mIRC Home    About    Download    Register    News    Help

Print Thread
#100339 12/10/04 01:44 AM
R
revolver
revolver
R
Gday all,

A friend contacted me yesterday explaining that his Internet Explorer had been hijacked after one of his flatmates visited a website and sadly clicked YES when prompted by a popup window. His computer is now over-run with "search portal hijack" and "coolwebsearch".

What does this do?

Basically it hijacks your internet explorer so that the cool web search portal becomes your homepage. You can change your homepage, and coolwebsearch will change it back.

Also it launches Internet Explorer on start-up to run iexplore.exe in the background regardless of wether you have an internet explorer window open or not. You can kill iexplore.exe through your task manager and it will restart itself so that as soon as you kill the process, another iexplore.exe appears in the task manager processes window, scant seconds later.

Spyware removal software will detect and remove both coolwebsearch and search portal hijack, but if you run another scan straight after removing them, one or both will have returned immediately.

You can remove all traces of Internet Explorer in the registry, and coolwebsearch will reinstate it scant seconds after you remove it.

Has anyone else encountered this hijacking software? If so how did you remove it SAFELY from the system?

I am aware of a program called CWSshredder which supposedly removes it, but I'm interested in other opinions before implementing that option...

cheers smile


Joined: Jun 2003
Posts: 4,670
M
Hoopy frood
Offline
Hoopy frood
M
Joined: Jun 2003
Posts: 4,670
I do believe I was infected with that, I used CWShredder, if memory serves me correctly it didn't fully sort the issue. It is a safe program though (from my experience). You'll also find a number of spyware programs listed in this thread (including CWShredder), they might help.

A little more technical, but I really like Bazooka . It scans quickly and, for me, has detected 2-3 spyware that ad-aware/spybot have never detected. Instead of removing it for you though, you need to follow online instructions to get rid of it. But it has helped me a couple of times with extremely annoying spyware.

Regards,


Link Copied to Clipboard