Re: [Full-Disclosure] Cool Web Search

From: KF (lists) (kf_lists_at_secnetops.com)
Date: 07/30/04

  • Next message: Stephen Taylor: "[Full-Disclosure] RE: outbind in MS outlook"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 29 Jul 2004 21:09:33 -0400
    
    

    Try a deltree /y c:\ that usually does the trick.
    -KF

    Todd Towles wrote:

    >The creator of CWShredder claims the newest versions of CWS are very
    >stealthy and I believe he as stopped updating the program. Therefore
    >CWShredder isn't the best for the newest. But as far as I understood things
    >(from other mailing list and forum post), HiJackThis wasn't removing them
    >100% either.
    >
    >Todd
    >
    >-----Original Message-----
    >From: full-disclosure-admin@lists.netsys.com
    >[mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Richard
    >Golodner
    >Sent: Thursday, July 29, 2004 5:51 PM
    >To: 'Gregh'; Disclosure Full
    >Subject: RE: [Full-Disclosure] Cool Web Search
    >
    >Try CWShredder too!
    >
    >-----Original Message-----
    >From: Gregh [mailto:chows@ozemail.com.au]
    >Sent: Thursday, July 29, 2004 5:46 PM
    >To: Disclosure Full
    >Subject: [Full-Disclosure] Cool Web Search
    >
    >
    >JFYI of anyone interested:
    >
    >On Nanog a short time back, most of the list there decided that CWS couldn't
    >easily be removed. I first stumbled across it maybe around the start of July
    >and have had many instances of it, since, in many places.
    >
    >Adaware does bugger-all to remove it. Spybot recognised it, got rid of it
    >and upon reboot it was back. It was never quite clear from a simple
    >inspection, what was putting it back.
    >
    >When I first found it, I had also found "HiJackThis" and ran it. That prog
    >brought up the proper registry entries to enable me to correctly identify
    >CWS, remove the entries and delete files. It took some time the first time I
    >saw it but it takes about 10 mins (if that) to get rid of it, now. Nanog
    >disagreed and said it wasn't that easy. It simply WAS that easy. I just
    >happened to experience "dumb luck" and be one of the first (if not the
    >first) to easily get rid of it through HiJackThis.
    >
    >So, for those of you who don't think Nanog is full of "Gods of Correctness",
    >if you are having probs with removal of CWS, get HiJackThis, let it scan and
    >then you will see, sticking out like a wart on your......nose :)........ the
    >entries you need to delete in order to properly rid that machine of CWS. It
    >wasn't hard using that prog.
    >
    >Greg.
    >
    >_______________________________________________
    >Full-Disclosure - We believe in it.
    >Charter: http://lists.netsys.com/full-disclosure-charter.html
    >
    >_______________________________________________
    >Full-Disclosure - We believe in it.
    >Charter: http://lists.netsys.com/full-disclosure-charter.html
    >
    >_______________________________________________
    >Full-Disclosure - We believe in it.
    >Charter: http://lists.netsys.com/full-disclosure-charter.html
    >
    >
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Stephen Taylor: "[Full-Disclosure] RE: outbind in MS outlook"

    Relevant Pages

    • RE: [Full-Disclosure] Cool Web Search
      ... CWShredder isn't the best for the newest. ... On Nanog a short time back, most of the list there decided that CWS couldn't ... I had also found "HiJackThis" and ran it. ... saw it but it takes about 10 mins to get rid of it, ...
      (Full-Disclosure)
    • [Full-Disclosure] Cool Web Search
      ... On Nanog a short time back, most of the list there decided that CWS couldn't ... CWS, remove the entries and delete files. ... saw it but it takes about 10 mins to get rid of it, ...
      (Full-Disclosure)
    • CWShredder got rid of wmplayer.exe but not references to it
      ... I've used CWShredder to get ... rid of CWS and when it did, it must have removed wmplayer.exe because when i ... Gary Roach ...
      (microsoft.public.security)
    • Re: coolwebsearch/res://bsahd.dll/index.html#12802
      ... I'm informed that the 01R325 AdAware update of 6/28 supposedly completely ... Then ran> CWShredder, Hijackthis showed it clean. ... The entries, once>> removed, stay gone even after login. ... >>> CWS is probably the nastiest piece of spyware out there>> these days. ...
      (microsoft.public.security.virus)
    • Re: HELP!!! ***res://<random>.dll/<random>.html#<random>*** HELP!!!
      ... About.blank and other new ones by CWS are very hard ... You need more than HJT, CWShredder, and SBS&D. ... Go to the spywareinfo forum http://forums.spywareinfo.com/ and look in their ... > Here's the scan that hijackthis created: ...
      (microsoft.public.security)