IE Hijackers are now unbeatable??

S

Speck

Reading through the posts in this newsgroup it would seem many people have
the same problem as me. Internet Explorer hijackers seem to have upped the
anti a bit as the usual methods of removing them do not seem to work. Have
they become unremoveable now?
My system has been hijacked by the COOL WEB SEARCH virus. I have run AVG
anti virus, Spy Sweeper, Spybot search & destroy, Bazooker, CWshredder and
Hijack this. None of these programs have been successful in removing the
problem.
So, what is the answer? Or have they finally got us beat??

Speck
 
J

Jan Il

Hi Speck :)

This may be a newer variant of about: blank. Methods that previously
removed the previous variant may not have any effect on it. Try the
following and follow and instructions carefully to clean your system fully.
This variant replicates itself, thus, you must fully clean it from your
system. This coolwebsearch infection uses a hidden dll to reinfect, thus it
replicates itself over and over if not removed properly.

As you have already downloaded SpyBot, AdAware and CWShredder, run them
again from Safe Mode with Hidden Files Enabled to be sure you are able to
get full file detection. Be sure you have AdAware configured for full scan
capability:

HOW TO: Reconfigure Ad-aware for a Full Scan
http://forum.aumha.org/viewtopic.php?t=5877

<<<<BE SURE TO FOLLOW ALL INSTRUCTIONS CAREFULLY>>>>

CAUTION!!!!!
Before you try to remove spyware using any of the programs below, download a
copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html (if your OS is Win2k or
XP) The process of removing certain malware may kill your internet
connection. If this should occur, this program, LSPFIX, will enable you to
regain your connection.

Also, get a copy of WINSOCKFIX available at:
http://www.spychecker.com/program/winsockxpfix.html


IMPORTANT!!
RUN ALL PROGRAMS OFF LINE IN SAFE MODE AND SHOW HIDDEN
FILES. THEN REBOOT AND RUN THEM AGAIN TO BE SURE ALL FILES
ARE ACCESSED, DELETING ALL ITEMS DISPLAYED IN RED IN SPYBOT

HOW TO Restart in Safe Mode
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

HOW TO Enable Hidden Files
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339

The about Buster is a very powerful tool, and has been able to get rid of
most of these replicating variants. Run from Safe Mode:
About Buster
http://www.majorgeeks.com/download4289.html

Get HiJackThis:

This is a very essential part of the cleaning process.

Unzip the Download file in a NEW FOLDER that you can create before you start
the download.
DO NOT install in your Desktop folder.
DO NOT use any of the TEMP folders that are presently in your computer.
Double-click "HijackThis.exe" and Press "Scan".

Go to:
http://www.majorgeeks.com/download3155.html
and download HiJackThis to the new folder. Unzip to a folder other than your
Desktop or the Temp folder, doubleclick HiJackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log"
button. Press that, save the log some place you remember where it is.
Most of what it lists will be harmless or even required, so DO NOT fix
anything yet.

Open the copy of your log in NotePad and make a copy. Then you can go to one
of the following to post your log:

<<PLEASE DO NOT POST YOUR LOG FILE TO THIS NEWSGROUP>>

Spyware and Hijackware Removal Support, here:
http://216.180.233.162/~swicom/forums/

or Net-Integration here:
http://www.net-integration.net/cgi-...86d536d57b5f65b6e40c55365e;act=ST;f=27;t=6949

or Tom Coyote here:
http://forums.tomcoyote.org/index.php?act=idx

You will need to register to open a new thread to post you log. It is free,
and no one will Spam you, it is one of many that provides this service. Once
registered, go to the HiJackThis section on the forum list and click to
open. Then start a new post and post your log. The experts there will
analyze the log and report back the results. Please allow at least a few
hours or a days time for a response, depending on when you post the log

Remember, you must return to the HJT site to get your answer. It is a good
idea to click the "Notify" box so that you will get an electronic
notification by e-mail to let you know when a response has been posted.
But, you must still return to the site of your answer

Finally, go to Windows Update and ensure that ALL Critical updates are
installed.

HJT Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42

If these steps do not resolve your problem, please post back to this thread
with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.

How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
G

Guest

Speck said:
Reading through the posts in this newsgroup it would seem many people have
the same problem as me. Internet Explorer hijackers seem to have upped the
anti a bit as the usual methods of removing them do not seem to work. Have
they become unremoveable now?
My system has been hijacked by the COOL WEB SEARCH virus. I have run AVG
anti virus, Spy Sweeper, Spybot search & destroy, Bazooker, CWshredder and
Hijack this. None of these programs have been successful in removing the
problem.
So, what is the answer? Or have they finally got us beat??

Speck

Aboutbuster scans for that second "hidden" .dll talked about in the link Don
provided for you
About Buster- http://www.spychecker.com/program/aboutbuster.html

Another good link
SpywareBlaster - http://www.javacoolsoftware.com/spywareblaster.html


If your using XP change these settings

To help stop unauthorized downloads via your activex controls change your
default settings.
These settings are good for XP. The wording should be close for other systems
as well.
Go to control panel and open "internet options.
Click on the security tab then custom level.
make sure these settings are as follows.

Download signed active x controls>set to prompt
Download unsigned active x controls>set to disable
Initialize and script active x controls not marked as safe>set to disable
Run active x controls and pluggins>set to enable
Script active x controls marked safe for scripting>set to enable
Java permissions>set to high
Launching programs and files in a IFRAME" > Prompt
Installation of Desktop items"> Prompt
Navigate sub-frames across different domains>prompt

This will provide a balance between protection and funtion
I have my system setup like this and never get any malware......Yet
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top