Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 15th, 2005, 09:44 AM
jon123 jon123 is offline
Regular Poster
 
Join Date: Mar 2005
Posts: 76
Exclamation coolwwwsearch prob, nothing finds it?

for some reason I can't start a thread in the addware spyware and hijack cleaning forum so I've come here

"One other thing, it seems I might have a problem with coolwwwsearch as occasionally ZA is catching a connection attempt (routed to 127~, loopback right?), any recommendations on dealing with that? I ran spysweeper 3.5 without success. Currently I'm using a cloned backup that hasn't had spysweeper installed."


update to my coolwwsearch prob.

ran f-prot for dos with updates and full options (was not slow btw)-nadda

ran Pepi's smartkiller, older version though for cool~ v1 and v2-nadda
ran cwshredder-nadda

installed avast free and ran-nadda

have had one more instance of ZA catching outbound destination coolwwsearch

will of course try latest smartkiller, is there any diff. to prog?
what else might I try?
-I left Tea Timer running S&Dv1.3 (does the 1.4dl now include latest engine and det. files?)
I also wonder if MS sec updates for 98 might be causing issue for any of these progs.

Last edited by jon123 : August 15th, 2005 at 09:56 AM. Reason: spelling
  #2  
Old August 15th, 2005, 02:16 PM
ravin's Avatar
ravin ravin is offline
Frequent Poster
 
Join Date: May 2003
Location: South Carolina
Posts: 241
Default Re: coolwwwsearch prob, nothing finds it?

try an online scan at trendmicro.com they have the coolweb detection in the scan for spyware. hope that catches it.
  #3  
Old August 15th, 2005, 03:20 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: coolwwwsearch prob, nothing finds it?

If nothing works :

Download HijackThis v1.99.1 from this link :
http://www.spywareinfoforum.com/~merijn/downloads.html

Install it in a separate folder, run it and copy/paste your HijackThis Log + a description of the problem and what you already tried to solve it at this Malware forum :
http://www.spywareinfoforum.com/
Subforum "Malware Removal" and wait for a qualified helper.

PS: Wilders Security Forum doesn't solve HijackThis Logs anymore according my readings.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #4  
Old August 15th, 2005, 06:16 PM
brjoon1021 brjoon1021 is offline
Regular Poster
 
Join Date: Aug 2005
Posts: 143
Default Re: coolwwwsearch prob, nothing finds it?

you need "aboutbuster.exe" google for it. It is free. There is also something called CWShredder at the free Trend online virus scan site.

It (aboutbuster) kicked the hell out of coolwebsearch for me. I also risked my neck and removed everything that I did not recognize with Hijackthis. It worked.

I was almost going crazy because of this evil program. Coolwebsearch is horrible. I hope the author gets a nasty case of something.
  #5  
Old August 15th, 2005, 06:58 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

I myself found this little spyware or whatever it is on my pc today - I just tried scanning with Panda's online scanner because my pc was all weird and slow. It found it, but of course couldnt remove it...

Ewido didn't find anything
Ad-Aware didn't find anything
Spybot didn't find anything

I'll try aboutbuster (http://www.bleepingcomputer.com/files/aboutbuster.php)
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #6  
Old August 15th, 2005, 07:08 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: coolwwwsearch prob, nothing finds it?

Yep aboutbuster.exe removes also CWS, but CWS has SO MANY variations.
I hope aboutbuster.exe is able to remove that specific CWS-variant.
Download aboutbuster from the original homepage :
http://www.malwarebytes.biz/index.php?page=downloads
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #7  
Old August 15th, 2005, 07:22 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

Well this sucks... Panda still finds it, can't remove it.
Aboutbuster didn't find anything (I updated prior to scan)
Attached Images
 
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #8  
Old August 15th, 2005, 07:25 PM
snowbound snowbound is offline
Retired Moderator
 
Join Date: Feb 2003
Location: The Big Smoke
Posts: 8,727
Default Re: coolwwwsearch prob, nothing finds it?

Post a HJT log over here,

http://gladiator-antivirus.com/forum...?showforum=170

and the experts there will help u get rid of it.


snowbound
  #9  
Old August 15th, 2005, 07:26 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

And CWShredder didn't find anything either ..
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #10  
Old August 15th, 2005, 07:29 PM
StevieO
 
Posts: n/a
Default Re: coolwwwsearch prob, nothing finds it?

Hi Brian,

If you have CWS you may like to have a look over on here, and see if it helps.

Detection for new CWS variant yet?
http://www.dslreports.com/forum/remark,14093526


StevieO
  #11  
Old August 15th, 2005, 07:43 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

Bah wish there was a boclean trial Looks like it can beat this nasty one.
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #12  
Old August 15th, 2005, 09:34 PM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

Man this is weird...
Panda ActiveScan detects it, but none of their apps does... 05 and 06 beta detects nothing.
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #13  
Old August 16th, 2005, 10:09 AM
jon123 jon123 is offline
Regular Poster
 
Join Date: Mar 2005
Posts: 76
Default Re: coolwwwsearch prob, nothing finds it?

Thanks for responses guys, I see that Wilder's has closed thei hijackthis section too, so I've dl'd the latest hijack this as per castlecops.com instructions. I read around here somewhere a recommendation for this site.
I'll be trying the other recommendations too.
And there is always fdisk, give me an opportunity to partition the drive anyway. Sad part is this infection got into my machine somewhere along the way with this new install, clone, install next, rinse repeat. Not sure how or when, maybe I should be checking md5s. Anyone know of a prog to generat them? hmm, will change sig font.....
__________________
Last seen running for the hills babbling something about
"Luddites! Where have you gone? Save me!....."

"Most web surfing begins on a search engine. It’s also where the threat of data theft begins."
- that's particularily funny atm
  #14  
Old August 16th, 2005, 10:17 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

Looks like this one can save the current md5 and test them later against the same files, and report if they have changed.

http://www.brandonstaggs.com/filecheckmd5.html
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #15  
Old August 16th, 2005, 10:25 AM
dog
 
Posts: n/a
Default Re: coolwwwsearch prob, nothing finds it?

Quote:
Originally Posted by jon123
Not sure how or when, maybe I should be checking md5s. Anyone know of a prog to generat them? hmm, will change sig font.....
Karen has a nice one -> http://www.karenware.com/powertools/pthasher.asp
  #16  
Old August 16th, 2005, 10:28 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: coolwwwsearch prob, nothing finds it?

Quote:
Originally Posted by dog
Well that looks more advanced indeed Hmm.. Must try it
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #17  
Old August 16th, 2005, 12:48 PM
jon123 jon123 is offline
Regular Poster
 
Join Date: Mar 2005
Posts: 76
Default Re: coolwwwsearch prob, nothing finds it?

well, well, well, i just got an email purporting to be from net-integration instrucing me to dl from antivirusprotection.pisem.net, ibforums
Anybody know if this site is legit?
Avast detects the dl as a trojan

net-integration hacked! beware email purporting to be from net-integration!

http://www.wilderssecurity.com/showthread.php?p=533597
__________________
Last seen running for the hills babbling something about
"Luddites! Where have you gone? Save me!....."

"Most web surfing begins on a search engine. It’s also where the threat of data theft begins."
- that's particularily funny atm

Last edited by jon123 : August 16th, 2005 at 01:39 PM. Reason: MALWARE!
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:12 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums