Monday, May 10, 2004

errorwear: embrace your computer problems
1001 Fonts .com | Download Free Fonts
CoolWebSearch info - Merijn.org
Merijn.org
eBay item 3290938839 (Ends May-11-04 19:32:07 PDT) - Rocky and Bullwinkle Pinball Sling Shot Plastic Set
spyware
Apparently my dad had a new variant of Coolwebsearch. It was a nasty SOB. Nothing would remove it.
All of the spyware apps had to be renamed to foo.exe (via another computer over the net) before they would even show up in Explorer.
CWShredder detected that it was being shut down by CWS and changed its title bar to garbage characters so it could run. It said it removed CWS, but it was wrong.
.... ....
AdAware would clean it off, but it would add itself right back in. Hijack this also helped but it still kept coming back.

If it isn't in the startup
It isn't a service that installed itself
Isn't an aberrent process running that can be killed via Task Manager
Isn't in the run section of the registry (HKLM\Software\Microsoft\Windows\Current Version\Run)
It is because these homepage hijack usually are in the installed programs section of Internet Explorer, which is why virus scanners and normal spyware cannot locate the root process, because it's actually running under IEexplore.exe's process!!!

Steps I have found that clean machines infected this way.
Go to IE's Internet properties (Internet Properties\General\Temporary Internet Files\Settings\View Objects (which is usually c:\%windir%\Downloaded Program Files).
Delete all objects (you can always reload flash and the other applications in there)
Then choose Internet Properties\Programs\Reset Web Settings.
Run AdAware/Hijack this one final time to clear out any last minute payload reinstalls.
You should now be able to browse normally without the page hijacking.

Thursday, May 06, 2004