Request for help to remove the 'coolwwwsearch.com' trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by dougmarkham, Oct 25, 2010.

  1. dougmarkham

    dougmarkham Private E-2

    Recently I opened an email from someone who I thought used to be an acquaintance. My hotmail account blocked some of the contents, so I got suspicious. I ran Spybot Search and Destroy recently detected the trojan 'coolwwwsearch.com' on my machine.

    From reading other posts, it seems to be a tough one to beat.

    I followed your cleanup instructions and used SUPERAntiSpyware in safe-mode to remove as much of it as I could. I used MGTools to create HJT logs etc (see attached). Also included in that log is my system info.

    I don't know if the computer is fixed, but my anti-keylogger software is not working properly (it keeps shutting down). Can this be fully removed or do I need to do a clean re-install?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the requested logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip
     
  3. dougmarkham

    dougmarkham Private E-2

    Hi TimW

    SAS and MBAM logs are attached, along with C:\MGLogs.zip.

    My system is Windows 7 home premium, so ComboFix wouldn't install.
    Regards,
    Doug
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I am seeing in your logs is this:
    C:\Windows\tasks\At1.job

    Remove it and then do an online scan:
    eSet Online Scan.

    Then attach that log and tell me what issues you are having.
     
  5. dougmarkham

    dougmarkham Private E-2

    Hi TimW,

    ESET found
    C:\MGTools\Process.exe Win32/PrcView application
    Is that a legitimate function for MGTools, e.g. a false +ve?

    I don't know whether the trojan has embedded into my system restore points or not: I've read others have had this issue. Is this likely to be an issue?

    The main result of this virus/clean up is that Guarded ID (my kernel based anti-keylogger program) is no longer functioning as it did before hand. Now, when I type into the "IE or mozilla: find box; the google toolbar; or the URL box", numbers come up instead of letters. Also, I run a program called Personal Brain (mind-mapping software), and the same issue occurs.
    I will probably attempt to re-install this program again, as when its not running, everything is fine.

    The other minor issue is that my hook-based anti-keylogger (Keylogger hunter) no longer runs from start up, as it did before the infection.
    I am wondering if the trojan attempted to mess with these programs?

    After deleting that At1.job, it seems that the random pop up ad's have stopped coming up. Has your strategy worked?
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that was a false positive on MGTools. Have you tried uninstalling the problem software, running CCleaner and then re-installing them?
     
  7. dougmarkham

    dougmarkham Private E-2

    I've just un-installed GuardedID and used CCleaner to do a clean up and registry clean.

    I re-installed and re-activated the GuardedID licence, and it is up and running again. However: the same issue remains, typing in text into the URL box, the google toolbar, and the find box in both IE and Mozilla result in numbers instead of letters.

    I am going to call their tech support too, but re-installing hasn't helped.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not familiar with that program so maybe you should post this in the software forum. There is the possibility that someone there uses that software.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds