New CoolWebSearch Variant

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

New CoolWebSearch Variant

Post by mnosteele52 »

In the past week I have run into a new variant of the CoolWebSearch that is a major pain in the a#$ to remove. Dannjr also told me he has seen it, I did some searching and so far I have only found minimal instructions on removing it.

What I have seen is Ad Aware detect it and say it's removed but it keeps coming back. :irate:

Has anyone run into this?

Do you know of an easy fix or a fix at all?

If you haven't seen this yet you will and it's very hard to remove.

FYI..... I have used Ad Aware, SpyBot, HijackThis, SpySweeper & PestPatrol to try and fully remove this,

:)
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

CWShredder

use that.

It IS the true CoolWebSearch Shredder!
User avatar
lobosblanco
Member
Posts: 81
Joined: Fri Apr 30, 2004 10:35 pm
Location: CA USA

Post by lobosblanco »

as YARDofSTUF said its better then both of them for coolweb varients


Go to http://www.spywareinfo.com/~merijn/cwsc ... cwshredder , and download the latest version of CWShredder by Merijn Bellekom, the creator of Hijack This.
Run it, press 'Fix', and allow it to fix all it finds.
And remember to click "Fix" (Not "Scan only")


if that doesnt work


please post your hjt log
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

YARDofSTUF CWShredder does not work. :(

I forgot to mention I have used it as well.

lobosblanco you may have misunderstood my post, this is not my pc, I have a pc business and have run into this a few times lately.

:)
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

I'm not doubting you, but are you sure it's a cool web variant and not this pain in the Arse new VX2? Let me search through my tools and see if I have anything that may work.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

also u made sure to use the latest version of cwshredder?
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

I've got nothing that you haven't tried except kill box and it's for vx2.
User avatar
Norm
SG VIP
Posts: 14195
Joined: Tue Mar 27, 2001 12:00 pm

Post by Norm »

Haven't come across it yet myself.
As I was searching I came across this page
http://www.spywareinfo.com/~merijn/cwschronicles.html
Man, that coolwebsearch team works hard to keep it running.

Sounds like merlin.org works hard to remove it, maybe the next update to cwshredder will remove this latest version.

More money for us repair guys if we have to do a format/reinstall.
If customers won't listen to advice there's not much else we can do but soak them.

If you know what app installed the problem, you could reinstall it while you monitor the registry, and file access/creation.
Then remove everything it created.
VIKTOR2020
Regular Member
Posts: 233
Joined: Mon Jan 29, 2001 12:00 am
Location: Atlanta, GA

Post by VIKTOR2020 »

I've had allaboutsearching and search2020 on my computer for about a month and they have resisted everything I've tried to remove them. I've used all of the suggested programs in this thread multiple times and have edited my registry repeatedly, to no avail.
First, when they are removed they regenerate themselves; then, if you find and delete the files that are set to recreate the deleted ones, there are files somewhere else that hijack the browser, go back to the site that installed them to begin with, and have the whole mess reinstalled.
Searching requires using the variants: search2020, 2020search, allabout, and aboutsearching as well as the obvious allaboutsearching.
Any help appreciated.
_ _______________________ _
Dell 420 quad core @ 2.4 GHz
3 Gig DDR 2
2 500 GB drives in Raid 0 configuration
ATI Radeon HD 3650 Graphics
User avatar
lobosblanco
Member
Posts: 81
Joined: Fri Apr 30, 2004 10:35 pm
Location: CA USA

Post by lobosblanco »

hi VIKTOR2020

Please do this. Click here: http://www.sherrylynn.us/HijackThis.exe to download Hijack This. Save it to it’s own folder (not temporary files or the desktop).
Close all open windows and open HIJACK THIS. Click “Scan”. When the scan is finished (it only takes a second), the scan button will change to “Save Log”. Click on “Save Log” and save it to NotePad. Copy the entire log and paste it here.

DO NOT FIX ANYTHING YET,

most items that appear in the log are harmless or even needed. Wait for someone to analyze the scan and advise.
$teve

Post by $teve »

The CWS "About Blank" is so far impossible to remove on all systems.
It actually hides from windows,is different in NTFS and FAT32 and also between Different operating systems....Some of the best brains on the net have been working on this 24/7 since before Easter.There is no auto-fix and no two versions act the same way.The instructions we put together for removal are just too complicated for most users to follow and even then theres no guarantee it works.The best thing to recomend at the moment is to ditch IE for now and go with Mozilla or Opera until we get a definate solution for it.
User avatar
mnosteele52
Posts: 11913
Joined: Tue Jul 24, 2001 12:00 pm
Location: Chesapeake, VA

Post by mnosteele52 »

$teve wrote:The CWS "About Blank" is so far impossible to remove on all systems.
It actually hides from windows,is different in NTFS and FAT32 and also between Different operating systems....Some of the best brains on the net have been working on this 24/7 since before Easter.There is no auto-fix and no two versions act the same way.The instructions we put together for removal are just too complicated for most users to follow and even then theres no guarantee it works.The best thing to recomend at the moment is to ditch IE for now and go with Mozilla or Opera until we get a definate solution for it.
Thanks $teve, that's the conclusion I have come to. It has racked my brain and anyone else who has actually run into it.

Personally Mozilla is the only browser I use and all the clients that I have talked into trying it love it.


:thumb:
HawkIT

Reducing problem

Post by HawkIT »

Hi all,

i'm currently infected by this pain in the butt spyware. I have minimised the damage in the only way I could think of (for now). I was annoyed with the changing of my start page and search page etc So i did this;

Windows 2000 / XP

1. Run regedt32.exe
2. Changed permissions on my HKLM\Software\Microsoft\Windows\CurrentVersion\Run key to READ ONLY for all users. Only ADMINISTRATOR has full control (i'm usually loged in as myself and find no need to modify the RUN key)

This will by no means fix the problem, but will reduce the impact. You will also have to do the same for the HKCU equivalent to the above. Also the HKCU\Software\Microsoft\Internet Explorer\Main key as well as it's HKLM equivalent.

Note: You or any program won't be able to modify any subkeys in these keys when you make these changes. I myself don't care about this as I find no need to have my RUN key modified, nor do I change my home page and search pages etc

Make sure you backup your registry first!
User avatar
YeOldeStonecat
SG VIP
Posts: 51171
Joined: Mon Jan 15, 2001 12:00 pm
Location: Somewhere along the shoreline in New England

Post by YeOldeStonecat »

YARDofSTUF wrote:CWShredder

use that.

It IS the true CoolWebSearch Shredder!
Useless on the new ones.
MORNING WOOD Lumber Company
Guinness for Strength!!!
srbarnes4ever
Member
Posts: 94
Joined: Fri Dec 06, 2002 9:15 pm
Location: Lexington, KY

Post by srbarnes4ever »

mnosteele52 wrote:In the past week I have run into a new variant of the CoolWebSearch that is a major pain in the a#$ to remove. Dannjr also told me he has seen it, I did some searching and so far I have only found minimal instructions on removing it.

What I have seen is Ad Aware detect it and say it's removed but it keeps coming back. :irate:

Has anyone run into this?

Do you know of an easy fix or a fix at all?

If you haven't seen this yet you will and it's very hard to remove.

FYI..... I have used Ad Aware, SpyBot, HijackThis, SpySweeper & PestPatrol to try and fully remove this,

:)
Yes I've seen it...been struggling for weeks to rid myself of this one...I've used all the removers you mention plus CWS...to no avail...
Peace,
Stevie B.
VIKTOR2020
Regular Member
Posts: 233
Joined: Mon Jan 29, 2001 12:00 am
Location: Atlanta, GA

Post by VIKTOR2020 »

I finally gave up and switched from Internet Explorer to Mozilla. That stopped the nonsense.
_ _______________________ _
Dell 420 quad core @ 2.4 GHz
3 Gig DDR 2
2 500 GB drives in Raid 0 configuration
ATI Radeon HD 3650 Graphics
musicguy

Post by musicguy »

Damn thing
Post Reply