E
EJN
Guest
Tried that too !! - nothing..says I'm clear...like them all .. !!!Try this.......
http://housecall.trendmicro.com/
--
EJN
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Tried that too !! - nothing..says I'm clear...like them all .. !!!Try this.......
http://housecall.trendmicro.com/
Well, guys, if nobody can come up with a solution I really think
this might be the last you hear from me - really ...
About 22 hours ago I foolishly logged onto what I knew was maybe a
dodgy site and in less than 1/2 hour I'd got 7 viruses.
Fortunately, most were of a nature that I sorted them out but right
now I'm plagued incessantly witrh this blasted 'Cool Web Search'
thing ...and CANNOT find a way to rid it - just changes my Home
Page EVERY time , even though I've done all in my power to stop it.
Had for years on my machines - AVG (excellent overall) - Triojan
Remover and Pest Patrol. Funnily , just a few hours before this
episode I d/loaded and setup Ad-Aware6. It found one or two things
but has done NOTHING to sort out the Cool Web Search thing. Got
'HiJackThis' which is a superb thing...it shows immediately the
entries giving this Cool Web page but although I clear them they
just auto return instantly. Got a super prog called CWShredder -
that found at first the 'AboutBlank' entry that had been popped in
, but within the last hour or two I've clearly done something and
CWShredder now tells me I've got a clean machine...which I haven't
of course.
Did NOT have before, Spybot, so d/loaded that this morning. It
found a few things but again done NOTHING to shift Cool Web ...and
in spite of numerous searches in Google , plenty of ideas on
shifting it but none work,.
This is on a two-month old new P4 3Gig laptop, on XP, my latest
pride and joy and have been piling tons of progs on it that I want
to use - NO WAY am I going to re-install to scratch and have to
start over again. Don't really know how to start and I don't know
where I'd find half the progs, keys etc to do that without a month
or more searches.
Frankly I'm just about fed up..spent 22 hours now trying to sort it
, apart from 6 hours restless night, and getting nowhere
I'd rather just give up the Internet if THIS is going to persist -
anyway, I believe that it can in fact open the door to allow
anything in ...so how on earth do I shift it after trying all this ?
Unlocked SysRestore just in case something was in there, nothing,
so I've now lost all my Restores too !!! and still no better off.
No problems in going into the Register but again, try as I may I
cannot find any clue as to WHERE is the kick-off...well, I DO find
the entry in 'Exolorer-Main' key , but that's obviously not where
it's triggered..as I change that but iyt just comes back.
It's thanks or gooodbye mates - I've about had it !
--
EJN
I've been into computers now for what surely must be 30+ years...bought the very first one ever intro'd to UK.. the old Atari 500 .. but NEVER NEVER had to do a reinstall and to be honest I just don't know where to start. Anyway - surely this effectively removes or makes non-working ALL you software as it is no longer 'installed' into the clean system ?? and the thought of re-installing ALL the stuff I've put on this is mind-boggling...even if I could lay my hands on all the progs AND keys etc. I just feel more like giving up --Personally, I would reformat and do a clean install. This is why I
religiously backup important files. Sometimes it's just easier to
start all over (i.e. you've already expended 22 hours trying to
find the .exe file of this viri).
Good luck in your search. I've only come across one virus that I
just couldn't get rid of. I hope yours isn't one of them.
In my haste, somehow missed copying link to the Security Forum in previous post:a lot of pro IT people for various companies and security software
reps from Ad-Aware, Sybot Seach & Destroy, etc. monitor and
contribute to this forum....
--Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware
from executing during startup.
Open Registry Editor. To do this, click Start> Run, type Regedit,
then press Enter.
In the left panel, double-click the following:
HKEY_CURRENT_USER> Software> Microsoft>
Windows> CurrentVersion> Run
In the right panel, locate and delete the entry or entries:
olehelp="%Windows%\olehelp.exe"
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from
memory as described in the previous procedure, restart your system.
Resetting Internet Explorer Homepage and Search Page
This procedure restores the Internet Explorer homepage and search
page to the default settings.
Close all Internet Explorer windows.
Open Control Panel. Click Start> Settings> Control Panel.
Double-click the Internet Options icon.
In the Internet Properties window, click the Programs tab.
Click the “Reset Web Settings…” button.
Select “Also reset my home page.” Click Yes.
Click OK.
Additional Windows ME/XP Cleaning Instructions
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files
detected as TROJ_BOOKMARK.B. To do this, Trend Micro customers must
download the latest pattern file and scan their system. Other
Internet users can use HouseCall, Trend Micro’s free online virus
scanner.
Trend Micro offers best-of-breed antivirus and content-security
If this is confusing let me know.....I have had this reset thing
occur every now and then, the above solution generally works.
wj
Well, guys, if nobody can come up with a solution I really think
this might be the last you hear from me - really ...
About 22 hours ago I foolishly logged onto what I knew was maybe a
dodgy site and in less than 1/2 hour I'd got 7 viruses.
Fortunately, most were of a nature that I sorted them out but right
now I'm plagued incessantly witrh this blasted 'Cool Web Search'
thing ...and CANNOT find a way to rid it - just changes my Home
Page EVERY time , even though I've done all in my power to stop it.
Had for years on my machines - AVG (excellent overall) - Triojan
Remover and Pest Patrol. Funnily , just a few hours before this
episode I d/loaded and setup Ad-Aware6. It found one or two things
but has done NOTHING to sort out the Cool Web Search thing. Got
'HiJackThis' which is a superb thing...it shows immediately the
entries giving this Cool Web page but although I clear them they
just auto return instantly. Got a super prog called CWShredder -
that found at first the 'AboutBlank' entry that had been popped in
, but within the last hour or two I've clearly done something and
CWShredder now tells me I've got a clean machine...which I haven't
of course.
Did NOT have before, Spybot, so d/loaded that this morning. It
found a few things but again done NOTHING to shift Cool Web ...and
in spite of numerous searches in Google , plenty of ideas on
shifting it but none work,.
This is on a two-month old new P4 3Gig laptop, on XP, my latest
pride and joy and have been piling tons of progs on it that I want
to use - NO WAY am I going to re-install to scratch and have to
start over again. Don't really know how to start and I don't know
where I'd find half the progs, keys etc to do that without a month
or more searches.
Frankly I'm just about fed up..spent 22 hours now trying to sort it
, apart from 6 hours restless night, and getting nowhere
I'd rather just give up the Internet if THIS is going to persist -
anyway, I believe that it can in fact open the door to allow
anything in ...so how on earth do I shift it after trying all this ?
Unlocked SysRestore just in case something was in there, nothing,
so I've now lost all my Restores too !!! and still no better off.
No problems in going into the Register but again, try as I may I
cannot find any clue as to WHERE is the kick-off...well, I DO find
the entry in 'Exolorer-Main' key , but that's obviously not where
it's triggered..as I change that but iyt just comes back.
It's thanks or gooodbye mates - I've about had it !
--
EJN
I've been into computers now for what surely must be 30+Personally, I would reformat and do a clean install. This is why I
religiously backup important files. Sometimes it's just easier to
start all over (i.e. you've already expended 22 hours trying to
find the .exe file of this viri).
Good luck in your search. I've only come across one virus that I
just couldn't get rid of. I hope yours isn't one of them.
years...bought the very first one ever intro'd to UK.. the old
Atari 500 .. but NEVER NEVER had to do a reinstall and to be honest
I just don't know where to start. Anyway - surely this effectively
removes or makes non-working ALL you software as it is no longer
'installed' into the clean system ?? and the thought of
re-installing ALL the stuff I've put on this is
mind-boggling...even if I could lay my hands on all the progs AND
keys etc. I just feel more like giving up --
EJN
EJN
--Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware
from executing during startup.
Open Registry Editor. To do this, click Start> Run, type Regedit,
then press Enter.
In the left panel, double-click the following:
HKEY_CURRENT_USER> Software> Microsoft>
Windows> CurrentVersion> Run
In the right panel, locate and delete the entry or entries:
olehelp="%Windows%\olehelp.exe"
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from
memory as described in the previous procedure, restart your system.
Resetting Internet Explorer Homepage and Search Page
This procedure restores the Internet Explorer homepage and search
page to the default settings.
Close all Internet Explorer windows.
Open Control Panel. Click Start> Settings> Control Panel.
Double-click the Internet Options icon.
In the Internet Properties window, click the Programs tab.
Click the “Reset Web Settings…” button.
Select “Also reset my home page.” Click Yes.
Click OK.
Additional Windows ME/XP Cleaning Instructions
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files
detected as TROJ_BOOKMARK.B. To do this, Trend Micro customers must
download the latest pattern file and scan their system. Other
Internet users can use HouseCall, Trend Micro’s free online virus
scanner.
Trend Micro offers best-of-breed antivirus and content-security
If this is confusing let me know.....I have had this reset thing
occur every now and then, the above solution generally works.
wj
Well, guys, if nobody can come up with a solution I really think
this might be the last you hear from me - really ...
About 22 hours ago I foolishly logged onto what I knew was maybe a
dodgy site and in less than 1/2 hour I'd got 7 viruses.
Fortunately, most were of a nature that I sorted them out but right
now I'm plagued incessantly witrh this blasted 'Cool Web Search'
thing ...and CANNOT find a way to rid it - just changes my Home
Page EVERY time , even though I've done all in my power to stop it.
Had for years on my machines - AVG (excellent overall) - Triojan
Remover and Pest Patrol. Funnily , just a few hours before this
episode I d/loaded and setup Ad-Aware6. It found one or two things
but has done NOTHING to sort out the Cool Web Search thing. Got
'HiJackThis' which is a superb thing...it shows immediately the
entries giving this Cool Web page but although I clear them they
just auto return instantly. Got a super prog called CWShredder -
that found at first the 'AboutBlank' entry that had been popped in
, but within the last hour or two I've clearly done something and
CWShredder now tells me I've got a clean machine...which I haven't
of course.
Did NOT have before, Spybot, so d/loaded that this morning. It
found a few things but again done NOTHING to shift Cool Web ...and
in spite of numerous searches in Google , plenty of ideas on
shifting it but none work,.
This is on a two-month old new P4 3Gig laptop, on XP, my latest
pride and joy and have been piling tons of progs on it that I want
to use - NO WAY am I going to re-install to scratch and have to
start over again. Don't really know how to start and I don't know
where I'd find half the progs, keys etc to do that without a month
or more searches.
Frankly I'm just about fed up..spent 22 hours now trying to sort it
, apart from 6 hours restless night, and getting nowhere
I'd rather just give up the Internet if THIS is going to persist -
anyway, I believe that it can in fact open the door to allow
anything in ...so how on earth do I shift it after trying all this ?
Unlocked SysRestore just in case something was in there, nothing,
so I've now lost all my Restores too !!! and still no better off.
No problems in going into the Register but again, try as I may I
cannot find any clue as to WHERE is the kick-off...well, I DO find
the entry in 'Exolorer-Main' key , but that's obviously not where
it's triggered..as I change that but iyt just comes back.
It's thanks or gooodbye mates - I've about had it !
--
EJN
EJN
Hey - I wonder if you've got onto something? i can almost pin-point the time the dirty-deed happened as about between 4:30 & 5:30pm yesterday - 31st May/04. I've found rucks of entries in Win between around 7:30pm and midnight but that would almost surely be when I found and tried some other progs that I hadn't on before. When THE event happened I didn't even install or load anything...was just looking...so there seems nothing to require a new file on that account.Hi,
Well I'll have to scratch my head a bit. I ran into the same
situation you are in last fall.....I found a reg entry but there
was also an executable in either system or system 32 that was
giving my the run around.
could you search your hdd for a newly created file/folder and
establish a time frame that it might have been created in?
wj
Hi,
I believe the following (copied from trend) will handle your issues:
Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware
from executing during startup.
Open Registry Editor. To do this, click Start> Run, type Regedit,
then press Enter.
In the left panel, double-click the following:
HKEY_CURRENT_USER> Software> Microsoft>
Windows> CurrentVersion> Run
In the right panel, locate and delete the entry or entries:
olehelp="%Windows%\olehelp.exe"
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from
memory as described in the previous procedure, restart your system.
Resetting Internet Explorer Homepage and Search Page
This procedure restores the Internet Explorer homepage and search
page to the default settings.
Close all Internet Explorer windows.
Open Control Panel. Click Start> Settings> Control Panel.
Double-click the Internet Options icon.
In the Internet Properties window, click the Programs tab.
Click the “Reset Web Settings…” button.
Select “Also reset my home page.” Click Yes.
Click OK.
Additional Windows ME/XP Cleaning Instructions
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files
detected as TROJ_BOOKMARK.B. To do this, Trend Micro customers must
download the latest pattern file and scan their system. Other
Internet users can use HouseCall, Trend Micro’s free online virus
scanner.
Trend Micro offers best-of-breed antivirus and content-security
If this is confusing let me know.....I have had this reset thing
occur every now and then, the above solution generally works.
wj
Hi,another link to try.....
http://www.spysweeper.com/remove-coolwebsearch.html
steps to remove manually at the bottom.
--
http://www.pbase.com/galleries/donald_spencer (pbase supporter)
http://spyware.pcwash.com/computer-parasite.htmlHi,another link to try.....
http://www.spysweeper.com/remove-coolwebsearch.html
steps to remove manually at the bottom.
--
http://www.pbase.com/galleries/donald_spencer (pbase supporter)
have you looked into parasite removal instead of virus...had
similar problem at work and our IT support person spent hours
getting rid of it by going thru the registry (unfortunately she's
on maternity leave, so I can't ask her what she did exactly).
sorry....
--
Helen K
this is not the same as the "smartsearch virus" that i had. Here
is a procedure to use that I cut and pasted for your consideration
----------------------------------------------------------------------------------------------------
cws.smartsearch.2 cool web search notice
Heads up for all system and network admins out there. It seems that
the arena of spyware versus spyware protection is getting more
vicious by the hour. Our technology dept has been seeing with
alarming frequency more and more spamware attacks on individual
systems (our mobile users are unprotected by our firewall rules at
their homes).
The most nefarious of these has been the coolwebsearch trojan and
any of its variants. cws.smartsearch.2 and .3, .4, .5 all have a
component which is designed to recognize the launching of the
cwshredder removal program and to close it mid operation.
Spybot, and Hijackthis in combination with any pop-up stopper will
not stop this trojan. CWShredder, if run will be terminated
abnormally during its scan. The new CWShredder version has built in
counters for this trojan technique, but recently even newer
variants of the CWS trojan have counterattacks for CWShredders
counterattacks.
The only effective solution we have found is this:
1. Run ad-aware, update ad-aware: perform a full scan (other
options have to be enabled via the custom options)
2. After ad-aware has removed or quarantined its discoveries, run
the cwshredder program again (make sure you are running ver. 1.57
or greater (this will remove and residual cws files left on the
system)
If this does not work and as a counter to any as yet undiscovered
trojans we remove the tcp/ip stack as well as the associated
winsock components (as this windows core component is now a major
target of the spammers)
--------------------------------------------------------------------------------------------------------
Note,I always ghost my pc's hd so that I can reload easily in case
of this type of infection. i wish that these hackers would find
something better to do than just screw with other people's machines.
Oh man,that's great,and I will check out the pandasoftwareI had 4 virus and nothing would get rid of them until today when I
found a FREE anti virus that has worked like a dream.Give it a try
and good luck.
http://www.pandasoftware.com/activescan/
Dave.
Yes - lost all my 'points' now of course...and it was to no avail ...NOTHINGIt sounds simple, but maybe it will work??
Judy
Well, guys, if nobody can come up with a solution I really think
this might be the last you hear from me - really ...
About 22 hours ago I foolishly logged onto what I knew was maybe a
dodgy site and in less than 1/2 hour I'd got 7 viruses.
Fortunately, most were of a nature that I sorted them out but right
now I'm plagued incessantly witrh this blasted 'Cool Web Search'
thing ...and CANNOT find a way to rid it - just changes my Home
Page EVERY time , even though I've done all in my power to stop it.
Had for years on my machines - AVG (excellent overall) - Triojan
Remover and Pest Patrol. Funnily , just a few hours before this
episode I d/loaded and setup Ad-Aware6. It found one or two things
but has done NOTHING to sort out the Cool Web Search thing. Got
'HiJackThis' which is a superb thing...it shows immediately the
entries giving this Cool Web page but although I clear them they
just auto return instantly. Got a super prog called CWShredder -
that found at first the 'AboutBlank' entry that had been popped in
, but within the last hour or two I've clearly done something and
CWShredder now tells me I've got a clean machine...which I haven't
of course.
Did NOT have before, Spybot, so d/loaded that this morning. It
found a few things but again done NOTHING to shift Cool Web ...and
in spite of numerous searches in Google , plenty of ideas on
shifting it but none work,.
This is on a two-month old new P4 3Gig laptop, on XP, my latest
pride and joy and have been piling tons of progs on it that I want
to use - NO WAY am I going to re-install to scratch and have to
start over again. Don't really know how to start and I don't know
where I'd find half the progs, keys etc to do that without a month
or more searches.
Frankly I'm just about fed up..spent 22 hours now trying to sort it
, apart from 6 hours restless night, and getting nowhere
I'd rather just give up the Internet if THIS is going to persist -
anyway, I believe that it can in fact open the door to allow
anything in ...so how on earth do I shift it after trying all this ?
Unlocked SysRestore just in case something was in there, nothing,
so I've now lost all my Restores too !!! and still no better off.
No problems in going into the Register but again, try as I may I
cannot find any clue as to WHERE is the kick-off...well, I DO find
the entry in 'Exolorer-Main' key , but that's obviously not where
it's triggered..as I change that but iyt just comes back.
It's thanks or gooodbye mates - I've about had it !
--
EJN