Minichan

Topic: Cool Web Search in msconfig

Anonymous A started this discussion 11 years ago #45,427

I somehow contracted CoolWebSearch in my msconfig file. CWShredder keeps finding it and removing it, but the next time I reboot, it is there again. Any ideas? Thanks!

hater !JGlOo5d1iU joined in and replied with this 11 years ago, 35 seconds later[^] [v] #599,449

use a condom

iHate !R3jQvKbkxw joined in and replied with this 11 years ago, 1 minute later, 1 minute after the original post[^] [v] #599,451

Upgrading CWS DATABASE HOPPER now!

Going down for cold reboot...

Anonymous A (OP) replied with this 11 years ago, 26 seconds later, 2 minutes after the original post[^] [v] #599,452

@599,449 (hater !JGlOo5d1iU)
Ok that still did not work. Any other suggestions?

iHate !R3jQvKbkxw replied with this 11 years ago, 40 seconds later, 2 minutes after the original post[^] [v] #599,453

@previous (A)
Next time use a condom.

Anonymous A (OP) replied with this 11 years ago, 3 seconds later, 2 minutes after the original post[^] [v] #599,454

@599,451 (iHate !R3jQvKbkxw)
Ok I tried that. I systematically disabled all of them, one by one, and it still did the same thing.

Anonymous A (OP) double-posted this 11 years ago, 51 seconds later, 3 minutes after the original post[^] [v] #599,455

@599,453 (iHate !R3jQvKbkxw)
No luck so far. Any more suggestions? Thanks.

iHate !R3jQvKbkxw replied with this 11 years ago, 31 seconds later, 4 minutes after the original post[^] [v] #599,456

@599,454 (A)
Memory banks are full of warez please flush memory and try again.

Anonymous A (OP) replied with this 11 years ago, 3 minutes later, 7 minutes after the original post[^] [v] #599,461

@previous (iHate !R3jQvKbkxw)
How do I turn off restore?

Anonymous A (OP) double-posted this 11 years ago, 1 minute later, 8 minutes after the original post[^] [v] #599,464

Hmm cannot seem to find Restore option.

iHate !R3jQvKbkxw replied with this 11 years ago, 45 seconds later, 9 minutes after the original post[^] [v] #599,466

@599,461 (A)
Let me guess. You do not make regular backups?

Please try again later.

Anonymous D joined in and replied with this 11 years ago, 40 seconds later, 9 minutes after the original post[^] [v] #599,467

@OP
Try google searching caveatipse some more

Anonymous A (OP) replied with this 11 years ago, 7 seconds later, 10 minutes after the original post[^] [v] #599,468

@599,466 (iHate !R3jQvKbkxw)
When I open My Computer and right click on the C:\ drive to bring up drop-down menu, it always says that Explorer has encountered an error and needs to close.

Anonymous A (OP) double-posted this 11 years ago, 38 seconds later, 10 minutes after the original post[^] [v] #599,470

@599,467 (D)
Ok here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 2:41:14 PM, on 7/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\OpenOffice.org 1.9.104\program\soffice.exe
C:\Program Files\OpenOffice.org 1.9.104\program\soffice.BIN
C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe
C:\Documents and Settings\Matthew Miller\My Documents\Download Escrow\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: IeMonitor - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\Conceiva\DownloadStudio\DLMonitr.dll
O3 - Toolbar: &DownloadStudio - {CB789373-04D5-4ef4-9C16-871463FD0830} - C:\Program Files\Conceiva\DownloadStudio\WebDLBar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - Global Startup: think.lgo
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download Image Using DownloadStudio... - C:\Program Files\Conceiva\DownloadStudio\ds_img.htm
O8 - Extra context menu item: Download Page Using DownloadStudio... - C:\Program Files\Conceiva\DownloadStudio\ds_all.htm
O8 - Extra context menu item: Download Selection Using DownloadStudio... - C:\Program Files\Conceiva\DownloadStudio\ds_sel.htm
O8 - Extra context menu item: Download Target Using DownloadStudio... - C:\Program Files\Conceiva\DownloadStudio\ds_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Show Page Links Using DownloadStudio... - C:\Program Files\Conceiva\DownloadStudio\ds_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {4D0C4820-53F7-4d79-A2E1-5252683CF69C} - C:\Program Files\Conceiva\DownloadStudio\DownloadStudio.exe
O9 - Extra 'Tools' menuitem: &DownloadStudio - {4D0C4820-53F7-4d79-A2E1-5252683CF69C} - C:\Program Files\Conceiva\DownloadStudio\DownloadStudio.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: DownloadStudio - {7FCA7BD7-8F4D-4a81-BE72-A470F4E517D5} - C:\Program Files\Conceiva\DownloadStudio\WebDLBar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120529858921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Anonymous D replied with this 11 years ago, 1 minute later, 11 minutes after the original post[^] [v] #599,472

@OP
How often do you think about Matt Miller per day?

iHate !R3jQvKbkxw replied with this 11 years ago, 12 seconds later, 12 minutes after the original post[^] [v] #599,473

@599,468 (A)
Have you tried simply launching what you need without the assistance of an explorer.exe?

Anonymous D replied with this 11 years ago, 1 minute later, 13 minutes after the original post[^] [v] #599,477

@previous (iHate !R3jQvKbkxw)
https://forums.techguy.org/threads/cool-web-search-in-msconfig.383035/

Its' one of Matts merry men, being all obsessed as usual.

Anonymous A (OP) replied with this 11 years ago, 1 minute later, 15 minutes after the original post[^] [v] #599,480

@599,473 (iHate !R3jQvKbkxw)
I have used Spybot and it did not detect it. Only CWShredder detected and removed it, but when I reboot it is there again.

Anonymous A (OP) double-posted this 11 years ago, 35 seconds later, 15 minutes after the original post[^] [v] #599,481

@599,472 (D)
@599,477 (D)
Ok I tried that. I systematically disabled all of them, one by one, and it still did the same thing.

Anonymous E joined in and replied with this 11 years ago, 4 hours later, 4 hours after the original post[^] [v] #599,581

@previous (A)
Sorry for your loss.

FuckAlms !vX8K53rFBI joined in and replied with this 11 years ago, 1 hour later, 5 hours after the original post[^] [v] #599,587

@599,470 (A)
> C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe
Well there's your problem.

@599,473 (iHate !R3jQvKbkxw)
I've done this before.
:

Please familiarise yourself with the rules and markup syntax before posting.