Coolweb Internet Explorer hijack again!

  Cybermaxx 17:53 28 Dec 2004
Locked

I've ran updated Adaware SE, Spybot, Coolweb Shredder (which finds nothing) and Panda Activescan Antivirus, but it's still taking over.

I've also tried MSCONFIG, diasable all Startup, but no effect there either.

Any way to stop this damned thing?

  wotbus@ 18:06 28 Dec 2004

go here and download the 30day free trial of SpySweeper click here . Good luck.

  holly polly 19:06 28 Dec 2004

click here

download and run this then follow pancakes instructions here create a restore point first
click here
regards-hol pol...

  Cybermaxx 20:21 28 Dec 2004

Thanks for the help. Spy Sweeper seemed to get rid of it, but it came back again. I've now switched from IE to Firefox. I've been told that this is less open to spyware. Whether that's true or not I dod not know!

  tornado3 13:34 05 Jan 2005

was hijacked today by cool www search.yexe. tried spybot found it deleted it but still there. tried hijack this but i cant see it in the results. wot will it come under? the name of it or something else? cw shredder keeps shutting down when i run it. any ideas?

  holly polly 15:18 05 Jan 2005

if you follow my instructions and the link i posted you to pancakes post follow these instructions to the letter and the damm thing should go-hol pol...





Hi
Make sure you have already run Adaware, Spybot S & D(check for updates) as these will do a preliminary clean first.Some files below may not be present after running the above programs.

Then....
Turn off your System Restore SEE HERE Reinstate it when your log is cleaned and then create a new restore point.Close your browser window and run hjt in safe mode... and have "Hijack This" fix all the following items by placing a check in the appropriate boxes and selecting "fix checked". Files highlighted in BLACK in the log will need to be removed from your hard drive. Make sure to have your system set to show hidden files and folders.. ..Please reboot and post a new log when finished...

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winxie32.exe
O4 - Startup: WindowsUpdate06167[1].exe
C:\WINDOWS\System32\pbiokr.exe

  holly polly 15:20 05 Jan 2005

ps read pancake instructions and follow to the letter -hol pol...

  holly polly 15:29 05 Jan 2005

run hijack this ,find the files listed in hijack this that coincide with my and pancakes listing ,place a checkmark against to have hijack this fix it finally delete the files-winxie32.exe and pbiokr.exe- and all should be well

This thread is now locked and can not be replied to.

Elsewhere on IDG sites

Alienware 17 R4 2017 review

These brilliant Lego posters show just what children's imaginations are capable of

Mac power user tips and hidden tricks

Comment réinitialiser votre PC, ordinateur portable ou tablette Windows ?