Recommended Posts

Hello,

My computer is infected with a trojan virus called norio. It started by a hacking file called coolwebsearch, or at least that's what I've found out by running Adaware and Spybot.

Apparantly Norton Antivirus 2005, nor Panda Antivirus are able to do anything about this Trojan. Can anyone help me out? I've been searching the net for a sollution for the last 4 days now (what a way to spend the New Year eh...). Not to say I'm desperate.

Many thanks in advance

Brgds

Thomas O'Malley

Link to comment
https://www.neowin.net/forum/topic/266168-wwwcoolwebsearchcom/
Share on other sites

Are you sure Norton can't do anything about it?  Have you booted into Safe Mode before attempting to clean it?

http://securityresponse.symantec.com/avcen...ojan.norio.html

Follow these steps!

585223873[/snapback]

I saw that page, but no... It didn't work... :no:

CoolWebSearch is one of the worst Spyware infections. The latest variants use a Hidden DLL that is installed by taking over the file system's data stream and stealthing the DLL file. Some AntiVirus programs will detect and clean it from memory but as soon as your system is rebooted and another Internet connection made, it will reinstall itself. CWShredder 2.x removes this variant.

Here is the prog to clean it CWShredder

This will fix it :D

Sorry, here are the instructions, pretty easy! :cool:

Instructions - Download, close all web browsers and run, select "I AGREE", "Fix" and "OK". After it is finished select "Next" to see if you were infected. Run CWShredder again to confirm all variants of CoolWebSearch have been removed.

Sorry, here are the instructions, pretty easy! :cool:

Instructions - Download, close all web browsers and run, select "I AGREE", "Fix" and "OK". After it is finished select "Next" to see if you were infected. Run CWShredder again to confirm all variants of CoolWebSearch have been removed.

585223912[/snapback]

Hi Toejam,

Maybe it's me, maybe something changed over the last days but, following these instructions it does not work.

I can download and make the scan run (it finds 46 infected files). At that time I need to register and pay for the complete version.

Did you download the file from the link that I gave you? You end up on majorgeeks website and there it quite clearly says that it is freeware, sorry if this is not the case. I ran the thing and did not run into any registration requests, so I am not really sure what it is asking you! :blink:

Did you download the file from the link that I gave you? You end up on majorgeeks website and there it quite clearly says that it is freeware, sorry if this is not the case. I ran the thing and did not run into any registration requests, so I am not really sure what it is asking you! :blink:

585224068[/snapback]

Indeed I did download it from the site you gave me.

And indeed you do end up here: http://www.majorgeeks.com/download3019.html

If you decide to download you are transferred to this site http://www.pctools.com/spyware-doctor/?ref...al_mg_sd_336_rd . All of a sudden they don't mention Freeware anymore. If you finally perform the scan, they ask you to register.

So far, no sollution found, I may add ;)

Sorry to hear that bud, I will see what I can do!

Just checked the link you said you tried, you are downloading the wrong thing, you must download CWShredder 2.12 click on one of the American sites!

Edited by toejam

I can see what you did, you must wait for the download to start, you did not give it a chance to start, and then you clicked on download Spyware Doctor, no wonder you ended up with the wrong thing! As they say in the classics read the instruction and ye shall be rewarded!!! :whistle: :whistle:

Thanks guys,

CWShredder scanned and worked. At least that problem is solved. There was no infected file from www.coolwebsearch found.

So the next question I have is how it can be possible that CWShredder doesn't find anything while my Homepage on my browser always resets itself on about:blanc (while it was www.google.com) and how it is possible that Adaware finds 19 infected files from www.coolwebsearch.com... :wacko:

Thanks guys,

CWShredder scanned and worked.  At least that problem is solved.  There was no infected file from www.coolwebsearch found. 

So the next question I have is how it can be possible that CWShredder doesn't find anything while my Homepage on my browser always resets itself on about:blanc (while it was www.google.com) and how it is possible that Adaware finds 19 infected files from www.coolwebsearch.com...  :wacko:

585224557[/snapback]

google a removal tool called "about:buster", or post a Hijackthis Log, CWShredder can't clean all CWS variants.

google a removal tool called "about:buster", or post a Hijackthis Log, CWShredder can't clean all CWS variants.

585227775[/snapback]

This is correct. CWShredder can handle most primitive forms of CWS, but there are one or two that are just totally nefarious and cannot be removed by CWShredder. I actually had one of the types that cannot be removed from it on my computer, and at that time, the variant was still fairly new, and boy, I thought I would have to take a jackhammer to my computer before I finally got rid of it.

