_dbg.exe into the box – If it exists, it will show up in Blue. Check the option to Replace on Reboot and also check the Use Dummy option and also check the End Explorer Shell While Killing File option too. Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No!
     
  23. iamPatrick

    iamPatrick Private E-2

    Ok I performed exactly like you said, but now I have no icons or taskbar. No desktop at all.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you enter: c:\windows\explorer32dbg.exe and c:\windows\iexplore_dbg.exe
    Or did you enter c:\windows\explorer.exe ?

    Hit CTRL-ALT-DEL to bring up Task Manager and click on File, New and enter explorer.exe and click OK. Does that work and bring back your Desktop.
     
  25. iamPatrick

    iamPatrick Private E-2

    Yes actually I copy and pasted it in from your post.(c:\windows\explorer32dbg.exe, c:\windows\iexplore_dbg.exe)

    It will not bring me back to descktop though. It says it cannot find c:\windows\explorer.exe even though I see it right there.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the same thing with to bring up Task Manager but enter the full path to the file:
    c:\windows\explorer.exe

    How are you looking for files if explorer is not running?
     
  27. iamPatrick

    iamPatrick Private E-2

    It gives me a browse button from task managers run command. I have tried entering full path
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you running Internet Explorer from this problem PC in order to come here?
     
  29. iamPatrick

    iamPatrick Private E-2

    LOL... no I am on another computer.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From Task Manager, enter cmd and click OK! Does a command prompt window open?

    If so enter the below and tell me what happens:

    cd c:\i386

    dir explorer.*
     
  31. iamPatrick

    iamPatrick Private E-2

    Yes at command prompt, it tells me that in directory C:\i386 2 files explorer.ex_ and explorer.SC_
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now type the below and tell me if what it says.

    expand explorer.ex_ c:\windows\explorer.exe
     
  33. iamPatrick

    iamPatrick Private E-2

    It said expanding explorer.ex_ to c:\windows\explorer.exe
    explorer.ex_ 351603bytes expanded to 1004032bytes, 185% increase
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now at the command prompt type:

    explorer.exe


    What happens?
     
  35. iamPatrick

    iamPatrick Private E-2

    grrr. It still says windows cannot find explorer, or c:\windows\explorer
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Go back and do the below again (notice it is slightly changed to make a copy in the i386 folder);


    expand explorer.ex_ explorer.exe

    Now enter:

    explorer.exe

    Does that work?
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note these problems we are having are all due to the infection you had. It attaches itself to explorer.exe and iexplore.exe (that Internet Explorer) and that's why we were having problems removing it.
     
  38. iamPatrick

    iamPatrick Private E-2

    No it still didnt run says cannot find file c:\i386\explorer.exe
     
  39. iamPatrick

    iamPatrick Private E-2

    yes and I very much appreciate your help with this problem.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you type in regedit and hit enter does the registry editor open.
     
  41. iamPatrick

    iamPatrick Private E-2

    yes it does
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That's good. Are you familiar with using regedit?


    Does your prompt currently say somethings like:

    c:\i376>

    If so, type

    dir explorer.*

    do you see explorer.exe in the list and what is the file size.
     
  43. iamPatrick

    iamPatrick Private E-2

    I am only a little familiar with regedit.
    Yes it is showing explorer.exe in c:\i386 file size is 1004032
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Type in the below:

    copy explorer.exe myexp.com

    Then type:
    myexp.com

    Does that bring up an explorer shell (desktop)?
     
  45. iamPatrick

    iamPatrick Private E-2

    Yes that brought up windows explorer shell, but not full desktop.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have any way you can put the below quote box text into a file named fixtsp.reg and then get it copied to the problem PC. Perhaps a floppy disk?

     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are the below files actually gone now?
    c:\windows\explorer32dbg.exe
    c:\windows\iexplore_dbg.exe
    C:\WINDOWS\xmllib.dll
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE
     
  48. iamPatrick

    iamPatrick Private E-2

    Ok I got it. do you want me to run fixtsp.reg?

    Sadly all are files are still there except
    c:\windows\explorer32dbg.exe
    c:\windows\iexplore_dbg.exe
    which looks like those two are probably now
    c:\windows\explor~1.exe
    c:\windows\iexplo~1.exe
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means they are all there. Those are the shortened DOS names. If you use that explorer window that opened I would expect the full name to appear.

    Bring up Task Manager again and then Processes. Find Explorer.exe , Highlight it (if running) and End Process. Ignore the warning. This would make your desktop disappear if there is a desktop. If you see any of these files in the process list then End them too.

    explorer32dbg.exe
    SMSSU.EXE
    Tmntsrv32.EXE
    iexplorer.exe
    iexplore_dbg.exe
    iexplore.exe

    Now from the command prompt Window you need to be in the folder where you saved the fixtsp.reg file. It would probably be easist if you had copied it to c:\i386 where we were last working. Then enter the below command.

    regedit /s fixtsp.reg

    Then run pocket killbox and have it fix all of those files again. The list is below:

    c:\windows\explorer32dbg.exe
    c:\windows\iexplore_dbg.exe
    C:\WINDOWS\xmllib.dll
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE


    Let me know how that works out. I need to get some sleep now. It's 3 am here.
     
  50. iamPatrick

    iamPatrick Private E-2

    Thanks for all your help tonight I have to get to sleep now too. Long day at work tommorow.

    What is interesting though is from the windows explorer shell it shows those files as c:\windows\explor~1.exe
    c:\windows\iexplo~1.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds