Wilders Security Forums  

Go Back   Wilders Security Forums > Browser Hijacks and Spyware Problems > adware, spyware & hijack cleaning
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Spyware Cleaning Section Closed!!
Notice: The spyware cleaning (HijackThis) section is closed. Wilders Security no longer provides one on one spyware cleaning assistance. Please see this announcement for a list of websites that provide such services.
 
 
Thread Tools Search this Thread
  #1  
Old April 16th, 2004, 09:36 PM
lorellen lorellen is offline
Infrequent Poster
 
Join Date: Apr 2004
Posts: 1
Exclamation cookies reproducing - coolshader??

Yesterday a virus alert popped up - for trojan.byte. Norton successfully deleted it twice - but the third time it said it failed. I followed all the instructions on the web site - disable system restore - go to safe mode - run norton anti-virus & delete the trojan. But it didn't work. I get this porn icon on my desktop now. A program called coolshader keeps ru nning & whiting out my screen - and when I tried to delete my cookies - they kept REPRODUCING! I now have up to 300 copies of many cookies! HELP!!!
  #2  
Old April 16th, 2004, 09:44 PM
snowbound snowbound is offline
Retired Moderator
 
Join Date: Feb 2003
Location: The Big Smoke
Posts: 8,727
Default Re: cookies reproducing - coolshader??

Hi lorellen

Welcome to Wilders.

I moved your post over here for better attention.

Could u please follow the instructions here,

http://www.wilderssecurity.com/showthread.php?t=15913

then after u post your HijackThis log one of the experts will give u recommendations on any Malware found.


snowbound
  #3  
Old April 16th, 2004, 09:44 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,639
Default Re: cookies reproducing - coolshader??

Hi lorellen,

Welcome to Wilder's!!!!!

First download Ad-Aware and double-click to install.
Then follow the following steps:

1.) Start Ad-Aware by double-clicking on its desktop icon.
2.) Update Ad-aware by using its Globe icon.
3.) After updating, close all IE windows, then close and restart Ad-aware.
4.) Be sure the following items are checked under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
"Unload recognized processes during scanning".
5.) Be sure the following items are checked under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
"Automatically mark all objects in result list".
"Automatically try to unregister objects prior to deletion".
"XP/2000: Allow unloading explorer to unload shell extensions prior deletion" <-- Check only if you have Windows XP or 2000.
"Let Windows remove files in use after reboot".
6.) Press "Scan Now".
7.) Check option "Use Custom scanning options".
8.) Check option "Activate In-Depth Scan".
9.) Press "Select drives\folders to scan".
10.) Select the active partition which is usually C:
11.) Press "Next" to let Ad-aware scan your drives...
12.) If it finds "bad" files and registry keys, press "Next" again.
13.) All items should be checked. if not right-click in that pane and choose "select all".
14.) Press "next".
15.) When it asks to remove all checked items, Press "OK".
16.) You may now exit out of Ad-Aware and reboot your system. Then go to the next section for SpyBot S&D.

Now download Spybot S&D and install by double-clicking on the downloaded file.
Then follow the following steps:

1.) Run Spybot S&D from desktop icon or Start menu.
2.) Press "Search for updates" button to get list of updates available.
3.) Press "Download updates" button.
4.) Close all IE windows, then close and restart Spybot S&D.
5.) Press "Check for problems" button.
6.) Have SpyBot remove all it marks in red by pressing "Fix selected problems".
7.) You may now exit out of Ad-Aware and reboot your system. Then go to the next section for CWShredder.

Please download the latest copy of CWShredder and run by double-clicking the icon of the file you just downloaded.
Click FIX and follow the instructions given.

Now reboot your system and post a HJT log.
Please download the latest copy of HJT.
Run HijackThis.exe
Press "Scan" button.
When done the "Scan" button will change to "Save Log", press that.
Save the log as a text file and copy and paste it here.

Regards,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
 

Wilders Security Forums > Browser Hijacks and Spyware Problems > adware, spyware & hijack cleaning « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:10 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums