PLEASE HELP ME--- Coolwebsearch about:blank

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dancer620, Sep 21, 2004.

  1. dancer620

    dancer620 Private E-2

    Hey guys... I'm new to this site but I figured I'd be able to find the help that I need here!
    I unfortunately and regrettably managed to get the coolwebsearch about:blank spyware on my poor mother's brand new computer (it's like the first new thing she's bought for herself since I was born- so I feel HORRIBLE.) I've been working hard day and night for the past few days trying to get rid of it-- and sometimes I think I've succeeded -- but then it comes back full force worse than ever all of a sudden. I am by no means a computer whiz... I know more than enough to get me by... and I'm not too bad with them... but not good enough to know really detailed and advanced stuff. I am really good at following directions though... just not up on all of the really advanced computer lingo.
    Anyway--- I've tried adaware, cwshredder, spybot search and destroy, my mcafee anti virus, and downloading all the critical new XP service packs. I've downloaded hijack this.... but haven't done anything with it yet.
    When I run adaware--- it detects like 11 or so registry values that are corrupt, a few different registry keys that are corrupt, and many tracking cookies and other coolwebsearch files that are there. I change my homepage back and it stays for a while.. then it switches itself back to about:blank. I know how to get into my registry.. but do not know how to modify it.. and won't without help cuz I know it can screw up my mom's entire system.
    Can someone PLEASE help me so I can fix my mistake for my mom????

    ~Alicia~
     
  2. Kodo

    Kodo SNATCHSQUATCH

  3. rickerby47

    rickerby47 Private E-2

    Download Cws Shredder From Geeks And Suggest Spystormer This Will Get Rid Of Hijacker Run Shredder This Should Detect The Pest And Remove Good Luck Alan
     
  4. dancer620

    dancer620 Private E-2

    Okay..
    I followed the link you posted and here are the possible problems/situations I encountered...

    First of all- I was unable to boot into safemode with networking and run the online scans... because I am on 56K Dialup (unfortunately) at this time.... so it would not let me sign onto AOL to access the sites. So-- I ran those programs in regular mode... and then proceeded to run the rest of the suggested programs in the safe mode.

    When I did run the micros scan online.... it did find 5 files. However... it would only remove 1 on it's own. So, I noted the filenames of the remaining 4 files and deleted them manually (hoping that it wouldn't backfire on me.)

    Then I moved on to the symantic security check... and had nothing but problems with it. It kept going into error and it wouldn't finish scanning no matter how many times I tried to do it.

    So I finally booted into Safe Mode and ran the McAfee Stinger program. It claimed to have found some sort of Backdoor virus... but said that there was an error in cleaning it and that I would have to reboot in order to clean. No idea on how to handle that mess.

    Everything else seemed to have run alright and said to have done their jobs.... except for about:blaster. About blaster said it found a corrupted .dll file... "hlpggac.dll" when i ran it in safe mode.. but then it repeatedly tried to remove it and wouldn't stop.. so I had to reboot. It never finished the scan. So I gave up and booted into regular mode-- and ran it again. There were no messages about that .dll and it claimed to have fixed any problems.


    So.. that's where I'm at right now. Not sure if the coolwebsearch about:blank spyware crap is gone yet or not-- but I did at much as I could of those instructions. Please help!

    ~Alicia~
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have just rebooted and let it do its thing. It could not delete the file because it was most likely in use. It was now flagging it to delete upon reboot before it could run again.


    So have you rebooted a few times and performed some surfing and opening and closing of a few browser sessions. That should tell you if you still have the problem.

    If so, you should You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    And post a HijackThis log as a .txt file attachment.

    Make sure you close all running programs including your web browser (including this one your reading in), e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds