coolsearch.yexe NIGHTMARE!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by vae, Nov 23, 2004.

  1. vae

    vae Private E-2

    When I run Spybot I get this entry: coolsearch.yexe

    It is checked and has two entries.

    I run the FIX and Spybot delets both.

    The minute I open up Explorer, it's back.

    Things appear on my favorites list such as, Automotive, Medicine etc..

    Which I try to delete them, but they just come back when I open Explorer.

    I occasionally a get pop up that says "Internet Explorer needs to close" and it gives an option to send or not send an error message to MS.

    Is there a simple way to get rid of coolsearch.yexe?

    There was a registry fix I found on another forum to get rid of DSO while in Spybot that worked well and wasn't to complicated.

    THIS THING IS A REAL NIGHTMARE.

    Thanks,

    Von
     
  2. Tribulattifather

    Tribulattifather Private E-2

    Your best bet isto run a few applications in safe mode such as CWShredder (http://www.majorgeeks.com/download3019.html)

    Then run a program like Adaware SE Personal (http://www.majorgeeks.com/download506.html) and install the VX2 plugin (http://www.majorgeeks.com/download4283.html)

    And lastly use a program like HiJackThis (http://www.majorgeeks.com/download3155.html) Only too see the log file... If you are a novice it is best to let us see the log file from HiJackThis....Open HiJackThis up, then click on config and in default start page, put your favorite search engine i.e. http://www.yahoo.com and the same for default search page. Then click on Back and click on Scan and then where scan was will be a Save Log button....Find that save log button and email (Tribulattifather@yahoo.com (<<Don't click this link, copy and paste into emailer clientel)) it to me and I'll review it for you to tell you which ones to fix... If you do this, make sure you do this in safe mode with System Restore off. (Right click My Computer go to Properties and then go to the System Restore tab and check the unchecked box if not checked already.
     
  3. Kodo

    Kodo SNATCHSQUATCH

    Please follow all the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal


    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  4. vae

    vae Private E-2

    Many Thanks PFC, here is the log:
    VE

    Logfile of HijackThis v1.98.2

    Scan saved at 5:15:21 PM, on 12/2/2004


    <SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">Platform: Windows XP SP1 (WinNT 5.01.2600)
     
  5. vae

    vae Private E-2

    Sorry about that PFC. I didn't read your response in a very thorough manner. I will email file results to your address per your instructions.

    Thanks,

    VE
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds