Search blogs
Did you find a problem ? Tell us about it! Get a blog Report blog Random blog

How to remove Cool Web Search

Posted on 06/03/2006

Yesterday I got infected my mistake with CoolWebSearch. First I tried removing it with Microsoft Antispyware, Lavasoft Ad-Aware, CWShredder, Bitdefender and Norton Antivirus.
Microsoft Antispyware, CWShredder, Bitdefender and Norton Antivirus did not even recognized it.
Lavasoft Ad-Aware is the only one that recongized it, but it was unsuccesfull removing it.
CoolWebSearch has one primary file e2020cdoef0c0.dll (random name, ~ 231 KB in my case) in Windows/System32
This random named DLL is started by winlogon.exe every windows startup, so the file can't be deleted.
If you try to delete the registry keys in HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Notify/App Management and HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Notify/Welcome
it will write them back almost instantly. The same thing happens in normal mode/save mode/save mode, command prompt.
The only way to remove it is to run Lavasoft Ad-Aware to identify the file name, then simply shut down the computer by removing the back AC plug.
Then remove the hard disk and insert it into another computer as slave. Browse to Windows/System32 and delete the DLL file identified by Ad-Aware.
I also found a file named guard.tmp in Windows/System32. Search for it and if you find it, remove it.
If you have deleted the file(s), then is safe to install back the hard disk and reboot.

If you know another way to remove it, please contact me using the form below.


Your Name
Subject
Message
E-mail
These icons link to social bookmarking sites where readers can share and discover new web pages. Bookmark page
  • digg
  • del.icio.us
  • YahooMyWeb
  • Furl
  • Fark
  • Ma.gnolia
  • Reddit
  • Smarking
  • Spurl
  • NewsVine
  • blinkbits
  • Yahoo Messenger
Razvan @ 15:26
Filed under: stuff

No comments have been added to this post yet.

No trackbacks have been added to this post yet.

Leave a comment





Human test

Information for comment users
Your e-mail address is never displayed. Please consider what you're posting.