View Full Version : Cool Web Search
Riverrun
March 12th, 2007, 10:39 AM
CWshredder found the following items on my PC:
CWS.Mupdate
CWS. Msconfd
CWS.Smartsearch
CWS.Aboutblank
After running fix, the program told that the items were not present.
After rebooting, I did a new scan and the items were 'found' again.
What's going on there?
Did CWshredder remove them or not?
I can't figure it out.
Can anyone help?
Get
March 12th, 2007, 11:02 AM
Have been a bit to hasty. I would recommend posting at this site: http://www.spywareinfoforum.com , because most likely a hijackthis-log will be needed and those aren't done on Wilders anymore ( http://www.wilderssecurity.com/showthread.php?t=31835 ).
aigle
March 12th, 2007, 12:57 PM
Did u try SuperAntispyware free and AVG antspyware free?
fcukdat
March 12th, 2007, 02:37 PM
2nd to what aigle has suggested but run them both in safe mode:thumb:
The reason why CWS is failing is that it has not been updated to deal with most of the recent stuff and only dose a part job which then allows the infection to restore itself on reboot::)
Riverrun
March 13th, 2007, 12:41 PM
Guys, thanks for the help. I got rid of them eventually. My internet connection is faulty and that's how they got in in the first place. I need a new provider. At least I discovered what was going wrong and I won't be using the old ISP anymore.
They're gone anyway after a dreadful struggle.
Thanks again folks.
Riverrun
April 7th, 2007, 09:13 PM
Found the following suspicious file on my system:C:\WINDOWS\Alcmtr.exe. CWShredder indicates that it might be connected to Cool Web Search. Does anyone recognise it?
aigle
April 7th, 2007, 09:17 PM
Upload it to virus total.
LoneWolf
April 7th, 2007, 09:17 PM
http://www.processlibrary.com/directory/files/alcmtr
-{ Quote: "Upload it to virus total" }-
A very good idea.
fcukdat
April 8th, 2007, 04:48 AM
http://www.virustotal.com/en/indexf.html
Here's the direct url for VirusTotal service:)
Riverrun
April 8th, 2007, 11:24 AM
Thanks for the help, guys.
Riverrun
April 8th, 2007, 06:21 PM
Looks like C:\WINDOWS\Alcmtr.exe is not infected. Thanks again for the help.
aigle
April 8th, 2007, 06:41 PM
What were the results.( don,t put a screenshot though).
Riverrun
April 8th, 2007, 06:46 PM
Didn't get a reply yet but scanned with Avira and Kaspersky and it came out clean.
aigle
April 8th, 2007, 06:51 PM
On their homepage, u can just upload the file to get results online instantly rather than sending a mail to them.
Riverrun
April 8th, 2007, 07:32 PM
Aigle, I tried that, uploaded the file and couldn't find the scan button. Didn't like to pester people by asking again for help.
OK, here goes, how do I scan once I've loaded the file?
Riverrun
April 8th, 2007, 07:36 PM
All I can see is a send button. I press that and nothing happens. ???
lodore
April 8th, 2007, 07:37 PM
go here
http://www.kaspersky.com/scanforvirus
click browse point to the file click on it then clikc ok.
then click on the submit button
lodore
Riverrun
April 8th, 2007, 07:47 PM
Did the Kaspersky file scan and it's come up clean...of virus at any rate. I'm more concerned about malware infection.
Riverrun
April 8th, 2007, 07:51 PM
I think Virustotal is scanning now. I had scripts disallowed for that site.
Riverrun
April 8th, 2007, 08:08 PM
I give up...I just can't scan it with Virustotal...phew:-[
lodore
April 8th, 2007, 08:32 PM
sometimes you have to allow scripts for certain sites then refresh the page to upload files.
lodore
aigle
April 8th, 2007, 08:50 PM
-{ Quote: "I think Virustotal is scanning now. I had scripts disallowed for that site." }-
U need to allow scrips for Virus total. It does not work for me in Opera( unless I allow scripts globally in Opera) but works Ok in FireFox and IE. U can try InternetExplorer.
aigle
April 8th, 2007, 08:52 PM
It,s uploading file. You have to wait a bit for results, for few minutes on dial up for me and more if site load is more.
Here is another scanner
http://virusscan.jotti.org/
One more here.
http://scanner.virus.org/
Have fun!!:)
Riverrun
April 8th, 2007, 09:39 PM
Guys, thanks again for the help. It just wouldn't work with FF. Tried it on IE and it worked a dream. No worries...the decision was unanimous, no virus found. That's a relief. I thought I might be infected. Boy, am I glad. Great suggestion! Thanks again. ;D ;D ;D
aigle
April 8th, 2007, 09:44 PM
Nice to hear.
Riverrun
April 13th, 2007, 02:19 PM
In the past few days I've learnt that CWS infections occur because of an exploit in Microsoft's Java Virtual Machine and that this can be uninstalled safely thus preventing the problem from recurring.
I'm contemplating doing so but thought I'd check here before carrying out the following procedures:
Removing MJVM
Patching the Registry
Installing Sun's JVM
I plan to use Microsoft Java Virtual Machine v1.1.4 Removal Tool.
Can anyone recommend a reliable location from which to download these tools?
Not sure if I should enact these kind of changes in the first place and I'd appreciate some good advise.
Not going to do anything hasty.
TopperID
April 13th, 2007, 04:17 PM
Removing MS JVM should be easy if you follow these instructions:-
http://www.java.com/en/download/help/uninstall_msvm.xml
dja2k
April 13th, 2007, 04:22 PM
AutoPatcher also has this option in its list to do it automatically.
dja2k
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums