Question

cool Search Virus

Asked by: lbp4433

I am running Windows XP Home Edition and I am having a problem with my Internet Explorer.  When I type search words in the location bar I am directed to this search engine called cool search and I cannot change it.  Is this cool search considered a virus or a trojan?

Thank you lbp4433

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2004-01-15 at 18:29:11ID20852483
Tags

virus

Topic

Web Browsers

Participating Experts
3
Points
250
Comments
34

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Download Trojan
    Where can I download Trojan virus and the clean Trojan programs ?
  2. Virus ??
    A frend called me with the following : He say he has 4 Virus VBS.FRELINK VBS.FRELINK VBS.NETWORK VBS.WORM GENERIC The following files are infected : LINKS.VBS RUNDLL.VBS Northon an Pc_cellin don't find anything. The machine is very slow starting... It is a NEC computer wit...
  3. VIRUS ????
    Hello everyone... I have a Windows XP system that I am working on that I am pretty sure has a virus... These are the symptoms Cannot access the control panel Clicking on internet explorer does nothing Cannot access My network Places In command prompt I am getting an ...
  4. latest cool webs search problem..
    I have a pc with a very difficult to shift variation on the Cool Web Search Spyware. I have had this in the past and despite using... Spy Washer Spybot Adaware AboutBuster HijackThis SpyWareBuster the bloody comes back generating popups and bogus tool bars as usual. Is ther...
  5. Liquid Cooling
    Hey, My rig is as follows, but I would like to liquid cool it, as the fans are obnoxious, and I would like it to run cooler than it is. Intel P-4 530 (3.0e ghz Prescott) - LGA 775 (Socket T) OCZ 1GB KIT PN- OCZ4001024PDC-K Running at 200 mhz, 1:1 Ratio, CL 2.5, 3, 3, 7 As...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: lbp4433Posted on 2004-01-15 at 18:38:10ID: 10126573

I will download the hijacked software and then post the log thank you

 

by: sunray_2003Posted on 2004-01-15 at 18:39:20ID: 10126581

First try spybot . It will give you a list of unwanted files.Then download hijacthis.RUn it and post the log here
Also before running spybot update it with the latest spyware definitions same with hijackthis

Sunray

 

by: lbp4433Posted on 2004-01-15 at 18:42:25ID: 10126606

We will do think you I will get back to you with my results if I have successfully removed the cool search component or not

 

by: sunray_2003Posted on 2004-01-15 at 18:43:47ID: 10126614

Dear Nitty,

I have faced these issues before.

First power off the cable modem
power off the router
wait for 5 MINS. ( Actually 3 or 4 MINS is fine)
Now plug in everything
Press the reset button at the back of the router
Check if that would work .. This can be the simplest remedy


Try pinging 192.168.0.1 and check what you get

Thanks,
Sunray

 

by: sunray_2003Posted on 2004-01-15 at 18:43:57ID: 10126616

OOPS sorry wrong thread

Sunray

 

by: sunray_2003Posted on 2004-01-15 at 18:45:03ID: 10126625

lbp4433,
> We will do think you I will get back to you with my results if I have successfully
> removed the cool search component or not

Sorry I am not understanding what you are trying to say here

Do as I had said and post the logs that you get from hijackthis HERE. Myself or any other expert can help you.
I will be online for few more hours

Thanks,
Sunray

 

by: lbp4433Posted on 2004-01-15 at 18:48:46ID: 10126649

If I am not mistaken you wrote

First try spybot . It will give you a list of unwanted files.Then download hijacthis.RUn it and post the log here
Also before running spybot update it with the latest spyware definitions same with hijackthis

Sunray

Will this get rid of the cool search problem after I download the software and run it as suggested?

 

by: sunray_2003Posted on 2004-01-15 at 18:50:38ID: 10126658

lbp4433,
> Will this get rid of the cool search problem after I download the software
> and run it as suggested?

The idea of running these 2 are most of the time they can solve the problem.
There are others in the list that I have sent you that you should try if the problem is not resolved

Most likely Hijackthis will give the key cos it will tell you what registry keys that you need to delete to get rid of the cool search issue ..
post the log here

After these 2 you can test Adaware and CWshredder

Thanks,
Sunray

 

by: LRI41Posted on 2004-01-15 at 19:55:50ID: 10126987



CoolWebSearch-the coolwebsearch chronicles


[langalist] LangaList Standard Edition 2003-10-23
Date: 10/22/2003 9:17:30 PM Pacific Daylight Time

CoolWebSearch = Very UnCool

It is a nasty hijack program that hides very well. It would run
once a day so even if he thought he had things fixed and
working the problem would return the next day (after a reboot).
[The CoolWebSearch exploit (explained at
http://www.spywareinfo.com/~merijn/cwschronicles.html )] was
the root of the problem. If you read this site you can see just
how nasty this is. The dam* thing can install from a web page
you may be at or passing through.

http://www.spywareinfo.com/~merijn/

 has a fast little shredder
to remove it plus a few other useful utilities. He won't be
100% sure that he has finally beat this bug for a couple days,
but from the tests he's done so far it does appear to have been
killed.


Subject: Registry cure for Searchv hijacker

http://www.computing.net/security/wwwboard/forum/6873.html



 

by: lbp4433Posted on 2004-01-15 at 20:05:09ID: 10127023

ty 4 the info  LRI41

 

by: lbp4433Posted on 2004-01-15 at 20:18:59ID: 10127075

So i go to http://www.spywareinfo.com/~merijn/cwschronicles.html#cwshredder and downlad CWShredder.exe ??  LRI41 ??

 

by: LRI41Posted on 2004-01-15 at 20:26:55ID: 10127108

So it says and this solution has been posted several times:

After reading all of this, you must be under the impression that a CoolWebSearch hijack is near impossible to fix since there are so many variants. Though it is true that the conventional tools like Ad-Aware, Spybot S&D and HijackThis won't fix all of the variants, there is one tool that will.

After about the 3rd CWS variant, I realized this particular spyware company moved faster than any other I'd seen before, and that the anti-spyware programs wouldn't be able to keep up with it. So I decided to write a separate program dedicated to removing CoolWebSearch. It's called CWShredder and can be downloaded here, in several forms:

Normal form, will work for most people:
  http://www.merijn.org/files/CWShredder.exe  

--------------------------------------------------------------------------------
 

If you get a message saying 'A required dll, MSVBVM60.DLL, was not found', install this first:
Visual Basic 6 runtime libraries from Microsoft  

--------------------------------------------------------------------------------
 

If you can't or won't download bare executables for some reason, try this link to the zipped version:
Zipped version of CWShredder  

--------------------------------------------------------------------------------
 

If you get a virus warning for W32/Generic.worm!p2p, try this link instead:
Unpacked version of CWShredder  


This removal tool will be updated for any new variants of CoolWebSearch, as well as new affiliates that are sighted. It can remove all of the variants mentioned above.

Note that CWShredder is update very often. If you have a copy that's more than a week old, check for an update first before emailing me it's not working well.

 

by: sunray_2003Posted on 2004-01-15 at 22:06:19ID: 10127422

lbp4433,

Did you download and run hijackthis Post the log  here .
I can tell you the registry keys that you need to delete first.

Why did you accept an answer before doing that ?

Thanks,
Sunray

 

by: sunray_2003Posted on 2004-01-15 at 22:52:52ID: 10127573

lbp4433,
>  http://www.spywareinfo.com/~merijn/cwschronicles.html#cwshredder and downlad
> CWShredder.exe ?

and regarding this one I had already asked you to do so after using hijackthis ?

Thanks,
Sunray

 

by: lbp4433Posted on 2004-01-16 at 12:25:11ID: 10132678

sunray_2003 I apologize for not posting the log file first I will do that shortly.  And I also apologize for excepting an before posting the log file.  I really appreciate everyone's help I am new to web site.  I will certainly go through all the frequently asked questions on using this web site appropriately

 

by: sunray_2003Posted on 2004-01-16 at 12:28:48ID: 10132711

I am not saying what  LRI41  told was wrong.If you can see in that article that there can be many variants for that spyware. But I have helped to solve many spyware issues.
if you can post the log we can assist you and then if it doesnot go away with all the softwares then accept the answer

Sunray

 

by: LRI41Posted on 2004-01-16 at 12:42:21ID: 10132809

lbp4433

If you want to reconsider and split and points  or even award all of the
to the Bellyacher since he really needs them and wants them, it make me no never mind, just post a 0 point question in CS listed at the top right of you screen.

