Computer Maintenance
To start, I'll post a little bit about the CWS (Coolwebsearch) Trojan, namely the SearchX variant.
For those of you that don't know, CWS is a widespread trojan that affects many computers, there are dozens of variants of it, but the SearchX variant is especially hard to remove. It burrows itself in your computer and the registry entry is hidden so you cannot read it. The registry entry also restores the infected dll if you delete it, and the infected dll restores the registry. To remove it, go onto your start menu and use run. Type "regedit" (without the quotations) in the box. Be sure to make a backup before editing.
Expand the registry tree until you get to; HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
Try deleting the key AppInit_DLLs. It gets deleted, but press F5 and you'll see that it is restored again. To get around this problem you will have to do the following:
1. Go back to the part of the tree you were just in, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
2. Rename the Windows folder in that part to Windows2.
3. Delete the AppInit_DLLs key from the registry.
4. Rename the folder to Windows again.
5. Now that the key is gone, and the infected file is unable to restore it, run your adaware (or whichever scanner you may use) scanner (after updating it) and delete any infected files.
Linkies :
Lavasoft - Ad-Aware
CWShredder - CWS Trojan Removal Tool
Hijackthis - Before deleting anything using this program, post log on computer help website
Computer Help Forums - Here is where you can post logs from Hijackthis
Tweaknow - Developers of Regcleaner, buy or download the free version here
See, I try to help the community out sometimes
Edited by - parabolix on 10/11/2004 1:46:45 PM