CoolWebSearch Keeps Re-Installing

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gorey_girl100, Sep 24, 2004.

  1. gorey_girl100

    gorey_girl100 Private E-2

    Please excuse this post; I know someone has just recently posted a very similar problem but I didn't want mine to get lost in that thread. It is very discouraging to have to put up with CoolWebSearch every time I start up or reboot my PC.

    Running Win98se, have done all the scans by major software programs mentioned here: Ad-Aware, Spybot, etc. etc. They all come up clean, but only because I run X-Cleaner Malware scan on boot up and it always finds CoolWebSearch, which I have it remove. Of course I must have the variant(s) which re-install themselves as I can count on X-Cleaner finding it again when I start a new session.

    CWS is of no use anymore since it is no longer being updated http://www.emotipad.com/newemoticons/Noooooooo.gif

    HijackThis Log shows an entry in I.E. with the about=blank value. I was considering deleting this line but want to be sure that is the right thing.

    What erks me is that I'm mainly using Firefox and when I went to go to my electric company's home page a stupid search engine showed up. Obviously the page has been hijacked and I'm sure CWS is to blame. I'm concerned because I was hoping using Firefox would prevent this from happening but it did anyway.

    I know the CWS problem has been discussed many times here but felt that I needed to give my personal experience and let the group know I do update and run a variety of anti-spy, mal-ware, and trojan detector programs on a daily basis. CWS is only found by X-Cleaner on boot-up and doesn't show on the others probably because I remove it at start up time.

    Going to stop X-Cleaner from scanning at start up and run another program first to see what it picks up. In the meantime, any thoughts, suggestions etc. would be most appreciated. Especially about deleting the about=blank line I found in the Hijack this log.

    Have a great day & God Bless! http://www.emotipad.com/newemoticons/Swing.gif
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Please attach a Hijack This log file.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but without X-Cleaner changing anything. Otherwise we will not see the real problem.
     
  4. gorey_girl100

    gorey_girl100 Private E-2

    Thank you for your patience. I'm trying to do 10 things at one time, as usual!

    Here is the Hijack This log of this morning before removal of anything by X-Cleaner (or anything else, for that matter). It's really frustrating when I try to do everything possible to keep my PC clean and this little bugger won't go away. Kinda like one of those relatives that come to visit and stay for 10 days. :rolleyes: Thanks in advance....
     

    Attached Files:

    Last edited by a moderator: Sep 26, 2004
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please go back and read the HijackThis tutorial again. You did not follow directions, you made no attempt to shut any unrequired applications down, you have the wrong version of HijackThis (you said you follow the READ ME FIRST steps. If you did follow them completely, you would have the correct version.) and you did not post your log as an attachment like we asked. What you posted is called inline text.

    Get the proper version of HJT it could show other problems. Also shut down some stuff and uninstall any unnecessary applications. Are all thoses programs you have running really necessary for you? I would think that you really don't need most of that stuff. Does this PC run okay? You probably do not have much of you system resources left.

    Do you have any idea what these are:
    C:\WINDOWS\SROMTSR.EXE
    F1 - win.ini: load=sromtsr.exe

    Is this required by your ISP:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http:\\proxy:8080


    By the way in your first message you said,
    "CWS is of no use anymore since it is no longer being updated"

    It's CWShredder. CWS is the infection itself. It's true the CWShredder is not being updated but it is incorrect to say it is of no use. There are loads of CWS types of infections out there the CWShredder fixes everyday. If you do not run it, that is a big mistake. It never hurts and as I said, it still finds lots of CWS infections.

    Exactly what is it that you say X-Cleaner is deleting.

    Uninstall RealDownload Express if it has an uninstall.
    Otherwise have HijackThis fix the O4 line below:
    O4 - HKCU\..\Run: [RealDownload Express] C:\WINDOWS\SYSTEM\npnzdad.exe /t

    Then locate and delete (may have to do in safe mode):
    C:\WINDOWS\SYSTEM\npnzdad.exe

    The below can be fixed with HJT but they are not CWS related:
    O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - (no file)
    O16 - DPF: lass414 - https://onlinegames.lasseters.com.a...ses/lass414.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsol...ArcadeRdxIE.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0555360...ip/RdxIE601.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
    O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
     
    Last edited: Sep 25, 2004
  6. gorey_girl100

    gorey_girl100 Private E-2

    You must excuse me I suffer from a memory problem that really screws me up a lot. I'm really not the idiot I appear to me and it is very frustrating to me to try and follow directions properly and find that I do things backwards, etc. Please bear with me--it comes from being in an accident several years ago. Sorry I appear as a dunce.

    The "RealDownload Express etc" stuff all has to do with the RealArcade and Real Music that I belong to for my gaming and music downloads. I've been having problems with both lately and have had to re-install one of them completely in order to resolve the issue.

    No idea what C:\WINDOWS\SROMTSR.EXE
    F1 - win.ini: load=sromtsr.exe is. On the other question of what my ISP requires I will check with them.

    X-Cleaner says it's removing CoolWebSearch but does not provide further information. I tested my other software today and CWS does not show up at all even if I don't run X-Cleaner first. I'm starting to wonder if it is a bug in their program. CWShredder also comes up clean.

    It's back to the drawing board so I will work on your instructions; however, I hesitate about the Real Download stuff as it seems these entries are necessary for the programs to work properly. Will check with "Real" also about this.

    PC runs a lot slower then it should. I run out of RAM frequently. I might mention I am a photo, game and music buff and my PC is from 2000. Not much has been upgraded and I certainly would appreciate more RAM!

    I ask for your patience as I really feel like I am running against the tide with this problem. First thing--get the latest Hijack This version (thought I had it). Will go from there.

    Your help is most appreciated. Many thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry! I'm pretty patient! Although once in awhile I just preach a little when directions do not appear to be followed. I understand about accidents and what they can do. One of my sons still suffers from a brain injury due to a car accident and memory loss (especially short term) and ability to follow directions is a problem for him too. Just try to take it one step at a time and if you are not sure about something ask for help before continuing.

    So did you get the correct version of HijackThis yet? If not, do that now.

    As far as I know ReadDownloadExpress is Advertising spyware

    see this http://www.windowsstartup.com/wso/detail.php?id=2250

    I don't know if it has anything to do with ReadArcade or not.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds