I will download the hijacked software and then post the log thank you
Main Topics
Browse All TopicsI am running Windows XP Home Edition and I am having a problem with my Internet Explorer. When I type search words in the location bar I am directed to this search engine called cool search and I cannot change it. Is this cool search considered a virus or a trojan?
Thank you lbp4433
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Dear Nitty,
I have faced these issues before.
First power off the cable modem
power off the router
wait for 5 MINS. ( Actually 3 or 4 MINS is fine)
Now plug in everything
Press the reset button at the back of the router
Check if that would work .. This can be the simplest remedy
Try pinging 192.168.0.1 and check what you get
Thanks,
Sunray
lbp4433,
> We will do think you I will get back to you with my results if I have successfully
> removed the cool search component or not
Sorry I am not understanding what you are trying to say here
Do as I had said and post the logs that you get from hijackthis HERE. Myself or any other expert can help you.
I will be online for few more hours
Thanks,
Sunray
If I am not mistaken you wrote
First try spybot . It will give you a list of unwanted files.Then download hijacthis.RUn it and post the log here
Also before running spybot update it with the latest spyware definitions same with hijackthis
Sunray
Will this get rid of the cool search problem after I download the software and run it as suggested?
lbp4433,
> Will this get rid of the cool search problem after I download the software
> and run it as suggested?
The idea of running these 2 are most of the time they can solve the problem.
There are others in the list that I have sent you that you should try if the problem is not resolved
Most likely Hijackthis will give the key cos it will tell you what registry keys that you need to delete to get rid of the cool search issue ..
post the log here
After these 2 you can test Adaware and CWshredder
Thanks,
Sunray
CoolWebSearch-the coolwebsearch chronicles
[langalist] LangaList Standard Edition 2003-10-23
Date: 10/22/2003 9:17:30 PM Pacific Daylight Time
CoolWebSearch = Very UnCool
It is a nasty hijack program that hides very well. It would run
once a day so even if he thought he had things fixed and
working the problem would return the next day (after a reboot).
[The CoolWebSearch exploit (explained at
http://www.spywareinfo.com
the root of the problem. If you read this site you can see just
how nasty this is. The dam* thing can install from a web page
you may be at or passing through.
http://www.spywareinfo.com
has a fast little shredder
to remove it plus a few other useful utilities. He won't be
100% sure that he has finally beat this bug for a couple days,
but from the tests he's done so far it does appear to have been
killed.
Subject: Registry cure for Searchv hijacker
http://www.computing.net/s
So i go to http://www.spywareinfo.com
So it says and this solution has been posted several times:
After reading all of this, you must be under the impression that a CoolWebSearch hijack is near impossible to fix since there are so many variants. Though it is true that the conventional tools like Ad-Aware, Spybot S&D and HijackThis won't fix all of the variants, there is one tool that will.
After about the 3rd CWS variant, I realized this particular spyware company moved faster than any other I'd seen before, and that the anti-spyware programs wouldn't be able to keep up with it. So I decided to write a separate program dedicated to removing CoolWebSearch. It's called CWShredder and can be downloaded here, in several forms:
Normal form, will work for most people:
http://www.merijn.org/file
--------------------------
If you get a message saying 'A required dll, MSVBVM60.DLL, was not found', install this first:
Visual Basic 6 runtime libraries from Microsoft
--------------------------
If you can't or won't download bare executables for some reason, try this link to the zipped version:
Zipped version of CWShredder
--------------------------
If you get a virus warning for W32/Generic.worm!p2p, try this link instead:
Unpacked version of CWShredder
This removal tool will be updated for any new variants of CoolWebSearch, as well as new affiliates that are sighted. It can remove all of the variants mentioned above.
Note that CWShredder is update very often. If you have a copy that's more than a week old, check for an update first before emailing me it's not working well.
lbp4433,
> http://www.spywareinfo.com
> CWShredder.exe ?
and regarding this one I had already asked you to do so after using hijackthis ?
Thanks,
Sunray
sunray_2003 I apologize for not posting the log file first I will do that shortly. And I also apologize for excepting an before posting the log file. I really appreciate everyone's help I am new to web site. I will certainly go through all the frequently asked questions on using this web site appropriately
LRI41,
> even award all of the
> to the Bellyacher since he really needs them and wants them
I would think you need to watch your language here , Mr.LRI41.what I have said to the questioner is to check the softwares and see if the spywares can be removed. Using most of the softwares if it is not removed then fine. If it can be removed then it is going to benefit all of us here . I am not disagreeing with what you had given ..
Bellyacher since he really needs them = totally unacceptable
Thanks,
Sunray
So did you delete the all registry keys pertaining to cool search
If you have not or even had done that check these keys
***************
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKCU\Software\Microsoft\In
HKEY_LOCAL_MACHINE\Softwar
***************
So even after removing them , you are getting them ..
hav you tried Cwshredder aswell ?
Sunray
LRI41,
> even award all of the
> to the Bellyacher since he really needs them and wants them, it make me no never mind,
I would guess you are not going to mind even if I get all the points here cos I had asked him to use CWshredder FIRST
It would be generous of him to split the points and I donot mind
lbp4433 , If had already requested CS to open this question so that you can split , it is fine with ME
Thanks,
Sunray
here is what my Hijack this log has...any suggestions??
Logfile of HijackThis v1.98.2
Scan saved at 12:31:51 PM, on 8/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\System32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\netjs.exe
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\TASKMAN.EXE:ciq
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EX
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EX
C:\WINDOWS\msagent\AgentSv
C:\Documents and Settings\MIKE\Desktop\Hija
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.EXE
C:\Program Files\Trend Micro\Internet Security\PCCGUIDE.EXE
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {4EF24DB7-3509-B765-D598-C
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
O4 - HKLM\..\Run: [netjs.exe] C:\WINDOWS\netjs.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
Business Accounts
Answer for Membership
by: sunray_2003Posted on 2004-01-15 at 18:30:02ID: 10126527
Use spybot ,ad-ware ,CWshredder and post the log from Hijackthis here
----
spyware.ht ml
ownload/dl spybot.sht ml
ownload/dl adaware.sh tml
ownload/dl hijackthis .shtml
download/d lkldetecto r.shtml
download/d lxcleaner. shtml
download/d lspywarebl aster.shtm l
download/d lspywaregu ard.shtml
download/d lspysites. shtml
download/d lklhunter. shtml
/downloads /bhod/
.net/bhbla ster.html
m/GoodBye- Spy-downlo ad-2012.ht m
/~merijn/ c wschronicl es.html#cw shredder
ort/click2 findnow.sh tml
o.com/
om/
om/actives can/com/ ac tivescan_p rincipal.h tm
ntivirus/d efault.asp
Spyware/Adware removal tools:
--------------------------
What is spyware : http://www.spychecker.com/
SpyBot-S&D : http://www.webattack.com/d
Ad-aware : http://www.webattack.com/d
Trojan Remover :http://www.simplysup.com/
HijackThis : http://www.webattack.com/d
KL-Detector :http://www.webattack.com/
X-Cleaner Free :http://www.webattack.com/
SpywareBlaster :http://www.webattack.com/
SpywareGuard :http://www.webattack.com/
SpySites :http://www.webattack.com/
Keylogger Hunter :http://www.webattack.com/
Spycop: http://www.spycop.com/
BHODemon : http://www.spywareinfo.com
Browser Hijack Blaster : http://www.wilderssecurity
Goodbye Spy http://www.topshareware.co
CWShredder: http://www.spywareinfo.com
Other spyware removal instructions: http://www.pchell.com/supp
online virus scanner:
---------------------
http://housecall.trendmicr
http://security.symantec.c
http://www.pandasoftware.c
http://www.pcpitstop.com/a
Sunray