Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

coolweb related issue

Status
Not open for further replies.

ADoozer

Programmer
Dec 15, 2002
3,487
AU
apologies if this is a repeat post (search is down)

a friend has enquired about a new possible coolwebsearch trojan?!?

i suggested the usual CWShredder, spybot, adaware etc but he says they didnt work...

few quotes:
"it keeps regenerating itself"
"it changes it's name after every regeneration"
"first, odbc.ini"
"shows up in the process window)"
"wont let u end process"
"i deleted that file"
"then it became soap bubbles.bmp"
"found a hidden DLL that contained some hijack code"
"a program keeps respawning itself after I delete it (in system32)"
"found it in services.msc once"
"deleted it, then couldnt find it again"

any idea what? (apologise if its vague, im quoting an msn convo)

If somethings hard to do, its not worth doing - Homer Simpson
adoozer.servebeer.com
 
I'm thinking it was around June the hidden dll problems started showing up. It's only in the last few weeks better fixes have been emerging.

I have not tried to follow this through carefully, but I think this is a complete fix thread

And this program is now the one recommended to get the service names.
Getservice.zip




-------------------------------------
It's 10 O'Clock ( somewhere! ).
Are your registry and data backed up?
 
still not heard back from the guy.. so no idea if this cured the problems... thanks all the same

If somethings hard to do, its not worth doing - Homer Simpson
adoozer.servebeer.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top