I can't get rid of Coolwebsearch (CWS_NS3)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Asilverman, Mar 27, 2005.

  1. Asilverman

    Asilverman Private E-2

    I tried everything recommended by this site. I ran my Spy Sweeper. With all this done this damn thing keeps on coming back. It is jamming my IE and my Spy Sweeper. Attached is a log from Hijackthis. Please help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like you have read and followed the steps in the sticky threads. You log shows no signs of the online scanners being run. Also you did not stop and disable the Remote Procedure Call (RPC) Helper service per step 2 in the READ ME FIRST. You must do this. Also, you would not have posted a log one was requested and you would also know that HijackThis logs should be posted from a system running in normal boot mode not safe mode.

    Your problem is an HSA hijacker.

    Also you should look in Add/Remove programs and uninstall if found:
    WildTangent
    WeatherBug

    Do you know what the below process is related to?
    O4 - HKCU\..\Run: [acctres] C:\WINDOWS\System32\acctres.exe

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Whovian33

    Whovian33 Private First Class

    SpyBot S&D can remove this for you; get a download from majorgeeks.com--you might have conflict problems with SpySweeper, though. OLB
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PLEASE STOP! Spybot is not the answer to everything and in fact it will not remove an HSA hijacker. No existing programs that are available will remove a true HSA hijack. Some of them help locate a few of the problem files but they do not effectively remove them. Spybot will do nothing for this problem at all.

    I realize you are just trying to help, but your information is incorrect.
     
  5. Asilverman

    Asilverman Private E-2

    I went to the Add/Remove programs page and removed WeatherBug but I did not find WildTangent. I did a manual search of WildTangent and it came up but my computer wouldn’t let me delete it.

    I went through “Read Me First” and did everything as directed except for Alternative Scans because they were too complicated for me.

    I do not know what “O4 – HKCU\..\Run: [acctres] C:\WINDOWS\System32\actress.exe” is.

    I had no problems running complete scans. The Ad-Ware SE even found coolwebsearch and I deleted them but it keeps on coming back.

    My IE keeps on getting jammed after a few minutes of start up and my spy sweeper gets jammed after a few minutes of help.

    Please review HJT log, I would greatly appreciate help regarding this matter.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try right clicking on C:\WINDOWS\System32\acctres.exe and select Properties and then the Version tab. Go thru the Item name: list and determine who the company is. There is a chance that this is: Sak Labs - AppAlarm. This was supposedly an application security tool that prevents unwanted processes and applications from running. Does it sound familiar to you.

    In step 2 of the Getting Prepared section of the READ ME FIRST, we asked that you stop and disable any of the three services listed. You must go follow that step so that HijackThis can repair the O23 line.

    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\atljz32.exe (file missing)

    Please go back and do that now. If it is already stopped and disabled or it does not show up just continue with the below steps. Either way, follow the steps below! Do not stop any other services. If you do not match exactly word for word Remote Procedure Call (RPC) Helper, do not touch it.


    Please run HijackThis click on the "Open the Misc Tools Section" button on the open page. Then select "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK:
    Remote Procedure Call (RPC) Helper
    If that does not work try entering the short name: 11Fßä#·ºÄÖ`I
    You will need to cut and paste the short name since the characters are not easily typed.

    After doing the above exit HijackThis.

    Make sure you have both about:Buster and HSremove downloaded from the READ ME FIRST. And make sure you have UPDATED the database for about:buster. I believe it is up to number 25.

    You need to print or save these instructions locally because after this reading this sentence you will need to physically unplug your connection from your cable, ADSL, or dial-up modem to your PC and then you MUST exit all browsers and DO NOT run any again until requested.

    Okay, unplug your internet connection and exit browsers now!!!!
    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\mfcqa32.exe
    C:\WINDOWS\sdktn.exe


    After killing all the above processes, click "Back" button that is just under the process list next to the Run button.

    Select the "Delete an NT service" on the left-hand side. A "Delete a Windows NT Service" window will pop up. Try entering the following into the box and then click OK (I'm just double checking to make sure it has not restarted because sometime it does).

    Remote Procedure Call (RPC) Helper

    If that does not work try cutting and pasing in the following short name: 11Fßä#·ºÄÖ`I
    You must use cut and paste since the characters cannot be easily typed.

    Tell me what happens while doing the above. If you are told that the service must be stopped. You need to go back up to where we stopped and disabled this service as mentioned previously. Then repeat the above steps to have HJT Delete this NT Service.

    After killing all the above processes and deleting the NT Service, click "Back" on the lower right. Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now (DO NOT OPEN ANOTHER BROWSER UNTIL AFTER POWER DOWN AND POWER UP, see below):

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\jpxpy.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {8D2AADC8-5DBE-E870-1462-5E5624EFD2B6} - C:\WINDOWS\mfcna32.dll
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [sdktn.exe] C:\WINDOWS\sdktn.exe
    O4 - HKLM\..\RunOnce: [mfcqa32.exe] C:\WINDOWS\system32\mfcqa32.exe
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\atljz32.exe (file missing)

    Then exit HJT after clicking FIX

    Run Windows Explorer and look for and try to delete (sort the listing in windows explorer by Modification dates and look for possibly other similarly name files from the same date - let me know if you find others even if they have different 3 character extensions like .dat, .ini, .dll, .exe but DO NOT delete anything on your own.):
    C:\WINDOWS\jpxpy.dll
    C:\WINDOWS\mfcna32.dll
    C:\WINDOWS\system32\mfcqa32.exe
    C:\WINDOWS\sdktn.exe
    C:\Program Files\WildTangent <--- the whole folder.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. If you cannot find or delete them, note which ones and continue (tell me the results when you come back here).

    - Run about:Buster and save the log to ab1.log (make sure you let it do the second scan).

    - NOW PULL THE POWER PLUG TO YOUR PC! Yes, you read that correctly. This is very important! I do not want you to power down the normal way.

    - After that wait a minute or two and then power up into safe mode (still with no internet connection available and do not open any browsers). Only run what I request.

    - Empty your Recycle Bin and delete all files in the c:\windows\prefetch folder. In fact as an additional measure do the following, run Ccleaner that you installed while running the READ ME FIRST.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    - Run HSremove and then run about:Buster again and save the log to ab2.log (let it do second scan)!

    - Immediately after about:buster completes, reboot in normal mode. (you do not need to pull the powser plug here. Just reboot.)

    - Plug your cable to the internet back in now.

    - Open and close a couple of IE sessions and then with IE closed get a new HJT log.

    - Now come back here and post both about:Buster logs and the new HJT log. And tell me what happened during the procedure.

    Let me know anything else that you notice.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds