Wilders Security Forums  

Go Back   Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 28th, 2005, 05:30 PM
Michael_aust
 
Posts: n/a
Question Coolwebsearch found

I run spyware blaster and spyware guard and there both all up to date and have all protection enabled. But just then i ran a scan with aol spyware protection software and it found coolwebsearch. I was never notified that it was trying to be installed by spyware guard. How coem spyware blaster didnt stop it. The only software I have downloaded recently is Ewido anti Trogen software. I read all its liscence and it didnt say anything about additional software being installed in it. So any ideas how it got through? I thouth spyware guard was supposed to alert you of these kind of things.

I blocked and deleted it completely with aol spyware and it says its gone when i restarted my machine and ran the scan again. I also ran adaware personal se and that found nothing, neither did ewido i fact i ran that before aol and that didnt pick it up. Do you think it will have been gotten rid of from my machine or shouldi download spybot just to be sure?
  #2  
Old January 28th, 2005, 05:47 PM
~*Nat*~'s Avatar
~*Nat*~ ~*Nat*~ is offline
Incredibly Massive Poster
 
Join Date: Jul 2004
Location: Germany/Ohio-USA ~ between two worlds
Posts: 8,129
Default Re: Coolwebsearch found

Quote:
Originally Posted by Michael_aust
I run spyware blaster and spyware guard and there both all up to date and have all protection enabled. But just then i ran a scan with aol spyware protection software and it found coolwebsearch. I was never notified that it was trying to be installed by spyware guard. How coem spyware blaster didnt stop it. The only software I have downloaded recently is Ewido anti Trogen software. I read all its liscence and it didnt say anything about additional software being installed in it. So any ideas how it got through? I thouth spyware guard was supposed to alert you of these kind of things.

I blocked and deleted it completely with aol spyware and it says its gone when i restarted my machine and ran the scan again. I also ran adaware personal se and that found nothing, neither did ewido i fact i ran that before aol and that didnt pick it up. Do you think it will have been gotten rid of from my machine or shouldi download spybot just to be sure?


Hi Michael,

The Coolwebsearch - pest is a very sneaky and dangerous thing on the net.
With all those apps..its still easy to go through.

You'd want to download the CWShredder if you haven't done so yet.
  #3  
Old January 28th, 2005, 05:52 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Coolwebsearch found

Quote:
Originally Posted by Michael_aust
But just then i ran a scan with aol spyware protection software and it found coolwebsearch.
Hey Michael,

After the AOL scan....do you recall if the CoolWebSearch item\items it found were located in the below registry key or can you post a screen shot of what it found ?

This reg key--->HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains


FAQ: Screen Shots and Image Posting
  #4  
Old January 28th, 2005, 05:59 PM
~*Nat*~'s Avatar
~*Nat*~ ~*Nat*~ is offline
Incredibly Massive Poster
 
Join Date: Jul 2004
Location: Germany/Ohio-USA ~ between two worlds
Posts: 8,129
Default Re: Coolwebsearch found

Here, in case you are indeed infected by CWS......



http://www.softpedia.com/get/Interne...Shredder.shtml



Good Luck !
  #5  
Old January 28th, 2005, 06:09 PM
Michael_aust
 
Posts: n/a
Default Re: Coolwebsearch found

Im not really sure what you mean by what you sai Bubba but here is the log for when it found it. I cant seem to find the link to add images like you FAQ post said. I have uploaded it to a webpage. Please post and tell me when you have viewed it so I can take it down

http://www.geocities.com/toafaultroc...searchinfo.JPG

i dont thin k it gave me any windows registry info just the directories it was stored at. Hoope this is soem help.

Do you think it will have actualy gone from my machine or could tere still be bits lurking around. I ditn want to have to go into the registry because i dotn have a clue what im doing in it.
  #6  
Old January 28th, 2005, 06:23 PM
Michael_aust
 
Posts: n/a
Default Re: Coolwebsearch found

just downloaded and ran the cws shredder from download.com i presume its the same as the other person posted. It found absolutly nothing. So presume the system is clear i ran it twice and it gave nothing so.
  #7  
Old January 28th, 2005, 07:09 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Coolwebsearch found

Quote:
Please post and tell me when you have viewed it so I can take it down
Hey Michael....You can take your picture down.

The file name nsreg.dat is a valid file name for Windows XP....which is what your operating system is....correct ?

I also do not trust the AOL scan program and it's record for False positives. If I'm reading you correctly....you scanned with Adaware before you scanned with AOL and Adaware did not find anything....correct ?

If that's the case....and if you have the latest version of Adaware with up to date signature files....I'm leaning toward a false positive with AOL spyware cleaner.
Attached Images
 

Last edited by Bubba : January 28th, 2005 at 07:22 PM.
  #8  
Old January 29th, 2005, 07:14 AM
Michael_aust
 
Posts: n/a
Default Re: Coolwebsearch found

I scanned with ewido first, that found nothing. So i ran my usual aol scan expecting to find nothing it came up with that one file so cleaned it up. I ran adaware afterwards and it found nothing. I also ran that cwshredder and that said there was nothing. o your probobly right it was a false possitive. Yep I do run windows XP
  #9  
Old January 29th, 2005, 08:44 AM
ghodgson ghodgson is offline
Frequent Poster
 
Join Date: Dec 2003
Location: UK
Posts: 337
Default Re: Coolwebsearch found

Dear Michael, I would agree with Bubba that it sounds like a false positive. Incidentally, I 'fixed' a friend of mines' PC last week which was infected with Coolweb 'about blank' and COOLWEB shredder did not pick that up either, which was surprising. BUT Adaware SE did, however, I ended up having to manually edit the registry to get rid completly.
Gordon
__________________
Gordon
 

Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:19 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums