please help w/ coolweb search and spy sheriff

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by j-p, Aug 9, 2005.

  1. j-p

    j-p Private E-2

    Thanks M. A. for the time to research and prepare the post, "DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan And Virus Removal". I tried to do everything you said and still have many problems. I printed your post for reference and here's how it went. (win xp pro)
    In services.msc, I found 1 of the 3 you listed, RPC helper. Coolwebsearch seems to stay in the reg key, "008f__6q*00d4*00f5*0013'*00aa*00b4*00c6*00d08". I created a "spyware tools" folder and downloaded all the tools you recommended. I couldn't get online in safe mode so I ran ms.config, unchecked everything in startup, then rebooted in normal mode. RavAntivirus was unavailable, I had to skip this. When I got to and ran Trojanscan, the machine froze while removing infected files. I connect w/ sbc dsl but try to use firefox. Trojanscan would only run in sbc browser. I restarted the computer and lost my wallpaper and gained, or woke up, spysheriff, with 2 red x's on my toolbar. Spy sheriff popped up when I started this thread and wouldn't close. I tried to get into task mgr to close it and it said that the administrator blocked access. I rebooted.
    Trend micro runs in the backround and picks up many items and it say's, "access denied". Now when I click on a web page from google, I get "Alert! the document contains no data." I click on "OK" and try again. The page will come up if I do this up to 4 times. I can run Ad Aware repeatedly and immediately and still get coolweb search. One of the spyware programs says that coolweb is not on my computer but A Aware keeps finding it, says it's deleting it, but it comes back immediately.
    It seems I'm loaded w/ problems.
    please help.
    thanks, j-p
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should stop using msconfig to disable startups. Run it again and select Normal Startup.

    Then follow the steps in the following sticky thread: SpySheriff (aka SpywareNo) Removal

    If you already ran ALL of the steps in the READ ME FIRST, start at step # 2.

    Note the online scanners in the READ ME FIRST should be run in normal boot mode if you could not run them in safe mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds