Hi there,
I think that my PC is infected with the coolwebsearch bug. I am running Windows XP, and my antivirus programme is McAfee. The error messages that I have been experiencing have all been while I am online. My internet connection runs unusually slow for me (we are on DSL), and there have been a quite a few times that I have gotten the "Unable to display the webpage" message, as well as the "Unable to connect to server" messages. I also notice that when I log in to the internet, on the upper left hand corner of the screen, right before it goes to Google (my homepage) the words About, or About Blank will flash for a second or two.
So I disconnected from the internet, ran McAfee, these are the results I got:
Detection Type: Potentially Unwanted Program
Detection Name: Adware-CoolWebSearch
Status: Detected
Items: Registry
Registry Key: HKLM\system\currentcontrolset\enum\root\LEGACY_ZESOFT
When I click the "remove" button, this is the message that I get:
Program Disabled
McAfee has attempted to disable this program, but some parts of it cannot be removed. In most cases, the program will no longer run. If you restart and rescan your computer and the same program is detected again, you can send it to the McAfee Avert Labs for analysis. Samples must be sent to spyware_research@avertlabs.com (subject line:MAS Content) in a .ZIP file. The .ZIP file must be no more than 3MB, cantain no more than 30 files and be password protected using "Infected" without quotation marks.
I restarted my computer and ran the scan again, and the same thing was detected, and when I tried to remove it, I got the same message as before. (I have not sent it in to McAfee because I frankly do not know how. I know how to create a .ZIP file, but I do not know how I would go about locating this thing, nor do I know how to tell how many files it has or the size of the file.) I ran McAfee in safe mode and got the same results as before. When I scanned with SpyBot Search and Destroy, the coolwebsearch bug did come up along with, CasaleMedia, DoubleClick, and RightMedia. After I hit the "Fix This" button, it seemed to remove everything with no problem, however subsequent virus scans came up with the coolwebsearch bug, and again I was unable to remove it. I also downloaded the trial version of ZoneAlarmPro for Spyware, and it never once came up with the coolwebsearch bug, however it did show many other problems, from hijackers, to keyloggers. I am also getting many many notifications from Zone Alarm saying that Zone Alarm blocked access from to my computer from somwhere in the internet.
I have browsed around the forums here and gathered that standard procedure towards fixing this was to run the TrendMicro CWShredder, the Malwarebytes'. I have done both and will post both logs. I also would like to note that I ran a programme called RegFixPro, to fix registry problems. I don't remember exactly how many errors it found, but I do know that it was over 1000.
I am sorry about the length of this post, I am new at this and have tried to be as specific as possible. Thanks in advance for your help in this matter.
The MalWareBytes' log:
Malwarebytes' Anti-Malware 1.31
Database version: 1467
Windows 5.1.2600 Service Pack 3
12/7/2008 4:10:22 AM
mbam-log-2008-12-07 (04-10-22).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 273030
Time elapsed: 5 hour(s), 8 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I think that my PC is infected with the coolwebsearch bug. I am running Windows XP, and my antivirus programme is McAfee. The error messages that I have been experiencing have all been while I am online. My internet connection runs unusually slow for me (we are on DSL), and there have been a quite a few times that I have gotten the "Unable to display the webpage" message, as well as the "Unable to connect to server" messages. I also notice that when I log in to the internet, on the upper left hand corner of the screen, right before it goes to Google (my homepage) the words About, or About Blank will flash for a second or two.
So I disconnected from the internet, ran McAfee, these are the results I got:
Detection Type: Potentially Unwanted Program
Detection Name: Adware-CoolWebSearch
Status: Detected
Items: Registry
Registry Key: HKLM\system\currentcontrolset\enum\root\LEGACY_ZESOFT
When I click the "remove" button, this is the message that I get:
Program Disabled
McAfee has attempted to disable this program, but some parts of it cannot be removed. In most cases, the program will no longer run. If you restart and rescan your computer and the same program is detected again, you can send it to the McAfee Avert Labs for analysis. Samples must be sent to spyware_research@avertlabs.com (subject line:MAS Content) in a .ZIP file. The .ZIP file must be no more than 3MB, cantain no more than 30 files and be password protected using "Infected" without quotation marks.
I restarted my computer and ran the scan again, and the same thing was detected, and when I tried to remove it, I got the same message as before. (I have not sent it in to McAfee because I frankly do not know how. I know how to create a .ZIP file, but I do not know how I would go about locating this thing, nor do I know how to tell how many files it has or the size of the file.) I ran McAfee in safe mode and got the same results as before. When I scanned with SpyBot Search and Destroy, the coolwebsearch bug did come up along with, CasaleMedia, DoubleClick, and RightMedia. After I hit the "Fix This" button, it seemed to remove everything with no problem, however subsequent virus scans came up with the coolwebsearch bug, and again I was unable to remove it. I also downloaded the trial version of ZoneAlarmPro for Spyware, and it never once came up with the coolwebsearch bug, however it did show many other problems, from hijackers, to keyloggers. I am also getting many many notifications from Zone Alarm saying that Zone Alarm blocked access from to my computer from somwhere in the internet.
I have browsed around the forums here and gathered that standard procedure towards fixing this was to run the TrendMicro CWShredder, the Malwarebytes'. I have done both and will post both logs. I also would like to note that I ran a programme called RegFixPro, to fix registry problems. I don't remember exactly how many errors it found, but I do know that it was over 1000.
I am sorry about the length of this post, I am new at this and have tried to be as specific as possible. Thanks in advance for your help in this matter.
The MalWareBytes' log:
Malwarebytes' Anti-Malware 1.31
Database version: 1467
Windows 5.1.2600 Service Pack 3
12/7/2008 4:10:22 AM
mbam-log-2008-12-07 (04-10-22).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 273030
Time elapsed: 5 hour(s), 8 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top








