July 6th, 2004, 01:57 PM
|
#1 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Chicago
Posts: 2,163
| Nasty Trojan - Need Help Please
Windows XP w/ SP1A and IE6
I've been hijacked by 'CoolWebSearch' and i'm having major problems.
What happened: Installing weather watcher program (clean install), went back on the net without running msconfig and re-enabling 'Normal Startup' (and Zone Alarm / Norton).
What it did;
Changed browser homepage to 'about;blank'
Everytime I tried to opened windows explorer windows installer would activate and run in a continous loop. Same when trying to run Spybot nuker (only spyware removal tool I could DL)
Would not let me past TechIMO homepage to the forums for help.
Would not display any page from google's "hits" that had spyware removal tools (page not found)
Finally managed to get to Ad-aware to DL the newest version, said it was DLing but would not.
Went to Trendmicro's site to run there AV scanner, kept crashing IE right before the scan would begin.
Went to Windows Update, said I was not the administrator and when I would log in as such kept coming back with incorrect user. Tried to use the 'Run as' command, no go.
Every once in awhile windows pops a message up saying that my xp sp1 contains unrecognized file versions but will not let me repar them (msv...dll)
What I did;
DL'd and installed Mozill Firefox browser.This allowed me to DL the newest version of Ad-aware. Ad-Aware would remove the files but they would return.
DL'd CWSshredder and Hikackthis. CWS would remove malware but again they would return. The last (3rd ) time I ran the program it had to start with misc letters n the tittle bar because I had a variant2 of the trojan which would otherwise not let it start. WOW
Ran Hijackthis which found 7 entries and removed them. There are still entries that I don't recall seeing before.
Ran spyware nuker, found 1 entry but said I would have cough up $30.00 to remove it. I don't think so, I removed the program from the comp.
Where i'm at;
Back to being able to use TIMO forums, randomly. Still receiving the occastional 'page not found' message.
I still cannot access Windows update, same problem persists.
I removed Mozilla Firefox. It stopped working soon after I ran Ad-Aware, CWSshredder and HijackThis. I liked the browser but somethings wrong. Firefox does not contain spyware, right?
I went into services and disabled 'Windows Installer' but it keeps tring to pop-up (flashes open and then closes, looping for 6-7 times before finally closing). This also hapens when tryng to open other programs as well.
So, as you might guess, I've been trying to resolve this problem for about 24 hours as this happened about 2 pm yesterday afternoon. I did manage to DL'd the IT version of XP SP1 and tried to run it but it will not run because of the MSV or whatever dll.
I have not backed my comp in about 3 months (100th time head bangs wall) so I really need to finish fixing the issues and at this point do not know what the next step would be.
Any and all help would be appreciated
Thanks
WB |
| |
July 6th, 2004, 02:08 PM
|
#2 (permalink)
| | Senior Member
Join Date: Dec 2002 Location: SOUTH FLA
Posts: 937
|
i would try to see if it is in your precesses menu ,end task on it ,then disable system restore(thus clearing all restore points). then clear history/temp files/cookies then run your anti virus/adaware programs, clean them, and see if that helps
LINK to missing DLL files if you need it: http://www.dll-files.com/
Last edited by sam : July 6th, 2004 at 02:11 PM.
|
| |
July 6th, 2004, 02:15 PM
|
#3 (permalink)
| | Senior Member
Join Date: Dec 2002 Location: SOUTH FLA
Posts: 937
| |
| |
July 6th, 2004, 02:19 PM
|
#4 (permalink)
| | skating away.........
Join Date: Nov 2003 Location: purging the urge
Posts: 6,454
| |
| |
July 6th, 2004, 02:36 PM
|
#5 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Chicago
Posts: 2,163
|
Third time trying to type this, I keep randomly being bumped to TIMO's home page.
Sam, thanks for the quick response.
then disable system restore ---- do not use system restore, bad exp on a ME comp
clear history/temp files/cookies ---- 3times a day depending on comp use
then run your anti virus/adaware programs, clean them, and see if that helps--- 4th time, same deal
There is no indication to which of the dll or any files for that matter are courrupted or missing, Saved that link as there has been more then one time where I could have used it.
WB |
| |
July 6th, 2004, 02:48 PM
|
#6 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Chicago
Posts: 2,163
|
Thanks guys, i'm going to take alook now.
WB |
| |
July 7th, 2004, 05:10 AM
|
#7 (permalink)
| | Senior Member
Join Date: Dec 2002 Location: SOUTH FLA
Posts: 937
|
what is listed in your processes menu? (ctrl-alt-delete)the link i gave you above will help desifer good /bad .if the virus is listed ther it needs to be first disabled and task ended or it will return even after a cleaning. also what is in your start up menu start/ run/(type) "msconfig" (no quotes) -selective start up -startup |
| |
July 7th, 2004, 06:47 AM
|
#8 (permalink)
| | Ultimate Member
Join Date: Oct 2001
Posts: 10,821
|
there is also this tool http://www.majorgeeks.com/download4113.html called "CoolWWWSearch.SmartKiller (v1/v2) MiniRemoval "
its for one of the variants that tries to kill cwshredder...it might be worth trying
I do know that the dude who makes cwshredder said on his site that there are stronger variants out now and he doesnt have time to update cw shredder at this time because of other commitments.....so hopefully someone else steps up to the plate, lol
__________________
"Even a fool is thought to be wise if he is silent"
|
| |
July 7th, 2004, 07:13 AM
|
#9 (permalink)
| | Ultimate Member
Join Date: Aug 2002 Location: Cincinnati, Ohio
Posts: 2,014
| |
| |
July 7th, 2004, 07:28 AM
|
#10 (permalink)
| | Ultimate Member
Join Date: Oct 2001
Posts: 10,821
|
of course another thing you could try is....get a spare hard drive....build windows on it....boot off of it (by having your current drive in there as secondary or slave etc) and then get the data off of the original drive using the spare drive....
then once you have your data off of it onto the spare drive..you can scan the spare drive to be sure the spyware/virus didnt also come across....then you can just format the infected drive
---
my overall question is.....how are the authors of coowebsearch not in jail? |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Most Active Discussions | | | | | Recent Discussions  | | | | | |