Link to home
Start Free TrialLog in
Avatar of bigstar
bigstar

asked on

Can't remove Spyware: CoolWWWSearch.WCADW

I'm running both Spybot S&D and Ad-Aware but the following just keeps on coming back:

CoolWWWSearch.WCADW: IE Search page (Registry change, fixing failed)

Spybot offers to re-run on boot up but still cannot remove this item.

Any suggestions:

Thanks
Avatar of Microtech
Microtech
Flag of United Kingdom of Great Britain and Northern Ireland image

Hi bigstar,
http:Q_20975384.html#10973796 a tool to remove all spyware including coolweb etc


Hope This helps
Avatar of tanelorn
tanelorn

Hi
run your updated spyware tools in safe mode.

that should take care of it for you


Tanelorn
I'm sorry,  
boot your machine into safemode by pressing F8 at startup,  once the system boots up,  run your tools.

T
I'll just expand on that :$

Keep pressing F8 rapidly at startup just before the Windows logo comes up and select "Safe Mode"...

Is Ad-Aware actually detecting the spyware? You might need to hit "Web Update" in Ad-aware..
do this its defnetely help you.
         in internet explorer(properties) - set about blank then run this tools.

·      RepairDefaultPrefix.reg <http://mvps.org/winhelp2002/RepairDefaultPrefix.reg> [right-click and select: Save As]
Repairs the corrupted or altered (spyware) HTTP prefixes
Note: HijackThis can also repair the DefaultPrefix entry [more info <http://www.spywareinfo.com/~merijn/htlogtutorial.html>]

dheerendra
(Network Engineer)

This worked for me:
>Use Spybot but also enable teatimer (comes with Spybot) then run a scan.
>once scan is finished, reboot computer.
>Spybot will run again. clean any thing that was found.
>Spybot Teatimer will then report that its noticed a registry change, tick the box that reads 'remember this..' and then click on deny change.
>That's it.

What this does is it will disable the program from running - effectively deleting it and making sure it doesnt comeback.

I hope this helps you out.

regards

BAFP
oh when u do the first scan, make sure you click all the spyware and click Fix It. then follow the remaining intructions.
Avatar of bigstar

ASKER

So far I've tried running Spybot and Ad-Aware (with latest updates) in safe mode, then usermode. This is my company machine and I had to get the admin credentials. When I ran the progs in safe mode, I am seeing a different set of spyware found, I.E. not CoolWWWSearch.WCADW. When I return to my ordinary user mode, CoolWWWSearch is still there and still immovable.

I have also removed the Java VM as suggested.

Admittedly I have not tried all the solutions here, but I'm disappointed to know the safe mode method has not worked.

Can this be remedied?
How about making the user an Admin, Booting into safe mode, logging in as that user....Clearing computer of Spyware..

Remove Admin privallages..and then be done ready for tea time ;)?
Avatar of bigstar

ASKER

Hmmn

Good Idea Matthew.

I'll give it a bash.

Looking forward to teatime :)
Hi

Let's hope that works ok. If it doesn't, then disable system restore if xp or Me, restart in safe mode, run this and post the log up here for us to have a look at,
Hijackthis
http://www.spychecker.com/program/hijackthis.html

Deb :))
Read this:

https://www.experts-exchange.com/questions/20975384/Standard-response-material-re-Spyware-Adware-BHOs-and-other-Malware.html

Many experts contributed to this and it'll give you the right info you need to remove all spyware etc!

Good Luck

Kin
Have you tried the collwebshredder already?
update its definitions it solved my problem
Dear Bigstar:

Perhaps this is a variant or alias of CoolWebSearch.  Details and manual removal instructions are on Pest Patrol's web site at http://pestpatrol.com/pestinfo/c/coolwebsearch.asp.

Regards,
Michael Knoll
Dear Bigstar...

If you haven't already solved your CoolWebSearch problem, try CWShredder.  You can download it from the following sites:

http://www.softpedia.com/progDownload/CWShredder-Download-8114.html
http://www.majorgeeks.com/download4086.html
http://www.pcworld.com/downloads/file_download.asp?fid=23551&fileidx=1

Regards
James H
"Hmmn

Good Idea Matthew.

I'll give it a bash."

Wonder how that went, logically it was a good solution,
ASKER CERTIFIED SOLUTION
Avatar of modulo
modulo

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial