New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 938
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

coolweb keeps comming back
Goto page 1, 2  Next
 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My!
View previous topic :: View next topic  
Author Message
sworth

Trooper
Trooper



Joined: May 29, 2004
Posts: 13
Location: USA

PostPosted: Sat May 29, 2004 3:53 pm    Post subject: coolweb keeps comming back
Reply with quote

HELP !!!! Coolweb keeps changing my home page to about blank, I've run coolwebshredder, adaware, adwatch, spysweeper, and norton, I have highjack this but don't know what is ok and what is not. when coolweb rears its ugly head if I run adaware I get any where from 20min. to a day with out problems, but.... then it's back, right now (crossing fingers) it's gone again I'll include the log I have now (after adaware scan) for you to look at and when it comes back I'll get the log before I run adaware, you guys are my last hope next stop is the computer shop to format the hard drive and reinstall windows.
Thanks


Logfile of HijackThis v1.97.7
Scan saved at 12:22:36 PM, on 5/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\WINNT\System32\SK9910DM.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Documents and Settings\Owner\My Documents\downloads\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: (no name) - {9368D063-44BE-49B9-BD14-BB9663FD38FC}_ - (no file)
O2 - BHO: (no name) - {05F0B622-8F1D-4415-A104-8D3F443AFEA2} - C:\WINNT\System32\dmdkdaa.dll (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {5FF4BDBF-CDCD-484C-9FC7-748070A07DBB} - C:\WINNT\System32\eabhb.dll (file missing)
O2 - BHO: (no name) - {9A4339B2-36D4-41B4-96F6-E2745657A648} - C:\WINNT\System32\ccmecaa.dll (file missing)
O2 - BHO: (no name) - {A28D87BB-9ECF-467C-A123-4EF9E588ECCE} - C:\WINNT\System32\hlpp95en.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [qlmjwr] C:\WINNT\qlmjwr.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O15 - Trusted Zone: http://www.ebay.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/...1/chat.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://tdserver.bitstream.com/tdserver.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/packages/GSManager.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - hcp://system/TechTools.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/27db3f35481...xIE601.cab
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C....749537037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc...wflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EP...-0-3-0.cab
O16 - DPF: {f760cb9e-c60f-4a89-890e-fae8b849493e} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{964F4102-91F6-4F89-A15B-13B57B5467EC}: NameServer = 205.214.42.66,205.214.51.16
Back to top
View users profile Send private message
archimedes
Warnings : 1

Lieutenant
Lieutenant



Joined: May 21, 2004
Posts: 155
Location: USA

PostPosted: Sat May 29, 2004 4:14 pm    Post subject:
Reply with quote

hi sworth
let hijack fix these
R3 - URLSearchHook: (no name) - {9368D063-44BE-49B9-BD14-BB9663FD38FC}_ - (no file)
O2 - BHO: (no name) - {05F0B622-8F1D-4415-A104-8D3F443AFEA2} - C:\WINNT\System32\dmdkdaa.dll (file missing)
O2 - BHO: (no name) - {5FF4BDBF-CDCD-484C-9FC7-748070A07DBB} - C:\WINNT\System32\eabhb.dll (file missing)
O2 - BHO: (no name) - {9A4339B2-36D4-41B4-96F6-E2745657A648} - C:\WINNT\System32\ccmecaa.dll (file missing)
O2 - BHO: (no name) - {A28D87BB-9ECF-467C-A123-4EF9E588ECCE} - C:\WINNT\System32\hlpp95en.dll (file missing)
download winpatrol which has browser hijack prevention and is low on system resources.
let me know if this worked.
good luck

_________________
best tools:winpatrol, spywareblaster, spywareguard,zone alarm, hijackthis, crapcleaner, Ad-Aware, SpyBotSD, Jet Audio.
Back to top
View users profile Send private message Yahoo Messenger
sworth

Trooper
Trooper



Joined: May 29, 2004
Posts: 13
Location: USA

PostPosted: Sat May 29, 2004 5:15 pm    Post subject:
Reply with quote

First off thank you thank you thnak you for the quick reply ok I've done all that (keeping fingers crossed). I noticed in winpatrol found a exe file with no info ie. who made it and so on, it's call QLMJWR.exe I disabled it for now do you know what it is?
Back to top
View users profile Send private message
archimedes
Warnings : 1

Lieutenant
Lieutenant



Joined: May 21, 2004
Posts: 155
Location: USA

PostPosted: Sat May 29, 2004 5:28 pm    Post subject:
Reply with quote

I googled it but didn't see any results. if you wan't further scanning done , there is an online scan at
http://aumha.org/a/noads.htm. try it out
enjoy

_________________
best tools:winpatrol, spywareblaster, spywareguard,zone alarm, hijackthis, crapcleaner, Ad-Aware, SpyBotSD, Jet Audio.
Back to top
View users profile Send private message Yahoo Messenger
nice-but-dim

Cadet
Cadet



Joined: May 29, 2004
Posts: 9
Location: UK

PostPosted: Sat May 29, 2004 5:28 pm    Post subject: spyware
Reply with quote

hi sworth im new to all this but through research i have discovered spy ware blaster & spy ware guard stop a lot of crap before it gets on your computer you can download these from majorgeeks.com
hope this helps
Back to top
View users profile Send private message
archimedes
Warnings : 1

Lieutenant
Lieutenant



Joined: May 21, 2004
Posts: 155
Location: USA

PostPosted: Sat May 29, 2004 5:32 pm    Post subject:
Reply with quote

Thanks for the input nice. That's true sworth, there are lots of good programs out there, you can research some of them from this site. I personally use spyware blaster winpatrol zone alarm and avast but you can decide your own configuration. I also don't use explorer but choose firefox instead. good luck to you both and come back anytime
_________________
best tools:winpatrol, spywareblaster, spywareguard,zone alarm, hijackthis, crapcleaner, Ad-Aware, SpyBotSD, Jet Audio.
Back to top
View users profile Send private message Yahoo Messenger
sworth

Trooper
Trooper



Joined: May 29, 2004
Posts: 13
Location: USA

PostPosted: Sat May 29, 2004 5:44 pm    Post subject:
Reply with quote

thanks for the info BTW the link is no good. in regards to spyware blaster should that be used instead of sypsweeper and/or adaware? or with? I know I have a lot of questions but I just am sooo in over my head. To all of you thanks again for you patience and support.
Sarah
Back to top
View users profile Send private message
tchicken
Warnings : 1

Private
Private



Joined: May 26, 2004
Posts: 40
Location: USA

PostPosted: Sat May 29, 2004 5:46 pm    Post subject:
Reply with quote

sworth, you deleted those keys and still have the problem after the reboot?
Back to top
View users profile Send private message
sworth

Trooper
Trooper



Joined: May 29, 2004
Posts: 13
Location: USA

PostPosted: Sat May 29, 2004 5:51 pm    Post subject:
Reply with quote

YUP
Back to top
View users profile Send private message
archimedes
Warnings : 1

Lieutenant
Lieutenant



Joined: May 21, 2004
Posts: 155
Location: USA

PostPosted: Sat May 29, 2004 5:56 pm    Post subject:
Reply with quote

Sarah, I have not used spy sweeper so I cannot remark on it's ability. I can however remark on the other programs I mentioned such as spywareblaster. avoid programs called noadware and spy cleaner.
keep in mind that the more programs installed and running will begin to affect your performance by overwhelming your memory. so keep it as low as possible. A good configuration would be Ad-Aware, spybotSD, winpatrol spywareblaster and ZoneAlarm.
These programs have proven themselves again and again.

_________________
best tools:winpatrol, spywareblaster, spywareguard,zone alarm, hijackthis, crapcleaner, Ad-Aware, SpyBotSD, Jet Audio.
Back to top
View users profile Send private message Yahoo Messenger
tchicken
Warnings : 1

Private
Private



Joined: May 26, 2004
Posts: 40
Location: USA

PostPosted: Sat May 29, 2004 6:03 pm    Post subject:
Reply with quote

I agree. However, it looks like you have a morpher on your hands and you'll need to find the dll file that is changing every time you restart.

http://www.sysinternals.com/files/autoruns.zip
download this and run it. Delete the same keys as you did before with HJT, run spybot then restart.

Run autoruns again. This time, you'll notice a couple of character changes in the dll file. This is the morpher. Once you ID the morpher, then jump to the reg key with autoruns and delete it. Then delete the dll file that changes. This should fix the problem. Post your autoruns log as an attachment now and after.
Back to top
View users profile Send private message
archimedes
Warnings : 1

Lieutenant
Lieutenant



Joined: May 21, 2004
Posts: 155
Location: USA

PostPosted: Sat May 29, 2004 6:13 pm    Post subject:
Reply with quote

good catch TC
_________________
best tools:winpatrol, spywareblaster, spywareguard,zone alarm, hijackthis, crapcleaner, Ad-Aware, SpyBotSD, Jet Audio.
Back to top
View users profile Send private message Yahoo Messenger
sworth

Trooper
Trooper



Joined: May 29, 2004
Posts: 13
Location: USA

PostPosted: Sat May 29, 2004 6:18 pm    Post subject:
Reply with quote

to:archimedes OK, if I have a problem again (I hopefull for the 1st time in a week) I'll keep them in mind, right I'll think the wait and see approach will be best.


to: Tchicken Sorry I think I misunderstood your 1st post, its has been comming back proir to running and fixing with hjt (see above) right now it seems to be OK

Thanks All
Back to top
View users profile Send private message
archimedes
Warnings : 1

Lieutenant
Lieutenant



Joined: May 21, 2004
Posts: 155
Location: USA

PostPosted: Sat May 29, 2004 8:07 pm    Post subject:
Reply with quote

Sarah,
what TK was saying in laymens terms is that some adware programs can change themselves if removed so you may need to watch for this behavior.
If you have winpatrol setup now, this should be less of a problem, since winpatrol detects changes in the browser.
if something tries to change a help object for instance winpatrol will see it within 3 minutes (sniffs every three minutes)
So hopefully you won't need to worry abot the morphing part.

_________________
best tools:winpatrol, spywareblaster, spywareguard,zone alarm, hijackthis, crapcleaner, Ad-Aware, SpyBotSD, Jet Audio.
Back to top
View users profile Send private message Yahoo Messenger
sworth

Trooper
Trooper



Joined: May 29, 2004
Posts: 13
Location: USA

PostPosted: Sun May 30, 2004 1:04 am    Post subject:
Reply with quote

ok thanks BTW its baaaack I'll try the prosseses that TC recomended
But I'm not sure what I'm looking for
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops