WebCoolSearch hijacking my browser

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Biggy2
    Confirmed User
    • Feb 2002
    • 1821

    #1

    WebCoolSearch hijacking my browser

    anyone know how to remove this shit?

    been trying and trying and trying..

    CWShredder, Spybot S&D, still no luck

    PLease
  • liquidmoe
    Confirmed User
    • Mar 2002
    • 4994

    #2
    Tried ad-aware?

    Take Luck!

    Comment

    • psyko514
      See sig. Join Epic Cash.
      • Oct 2002
      • 22366

      #3
      does it constantly reset your homepage to teen-biz.com?
      i had to get rid of this shit on my mom's comp last night.

      run hijack this, delete the offending files and then boot-up in safe mode. navigate to your startup folder in your start menu and delete "winlogon". open IE, set your homepage to blank and then reboot.

      everything should be ok now.

      Bad Girl Bucks
      - 50% Revshare through CCBill.
      Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

      Phoenix Forum Pics | Webmaster Access Montreal pics
      email: psyko514(a)gmail.com | icq: 214-702-014

      Comment

      • SetTheWorldonFire
        Confirmed User
        • Feb 2002
        • 7444

        #4
        ad-ware

        plus, you might want to upgrade those proggies you have now.

        www.STWOFDesign.com
        hit me up on icq 154206276 or Skype: JaimeGizzle

        Comment

        • psyko514
          See sig. Join Epic Cash.
          • Oct 2002
          • 22366

          #5
          if he has what i think he has, ad-ware or anything else won't do jack shit.

          Biggy2, when you shut down, is there a program called Win Min that you have to force close?

          Bad Girl Bucks
          - 50% Revshare through CCBill.
          Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

          Phoenix Forum Pics | Webmaster Access Montreal pics
          email: psyko514(a)gmail.com | icq: 214-702-014

          Comment

          • candyflip
            Carpe Visio
            • Jul 2002
            • 43074

            #6
            Try this bad boy right here.

            http://www.kephyr.com/spywarescanner/

            It scans and tells you exactly what adware/spyware has infected your system and then provides detailed instructions on how to get rid of each and everyone.

            Takes some time to manually edit your registry, reboot and then delete any associated files for each piece of shit that has made it's way onto your computer. But...a little bit each day for a few days and my PC was clean again.

            Spend you some brain.
            Email Me

            Comment

            • bignasty
              Confirmed User
              • Nov 2003
              • 1421

              #7
              go here http://www.spychecker.com/program/cwshredder.html
              Ive had to use this several times to get rid of this.
              '

              Comment

              • psyko514
                See sig. Join Epic Cash.
                • Oct 2002
                • 22366

                #8
                Originally posted by bignasty
                go here http://www.spychecker.com/program/cwshredder.html
                Ive had to use this several times to get rid of this.
                did you read his post??

                Bad Girl Bucks
                - 50% Revshare through CCBill.
                Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

                Phoenix Forum Pics | Webmaster Access Montreal pics
                email: psyko514(a)gmail.com | icq: 214-702-014

                Comment

                • Choker
                  Confirmed User
                  • Apr 2001
                  • 9024

                  #9
                  Originally posted by bignasty
                  go here http://www.spychecker.com/program/cwshredder.html
                  Ive had to use this several times to get rid of this.
                  this works thanks, this CWS is by far the nastiest hijacker there is. This guy is taking over pcs like crazy
                  ICQ me lets make a deal 116894466

                  Need dating, cam, or tube traffic? I got it.http://http://www.chokertraffic.com

                  The Original http://www.chokertraffic.com/

                  Premium country pop-unders from $1.50 per k. I challenge you to compare this traffic to any other brokers.
                  http://www.chokertraffic.com/public/tabs.php?t=o

                  Comment

                  • candyflip
                    Carpe Visio
                    • Jul 2002
                    • 43074

                    #10
                    CoolWebSearch

                    Overview
                    CoolWebSearch is a collection of browser hijackers. Many of these hijacks your home and search page and redirect them to www.coolwebsearch.com.

                    Classification
                    Adware

                    Files
                    loader.exe, Tapicfg.exe, ctfmon32.exe, iedll.exe, svcpack.exe, svcinit.exe, bootconf.exe, msinfo.exe, svchost32.exe, msupdate.exe, msspi.dll, dnsrelay.dll

                    Vendor
                    CoolWebSearch.com

                    Privacy policy
                    No privacy policy available.

                    Detection
                    Bazooka Adware and Spyware Scanner detects CoolWebSearch. Bazooka is freeware and detects spyware, adware, trojan horses, viruses, worms, etc. Read more »

                    Feedback, suggestions, support
                    Please let me know if you need support, have questions or would like to give me feedback. Please notice that I'm not the author and not in any way affiliated with CoolWebSearch. This site is dedicated to help you with the detection and removal of spyware, adware, viruses, worms, trojans, keylogger, dialers, etc. Click here to contact me, the developer of Bazooka.

                    Uninstall procedure
                    Merijn BelleKom has written an uninstaller called CoolWebShredder that should remove all variants of the CoolWebSearch hijacker. You can also remove it manually using the instructions at doxdesk.com or spywareinfo.com.

                    Please support me
                    Thank you for using my site. Please help me to keep this site and software up-to-date.

                    Spend you some brain.
                    Email Me

                    Comment

                    • candyflip
                      Carpe Visio
                      • Jul 2002
                      • 43074

                      #11
                      Description
                      CoolWebSearch is a name given to a wide range of different browser hijackers. Though the code is very different between variants, they are all used to redirect users to coolwebsearch.com and other sites affiliated with its operators.

                      The script at this site can only detect one of the variants listed here, namely CoolWebSearch/DNSRelay.

                      Variants
                      CoolWebSearch/DataNotary: earliest known variant, hijacking to datanotary.com. Drops a CSS stylesheet file in the Windows folder and sets it to be used as the user stylesheet for all web pages viewed in IE. The stylesheet includes hahahahahaded hahahahahahahahahaha code which tries to guess when the user is viewing porn sites.

                      CoolWebSearch/BootConf: drops a user CSS file in the same way as DataNotary, but pointing at www.coolwebsearch.com. Also hijacks the home page and all search settings to point to coolwebsearch, and hacks the DNS Hosts file to redirect access of MSN address-bar search to coolwebsearch.com. The site names are obfuscated using URL-encoding (%XX) to make them difficult to read. A program bootconf.exe is set up to run on every startup, resetting the hijack. Finally coolwebsearch.com is added to the Trusted Sites list, along with msn.com, whom coolwebsearch are also impersonating.

                      CoolWebSearch/MSInfo: another user-CSS-hijacker, this time pointed at true-counter.com, currently redirecting to global-finder.com.

                      CoolWebSearch/SvcHost: a Hosts file hijacker, which works in a rather unusual way (probably to avoid being detected by anti-hijacker tools). Its targeted sites (Yahoo Search, MSN Search and all countries? versions of Google) are set in the Hosts file to point to ?localhost? (127.0.0.1). Since the local host (the computer the browser is running on) is most often not running a web server, this results in an error page; it is this error page that is then hijacked to the CWS site slawsearch.com.

                      CoolWebSearch/PnP: a search hijacker that hides inside the ?inf? folder usually used for storing device driver information. Its hijacker file oemsyspnp.inf is run on each startup, using a slightly different install command each time. This command cycles through install sections 'RunOnce', 'AudioPnP', 'VideoPnp', 'IdePnP' and 'SysPnP', though quite why is unknown as it does the same thing regardless of which section is used, namely hijacking home page and search settings to point at www.adulthyperlinks.com and www.allhyperlinks.com. It also adds activexupdate.com to the IE ?Safe Sites? list, for unknown purpose (this is not the same as the Trusted Sites Zone).

                      CoolWebSearch/MSSPI: a search results hijacker implemented as a Winsock2 Layered Service Provider (a fairly low-level networking component, which is tricky to remove). Targets Google, Yahoo and Altavista, opening advertising from unipages.cc.

                      CoolWebSearch/DNSRelay: an address bar search hijacker implemented as an IE URL Search Hook. As well as search phrases, entering any site name into the address bar without a leading ?http://? or ?www? will result in a search aimed at activexupdate.com, a CWS site redirecting through yellow2.com to allhyperlinks.com.

                      Distribution
                      Suspected to be installed by pop-ups exploiting security holes in IE.

                      What it does
                      Advertising
                      Yes. In DataNotary and BootConf variants, the script hahahahahaded in this style sheet may open mostly porn pop-ups if it thinks the page being viewed is porn-related. The MSSPI variant will pop up ad links in a window after every few pages viewed on a targeted search engine.

                      Privacy violation
                      No.

                      Security issues
                      Yes, in the BootConf variant. Adding coolwebsearch.com to IE's Trusted Sites Zone means pages there are allowed to download and install any code they like.

                      Stability problems
                      The DataNotary, BootConf and MSInfo variants may cause significant slowdown when typing in a browser window on some systems. The SvcHost variant also prevents you from reaching Google or the search services of MSN or Yahoo completely.

                      Removal
                      Merijn Bellekom has prepared a tool called CWShredder which should be able to remove all known CoolWebSearch variants automatically.

                      Manual removal
                      DataNotary, BootConf, MSInfo variants
                      For these variants, start by opening Tools->Internet Options->Accessibility and make sure the 'user style sheet' option is turned off.

                      You should then be able to delete the user stylesheet from the Windows folder. With DataNotary it is called 'default.css'; with MSInfo it is called 'oslogo.bmp'; with Bootconf it may be either.

                      MSInfo variant only
                      Next, open the file 'win.ini' from the Windows folder in a text editor. Delete the line ?run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSIN FO\msinfo.exe? and save. (This line may change a little on different systems, but will always point to msinfo.exe.) Delete the 'MSInfo' folder inside 'Common Files' in the 'Program Files' folder.

                      BootConf, SvcHost variants
                      Next, open the registry (Start->Run->regedit), find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run, and delete the bootconf.exe or svchost.exe entry. You can then delete the bootconf.exe or svchost32.exe file from the System folder (which is inside the Windows folder, and called 'System32' on Windows NT/2000/XP)

                      BootConf, SvcHost, MSInfo variants
                      From the System folder, open the drivers->etc folders and find the file named 'HOSTS', with no extension. Either edit it to remove the hijacker entries, or simply delete the file.

                      PnP variant
                      Open the registry (Start->Run->regedit) and find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run. Delete the 'SysPnP' entry, and the 'oemsysinf.pnp' file from the 'inf' folder (which is inside the Windows folder).

                      MSSPI variant
                      Removing a Layered Service Provider by hand is tricky and if you get it wrong you'll lose your internet connection. If you really want to try, open the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\WinSock2 \Parameters\Protocol_Catalog9\Catalog_Entries, delete the subkeys starting with the path of msspi.dll, renumber the remaining subkeys, and set the Num_Catalog_Entries value in the Protocol_Catalog9 key to match the highest numbered subkey left.

                      Normally it is better to get a program (eg. CWShredder, HijackThis or LSPFix to remove an LSP for you.

                      Having done that, open the registry and check the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run for an 'msupdate' entry; delete it if you find it. Restart the computer and you should be to delete msspi.dll in the System folder (which is inside the Windows folder, and called 'System32' on Windows NT/2000/XP), along with msupdate.exe if you have it.

                      DNSRelay variant
                      Open a DOS command prompt window (from Start->Programs->Accessories) and enter the following commands:

                      cd "%WinDir%\System"
                      regsvr32 /u dnsrelay.dll
                      Restart and you should be able to delete the file 'dnsrelay.dll' in the System folder (which is inside the Windows folder, and called 'System32' on Windows NT/2000/XP).

                      All variants
                      After having removed the software, use Internet Options->Programs->Reset Web Settings to remove the bogus home page and search settings.

                      Spend you some brain.
                      Email Me

                      Comment

                      • Biggy2
                        Confirmed User
                        • Feb 2002
                        • 1821

                        #12
                        Originally posted by psyko514
                        if he has what i think he has, ad-ware or anything else won't do jack shit.

                        Biggy2, when you shut down, is there a program called Win Min that you have to force close?
                        no,

                        its fucked up

                        SPybot and CWShredder detect it, but boom, i restart, open up a browser window and its there,

                        except i didnt once and it didnt happen, but 3 seconds later it was fucking there again.. it sets my homepage to

                        http://qwertysearch123.biz/?id=1017

                        Comment

                        • Biggy2
                          Confirmed User
                          • Feb 2002
                          • 1821

                          #13
                          CWShredder does not work, i just tried it again, and when i opened a new IE window after setting it blank and running it.. boom


                          i get sent right back to that page, this fucking shit sucks.

                          whoever wrote it should be sent to jail forever.

                          Comment

                          • psyko514
                            See sig. Join Epic Cash.
                            • Oct 2002
                            • 22366

                            #14
                            Originally posted by Biggy2


                            no,

                            its fucked up

                            SPybot and CWShredder detect it, but boom, i restart, open up a browser window and its there,

                            except i didnt once and it didnt happen, but 3 seconds later it was fucking there again.. it sets my homepage to

                            http://qwertysearch123.biz/?id=1017
                            ok, it's doing the exact same thing that my mom's was doing.
                            teen-biz.com is the same thing as that link except to the adult section of coolwebsearch.
                            i'll bet it adds bookmarks too, right?

                            if you get rid of the files with spybot/cwshredder, boot into safe mode and delete the winlogon file in your startup folder, it'll be gone for good.

                            Bad Girl Bucks
                            - 50% Revshare through CCBill.
                            Promote BrandyDDD, Pixie's Pillows, Action Allie and more!

                            Phoenix Forum Pics | Webmaster Access Montreal pics
                            email: psyko514(a)gmail.com | icq: 214-702-014

                            Comment

                            • Biggy2
                              Confirmed User
                              • Feb 2002
                              • 1821

                              #15
                              Originally posted by psyko514


                              ok, it's doing the exact same thing that my mom's was doing.
                              teen-biz.com is the same thing as that link except to the adult section of coolwebsearch.
                              i'll bet it adds bookmarks too, right?

                              if you get rid of the files with spybot/cwshredder, boot into safe mode and delete the winlogon file in your startup folder, it'll be gone for good.
                              hey psyko,

                              yes, it erased all my fucking bookmarks, IM GONNA FUCKING FLIP OUTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT.

                              thanks im gonna give it a shot.

                              Comment

                              • directfiesta
                                Too lazy to set a custom title
                                • Oct 2002
                                • 30217

                                #16
                                Got it off ( well desactivated it) my brother inlaw computer.

                                Ad-Aware doesn't work... But System Mechanic ( www.iolo.com) allows you to manage the start up and to clean adware proggies, and it worked.

                                Free 30 day trial on site.

                                Good luck
                                I know that Asspimple is stoopid ... As he says, it is a FACT !

                                But I can't figure out how he can breathe or type , at the same time ....

                                Comment

                                Working...