HijackThis-ignore list & coolwebsearch...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by acer06, Feb 21, 2006.

  1. acer06

    acer06 Private E-2

    Hi!
    I have two questions:
    1) If I ran HijackThis and no suspicious or unknown files were found on my computer (I checked with on the online analysis tool), is it a good idea to put any of those files in the ignore list?

    2) I have a new laptop and before I installed all my anti-spyware, firewall, etc. apparently coolwebsearch got on my system. As I installed each new anti-spyware progam it was discovered (or re-discovered) and I removed it (repeatedly). I believe the the Microsoft beta 2 (Windows Defender) must have removed it finally or the last piece of it.

    Afterwards, HijackThis did not find it. Nor has Windows Defender, Spybot or Adaware found it again.

    Do you think it is really gone, or might there still be some portion left. (Do I need to use CoolWebShredder to get rid of it completely?)

    Thank you for your help! :)
     
  2. acer06

    acer06 Private E-2

    Oh! and Norton Ant-Spyware is clean too!
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Don't use the filters! It will only run you into issues if someone like us ever looks at you log. We will question why so much is missing. If you are not an expert at reading logs you should not be using HJT on you own anyway. Also note that the analysis tools are far from perfect.

    There are around 170 to 180 forms of CWS. Most of which HijackThis does not show any signs of. HijackThis is not an antispyware program. It is a tool for expert users to snoop around at various things on your system. In reality, it shows very little of the kinds of malware that can be hiding on a system. That is why it is the last tool we run not the first. HijackThis logs can be perfectly clean but a system can still be badly infected.

    If you want to be sure you are clean, run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
     
  4. acer06

    acer06 Private E-2

    CoolWWWSearch... is it gone, now?

    Thank you very much for your time!

    History:
    I wote last month after CoolWWWSearch got on my system. Spybot had found it in 6 loations (on 2/20/06): 2 in "CameUp Root class", 2 in "CameUp Class ID", 1 in "CameUp Interface", and 1 in "Toolband Type Library". (Spybot never found CoolWWWSearch again.) There were no symptoms at that time.

    Since I last wrote, I have not used the laptop very much. When I did start it up recently, I began going through your 9 recommended steps.

    Current:
    But, I ran into a problem: files would not download from the internet (from your site and from my yahoo mail account). The download window would open, I would specify the file to put the download in, the download would begin (listing same file) and then when the download was over, the window would disappear and the application could not be found anywhere on the computer. I did have some IT professionals take a look. They had not seen this issue before either. They could not find the applications either.

    So I did a system restart to a day before that issue began. Then I went through your steps. All scans were clean (except one found 3 "no threat" items which I removed anyway). (I performed the following in safe mode: CCleaner, MS Malicious Software Removal Tool, Ad-Aware SE, Spy-bot, MS Windows Defender, CWShredder, Bitdefender, Panda ActiveScan, and Norton Anti-Virus; then I ran HijackThis.)

    Request:
    I have not been experiencing any more problems, but wanted someone to double check the hijackthis log to see if there is anything that's been overlooked. (Maybe I should have waited, but, after Step 7 I did clear the System Restore points (step 1).

    I have attached my system specs, the HijackThis log and the log from the Bitdefender. The Panda AcaiveScan did not povide a link to a log; I suppose because it did not find anything.

    Thanks again for your time!

    ---------------------------------------------------------------
    My system specs are:
    Operating System
    Windows XP Professional Service Pack 2 (build 2600)
    System Model
    Acer, inc. Aspire 5670
    Processor a
    1.67 gigahertz Intel Pentium III
    64 kilobyte primary memory cache
    2048 kilobyte secondary memory cache
    Main Circuit Board
    Board: Acer, Inc. Bodensee
    Bus Clock: 166 megahertz
    Drives Memory
    115.82 Gigabytes Usable Hard Drive Capacity
    103.64 Gigabytes Hard Drive Free Space
    Hard drive (120.03 GB)
    Modules
    2048 Megabytes Installed Memory
    Virus Protection =
    Norton AntiVirus Version 11.00
    Virus Definitions Version 3/22/2006 Rev 7
    All required security hotfixes (using the 03/14/2006 Microsoft Security Bulletin Summary) have been installed.
     
  5. acer06

    acer06 Private E-2

    Re--CoolWWWSearch... is it gone, now?

    Sorry,
    It appears that the attachments didn't attach before. Here they are.

    PS (The "3 "no threat" items which I removed anyway" were MRUs.)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Re--CoolWWWSearch... is it gone, now?

    You're log is clean. If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. acer06

    acer06 Private E-2

    Yea! I will work through the protection steps now.

    I want to thank you and the creators of this site for taking the time to make such an outstanding resource! Your instructions are extrememly helpful and they organize all the various information on the web.

    Thank you very much again!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds