CW Comeup Hijacker- how do i remove?

Discussion in 'Malware Help (A Specialist Will Reply)' started by DatboiFromCa, Mar 9, 2007.

  1. DatboiFromCa

    DatboiFromCa Private E-2

    ran counter spy.. not the whole way, because i ran for almost two hours and it wasnt halfway, but it found what i wanted it too. here it is

    CWS.CameUp
    Type Adware
    Type Description Adware, also known as advertising software, displays third-party advertising on the computer. The ads can take several forms, including pop-ups, pop-unders, banners, or links embedded within web pages or parts of the Windows interface. Some adware advertising might consists of text ads shown within the application itself or within side bars, search bars, and search results. Adware is often contextually or behaviorally based and tracks browsing habits in order to display ads that are meant to be relevant to the user.
    Category Hijacker
    Category Description Hijackers are software programs that modify users' default browser home page, search settings, error page settings, or desktop wallpaper without adequate notice, disclosure, or user consent. When the default home page is hijacked, the browser opens to the web page set by the hijacker instead of the user's designated home page. In some cases, the hijacker may block users from restoring their desired home page. A search hijacker redirects search results to other pages and may transmit search and browsing data to unknown servers. An error page hijacker directs the browser to another page, usually an advertising page, instead of the usual error page when the requested URL is not found. A desktop hijacker replaces the desktop wallpaper with advertising for products and services on the desktop.
    Level Elevated
    Level Description Elevated risks are typically installed without adequate notice and consent, and may make unwanted changes to your system, such as reconfiguring your browser's homepage and search settings. These risks may install advertising-related add-ons, including toolbars and search bars, or insert advertising-related components into the Winsock Layered Service Provider chain. These new add-ons and components may block or redirect your preferred network connections, and can negatively impact your computer's performance and stability. Elevated risks may also collect, transmit, and share potentially sensitive data without adequate notice and consent.
    Advice Type Remove
    Description CWS.CameUp is an adware application that hijacks the user's Internet Explorers start page, and prevents the user from changing the URL back to their preferred homepage.
    Add. Description CWS.CameUp also adds a toolbar and search bar that redirects users to advertising websites. CoolWebSearch StartPage is one of the many CoolWebSearch variants.
    Author CoolWebSearch.com
    Alias Adware.Iwantsearch, Adware-SBSoft
    File Traces
    %appdata%\ aelr.exe
    %local_settings%\ temp\ download_plugin.exe
    %LOCAL_SETTINGS%\ temp\ nsc59.tmp\ system.dll
    %system%\ toolband.dll
    %system%\ winaok32.exe
    %system%\ winttr.exe
    %windows%\ appfy32.dll
    %windows%\ downloaded program files\ ipreg32.dll
    %windows%\ downloaded program files\ rundlg32.dll
    %windows%\ gx9fzj83m9.exe
    %windows%\ ietlbass.dll
    %windows%\ madopew.dll
    %windows%\ webdlg32.dll
    %windows%\ winsx.dll
    amap.dll
    appfy32.dll
    crol32.dll
    dmoc.dll
    ico.dll
    ietlbass.dll
    ipreg32.dll
    lmk.dll
    madopew.dll
    nocj.dll
    pdeg.dll
    process.exe
    rundlg32.dll
    system.dll
    systime.exe
    webdlg32.dll
    winmm64.exe
    winsx.dll


    thats all good. but i have no idea how to fix it.. what do i do it to delete/remove it from my computer, helps please
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You re-run counterspy and then have it remove/quarantine whatever it finds.

    THEN:

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. DatboiFromCa

    DatboiFromCa Private E-2

    did it, it found it and i quaranteed it.. but when i went back on internet same thing happened.. should i restart my comp?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should do the rest of the instructions I gave you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds