Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93121 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

New "cool" Pest Discovered ...


  • Please log in to reply
18 replies to this topic

#1 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 11 November 2003 - 06:10 PM

Now this one is really burning me off, Tom.

I posted your thanks to the CWS tool, but this little bugger has me stumped ...

Please help.

I have the pest in my computer, and none of the previously used tools and Trojan Hunter's catch this bad, bad wormy.

Check it out ....

http://cool-search.net/

It has several variants, too ...


http://cool-homepage.co

Problem is I can't locate the "infestor" ... Can't find this bug where it has implanted itself into my XP.

I have temporarily used SBS&D to stop my page from changing, but the thought of having this in my machine bugs the snot out of me.

Please help, Tom.

KnightWaterTiger

P.S. Hope you don't mind, but I am linking your site to our Webpages. :thumbup:

Edited by mjc, 19 November 2003 - 06:46 PM.

    Advertisements

Register to Remove


#2 Zero

Zero

    Not really Less Than One ;-)

  • Authentic Member
  • PipPipPip
  • 268 posts
  • Interests:Long walks on the beach.

Posted 11 November 2003 - 07:33 PM

I take you are talking about CWShredder. What version are you using of it? I believe it was updated to include those URLS.
Posted Image

#3 Coyote

Coyote

    Emeritus-Expert

  • Authentic Member
  • PipPipPipPip
  • 979 posts

Posted 11 November 2003 - 07:45 PM

CWShredder
http://www.spywarein.../cwshredder.zip
Go forth and conquer your goals with the renewed spirit of Coyote and do not let small setbacks stop you from Your Dreams

Microsoft MVP 2006-2007


May your day be blessed by those you love and those you love be blessed by HIM ;-)

#4 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 11 November 2003 - 09:20 PM

Yea, I got it ... the updated one, Tom.

No workie, chief ...

The last time I had the "other" COOL bug you helped me with, the Trojan Hunter identified the base trojan and I simply deleted it.

This variant is not recognized as a trojan. Thank God for SBS&D, or my webpages would still be opening with that silly thing.

Help!!

P.S.

I have run Norton 2003 Business Professional, AVG 6.0, Trojan Hunter and all your online scanners .. nothing tags this bugger.

KnightWaterTiger

Founder,

Brotherhood of Trans-Atlantic Knights

http://www.botaknights.com

Edited by mjc, 19 November 2003 - 06:47 PM.


#5 Galadriel

Galadriel

    CEO - Chief Elvish Officer

  • Visiting Fellow
  • PipPipPipPip
  • 528 posts

Posted 11 November 2003 - 09:29 PM

Get Hijack This. Unzip using your favorite unzipping utility (http://www.winzip.com/)
Double click on the HijackThis.exe file. Press the "Scan" button, it will then change to "Save Log". Copy and paste its entire contents here. DO NOT fix anything yet, as most of what is listed is harmless or even needed.

http://tomcoyote.org/hjt/
I amar prestar aen. Han mathon ne nen. Han mathon ne chae. A han noston ne 'wilith. - Galadriel

'The world is changed; I can feel it in the water, I can feel it in the earth, I can smell it in the air.'

#6 Zero

Zero

    Not really Less Than One ;-)

  • Authentic Member
  • PipPipPip
  • 268 posts
  • Interests:Long walks on the beach.

Posted 11 November 2003 - 10:09 PM

Actually post the log here

http://tomcoyote.org...st&CODE=00&f=27
Posted Image

#7 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 12 November 2003 - 02:20 AM

Done ...

#8 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 12 November 2003 - 04:47 PM

Ahhhhhhhhh ..... It's back today.

New http ... OK< I'm throwing this computer out the window.

And, I had my SBS&D locked down!!!!!!

http://66.250.57.28/

WTF?

KnightWaterTiger

#9 Unzy

Unzy

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 12 November 2003 - 04:58 PM

Hi there, Can you open up the registry : start -> run -> type regedit and press enter Once inside press ctrl+f In the searchbox type cool-search.net and press 'search' Press F3 to find next Keep us posted if you found entries containing that name in the registry Thanks! Cheers,

#10 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 12 November 2003 - 07:42 PM

HOMEOldSP -- deleted .... http://66.250.57.28/

cool-homepage -- delted

Deleted from Regedit ..............

.......................................................................................................................

The problem with this bug, is that it morphs .... changes.

I just ran Trendo Micro Housecall (online scan) .... caught 3 Java trojans, and I have now found the loaders that reboot this bug into the system

JAVA BYTVERIFY.A
JAVA CLOADER.E
JAVA BYTVERIFY.A

So, now you have it. I sent the log file into your shop yesterday ...

BTW, Norton's best missed this, AVG missed this ... CWS (updated) missed it, it turned off the SBD&D block on the homepage and allowed it to reinfest -- not on reboot, but just on reloading the IE page.

OK, calming down now... breathhhheeee

Now you know what I know.

Cheers.

KnightWaterTiger

Founder and council member,

Brotherhood of Trans-Atlantic Knights

BOTAKnights

    Advertisements

Register to Remove


#11 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 13 November 2003 - 04:30 PM

IT'S BACK!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

WITHOUT REBOOT!!!!!!!!!!!!!!!!!!!!

http://66.250.57.28/

I hate this ....

CWS no workie on it ...

Nothing kills it.

HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!

WaterTiger

#12 YoKenny

YoKenny

    Authentic Member

  • Authentic Member
  • PipPip
  • 97 posts

Posted 14 November 2003 - 08:21 PM

I put 66.250.57.26 - 66.250.57.28 in my Kerio firewall block rules.

You may want to use IE-SPYAD and update regularly:
http://www.staff.uiu...rce.htm#IESPYAD
I rcommend installing IE-SPYAD and SpywareBlaster and keeping them up to date weekly.
SpyBot Search and Destroy

WinXP Home user
Posted Image member

#13 KnightWaterTiger

KnightWaterTiger

    New Member

  • New Member
  • Pip
  • 11 posts

Posted 16 November 2003 - 10:36 AM

Thanks Kenny .. that worked. WaterTiger

#14 Guest_Stan_*

Guest_Stan_*
  • Guests

Posted 08 December 2003 - 05:24 AM

I don't have the kinda $$ to afford any of the norton anti-evil softwares so I guess I'd have to settle for Ad-aware which happily located and removed the problem for me. Of course it means I have to stop visiting the very site that's causing me grief, I happen to know one and I'm gonna email the webmaster to see if he could help.

#15 Coyote

Coyote

    Emeritus-Expert

  • Authentic Member
  • PipPipPipPip
  • 979 posts

Posted 08 December 2003 - 06:13 AM

I don't have the kinda $$ to afford any of the norton anti-evil softwares so I guess I'd have to settle for Ad-aware which happily located and removed the problem for me. Of course it means I have to stop visiting the very site that's causing me grief, I happen to know one and I'm gonna email the webmaster to see if he could help.

From http://TomCoyote.org under the Heading "My Tips for safer computing":
These are the steps that I use to keep safe from a lot of problems:
(Along with SpywareBlaster and SpywareGuard and SpyBotSD and AdAware)
One step would be to block the adservers, If you use IE then go to http://www.staff.uiuc.edu/~ehowes/ And read about how to install IESpyads.

Another suggestion would be to turn off scripting in IE in the Internet Zone since most popups occur from scripts. Read more about controlling the zones here

==================================

Those are all free programs (the links to those are on the link above)

as well read the following link:
http://www3.ca.com/P...e.asp?CID=52733
CA To Offer Free Antivirus And Firewall Software To Windows Users Worldwide
This offer gives you a free AV and Firewall of high quality to protect your system, I use both here, they work very well.
Go forth and conquer your goals with the renewed spirit of Coyote and do not let small setbacks stop you from Your Dreams

Microsoft MVP 2006-2007


May your day be blessed by those you love and those you love be blessed by HIM ;-)

Related Topics



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users