Zhann opened this issue on Jun 13, 2004 ยท 54 posts
pakled posted Sun, 13 June 2004 at 7:52 AM
I sympathize..I got the 'cool web search' malware (spyware with an attitude), and here's what I had to do just to get rid of it (and I'm still not 100% sure I did..:|
First, what it does is put a .dll in your startup, so that no matter what ad-aware, spysweep, cwshredder, hijack this!, etc., program runs, it only deletes the results of the infection. Once it's run, it sticks 'about:blank' as your home page, and blows up IE if you try to use your 'back' arrow). To actually get rid of it, I did a Google search on 'about:blank', and found a Computer Cops site, which was pretty helpful.
I had to go through System32, and look on dates created for recent dll's. If you know (roughly) the date of infection, look at the properties of the dll's created on or after those dates. Your key will be if there's no tab between 'general' and 'security'. Usually the name will also look like a random collection of letters. You mark down these suspect dll's, then reboot the system in Command Mode (safe mode, I'm running Win 2k). Then you go to c:winntsystem32 (or wherever your system32 directory is), and delete the files. Rerun the Ad-aware, Spy Sweeper, CWshredder, etc., and for the more adventurous, go through regedit and delete any entry with 'about:blank' in it..but don't mess with the registry unless you're familiar with it).
I don't know if you're having problems like this, but I was just showing the deviousness and maliciousness of what's out there today. You can go to Computer Cop, or the Ad Aware forum, or the Hijack this! site, and they can look at what's going on. And explain it better than me..;)
good luck, Zhann..
I wish I'd said that.. The Staircase Wit
anahl nathrak uth vas betude doth yel dyenvey..;)