 

by: sunray_2003Posted on 2004-01-16 at 13:46:25ID: 10133319

LRI41,
> even award all of the
> to the Bellyacher since he really needs them and wants them

I would think you need to watch your language here , Mr.LRI41.what I have said to the questioner is to check the softwares and see if the spywares can be removed. Using most of the softwares if it is not removed then fine. If it can be removed then it is going to benefit all of us here . I am not disagreeing with what you had given ..

Bellyacher since he really needs them  = totally unacceptable



Thanks,
Sunray

 

by: lbp4433Posted on 2004-01-16 at 13:51:32ID: 10133367

In regards to posting the  log I have already run the software as suggested and its been removed I did post a zero point  question in cs I'm certainly willing to split the points without any hesitation.  Thank you again for everyone's help

 

by: sunray_2003Posted on 2004-01-16 at 13:53:35ID: 10133378

lbp4433,
> have already run the software as suggested and its been removed

what has been removed ?

Thanks,
Sunray

 

by: lbp4433Posted on 2004-01-16 at 13:56:12ID: 10133403

The cool search spyware problem

 

by: sunray_2003Posted on 2004-01-16 at 13:58:53ID: 10133425

So did you delete the all registry keys pertaining to cool search

If you have not or even had done that check these keys

***************

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
HKCU\Software\Microsoft\Internet Explorer\SearchURL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant
HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar

***************

So even after removing them , you are getting them ..

hav you tried Cwshredder aswell ?

Sunray

 

by: lbp4433Posted on 2004-01-16 at 14:04:00ID: 10133462

Cwshredder is what I used and that is all I used

 

by: sunray_2003Posted on 2004-01-16 at 14:05:45ID: 10133475

lbp4433,
> Cwshredder is what I used and that is all I used

OK finally..You used Cwshredder and it your problem is solved . is it NOT ?


Thanks,
Sunray

 

by: lbp4433Posted on 2004-01-16 at 14:07:11ID: 10133483

It is solved thank you

 

by: sunray_2003Posted on 2004-01-16 at 14:09:50ID: 10133495

LRI41,
>  even award all of the
> to the Bellyacher since he really needs them and wants them, it make me no never mind,

I would guess you are not going to mind even if I get all the points here cos I had asked him to use CWshredder FIRST

It would be generous of him to split the points and I donot mind  

lbp4433 , If had already requested CS to open this question so that you can split , it is fine with ME

Thanks,
Sunray

 

by: lbp4433Posted on 2004-01-16 at 14:12:32ID: 10133518

I will certainly split points not a problem there

 

by: lbp4433Posted on 2004-01-16 at 18:04:45ID: 10134444

Thank you for all yor help sunray_2003 and LRI41

 

by: LRI41Posted on 2004-01-16 at 18:41:48ID: 10134591

NPlbp4433

 

by: flex_hardPosted on 2004-08-10 at 09:33:01ID: 11764723

here is what my Hijack this log has...any suggestions??
Logfile of HijackThis v1.98.2
Scan saved at 12:31:51 PM, on 8/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\netjs.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\TASKMAN.EXE:ciqqy
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Documents and Settings\MIKE\Desktop\HijackThis.exe
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.EXE
C:\Program Files\Trend Micro\Internet Security\PCCGUIDE.EXE
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ayrfi.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ssgrd.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ssgrd.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ayrfi.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4EF24DB7-3509-B765-D598-CCE2A69F964D} - C:\WINDOWS\system32\javams32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [netjs.exe] C:\WINDOWS\netjs.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

 

by: LRI41Posted on 2004-08-10 at 11:13:48ID: 11765866

Comment from flex_hard
Date: 08/10/2004 09:33AM PDT

I think you should post a new question .

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...