Re: IE default Page
Date: 07/16/04

  • Next message: Ed Wittmann: "RE: IE default Page"
    Date: Fri, 16 Jul 2004 11:14:18 -0700

    My experience was that the fix (CWShredder) would not "take", until the
    machine was restarted after applying it. Applying fix, and then opening
    the browser just lead to reinfection. possibly because of a cached
    registry value/hive/key.

    Justin Ross
    Senior Network Security Engineer
    Signal Solutions Inc. -
    101 Wilcox Dr.
    Sierra Vista, AZ 85635
    Phone: (520) 459-1354 x3095
    Cell: (520) 234-4080
    Fax: (520) 459-1428

    Try this out, I had one that was doing that and used the technique
    described by LoPhatPhuud in the web-forum topic linked below to remove it.
     The only difference was that my .dll and .cpy.dll files had a different
    base name. But it's easy enough to find as it's mentioned in the Guardian
    branch and should be the only .cpy.dll file in the system32 directory. It
    is set to hidden, system, and read-only, so you'll need to tell Windows to
    show it to you.

    >Interesting bug going around, coolwebsearch, has anyone been successful
    >removing this virus from a system? It looks like it recreates the DLL
    >c:\windows\system32 and renames it after a few reboots. It's pretty
    >and I haven't been able to fully contain it.
    >Thoughts? Suggestions? I've used highjackthis, cwshredder and a few
    >detectors, but nothing is really fixing the problem.

    Steven Bairstow
    Computer and Network Services - Abington College - Penn State University              PGP Key ID = 0x0C81E13C
    "No trees were killed in the creation of this message.
    However, many electrons were terribly inconvenienced."

  • Next message: Ed Wittmann: "RE: IE default Page"

    Relevant Pages

    • Re: .DLL
      ... Spybot - ... CWShredder - ... MS-MVP Windows - Shell/User ... | I think my son deleated a DLL because when i restart ...
    • Re: Startseite Internet Explorer
      ... Lasse CWShredder darüberlaufen. ... Eintrag von oben ist es meist. ... Eine DLL ohne Namen mit 4 ... Buchstaben und einer Größe von ca 32KB. ...
    • Re: Cannot see email contents
      ... I tried these things -- The DLL is registered and CWShredder says that my system is clean, but the problem is still there, ... but I only see the email headers. ...