Post a HijackThis log here (you can attach it if you like). We will tell you where to go from there. HijackThis will catch some deviant DLL files that are associated with CWS.

This is correct. CWShredder can handle most primitive forms of CWS, but there are one or two that are just totally nefarious and cannot be removed by CWShredder. I actually had one of the types that cannot be removed from it on my computer, and at that time, the variant was still fairly new, and boy, I thought I would have to take a jackhammer to my computer before I finally got rid of it.

Post a HijackThis log here (you can attach it if you like). We will tell you where to go from there. HijackThis will catch some deviant DLL files that are associated with CWS.

585227850[/snapback]

This is all like chinese to me, but I haven't got anything to loose, do I?

Anyway, I think this is what I think you asked me to do:

Logfile of HijackThis v1.99.0

Scan saved at 17:12:54, on 4/01/2005

Platform: Windows 2000 SP2 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\SYSTEM32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\System32\svchost.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINNT\System32\nvsvc32.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINNT\system32\ZoneLabs\vsmon.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\System32\mspmspsv.exe

C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

C:\WINNT\System32\TCAUDIAG.exe

C:\WINNT\loadqm.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\ICQLite\ICQLite.exe

C:\program files\quicktime\qttask.exe

C:\Program Files\Logitech\MouseWare\system\em_exec.exe

C:\WINNT\System32\RUNDLL32.EXE

C:\WINNT\System32\ctfmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\OpenOffice.org1.1.0\program\soffice.exe

C:\WINNT\System32\msiexec.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINNT\system32\apilv.exe

C:\WINNT\system32\mfchk32.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\PROGRA~1\WINZIP\winzip32.exe

C:\WINNT\explorer.exe

C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.telenet.be

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\honmj.dll/sp.html#52409

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\honmj.dll/sp.html#52409

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\honmj.dll/sp.html#52409

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\honmj.dll/sp.html#52409

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\honmj.dll/sp.html#52409

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\honmj.dll/sp.html#52409

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\honmj.dll/sp.html#52409

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Telenet Internet

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://pac.telenet.be:8080

R3 - Default URLSearchHook is missing

F2 - REG:system.ini: UserInit=C:\WINNT\System32\Userinit.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {ECC139F7-6982-B594-DBFC-75FF0AA44A72} - C:\WINNT\crob32.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

O4 - HKLM\..\Run: [mfchk32.exe] C:\WINNT\system32\mfchk32.exe

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\RunOnce: [MNSIndex] C:\Program Files\ToDelete\MNSIndex.exe

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe

O4 - HKCU\..\Run: [spyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup

O4 - HKCU\..\Run: [ultimate Popup Blocker] C:\Program Files\ToDelete\Ultimate Pop-up Blocker.exe

O4 - HKCU\..\Run: [ultimate Popup Killer] C:\Program Files\Ultimate Popup Killer\Popupkiller.exe

O4 - HKCU\..\Run: [Each Ref] C:\DOCUME~1\Patje\APPLIC~1\FORVGA~1\enc stop.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\RunOnce: [MNShist] C:\Program Files\ToDelete\MNSHist.exe MNSErase

O4 - HKCU\..\RunOnce: [iCQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot

O4 - Startup: OpenOffice.org 1.1.0.lnk = C:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe

O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.telenet.be

O16 - DPF: Dexia netbanking - http://netbanking.dexia.be/PC//Dynamic/Sha...t//DexiaIIA.cab

O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab

O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.t058.com/inst/enter.cab

O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/091a39087ff674...ip/RdxIE601.cab

O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404...llInstaller.exe

O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab

O16 - DPF: {970BF476-3CF2-4572-9EF9-4479E1591DB8} (VacPro.belgio_ver3) - http://www.advnt01.com/dialer/belgio_ver3.CAB

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab

O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll

O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab

O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: InCD File System Service - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe

O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe

O23 - Service: Remote Procedure Call (RPC) Helper - Unknown - C:\WINNT\system32\apilv.exe

If you do find a sollution to my problem, please try to explain it in a language understandable for simple human beings as myself, will yah?

Just a quick question, what version of CWShredder did you download and use?

This from the people who now own and make CWShredder:

CWShredder? Version 2.1 is the latest defense against the new Cool Web Search variants.

CWShredder? Version 2.1

Released: December 2004

Here is the link, once you click on the correct link, WAIT FOR THE DOWNLOAD TO START, do NOT click on anything else, the download takes a few moments to start.

CWShredder 2.12

Hope this helps.

Here is a link from the homepage CWShredder

Just a quick question, what version of CWShredder did you download and use?

This from the people who now own and make CWShredder:

CWShredder? Version 2.1 is the latest defense against the new Cool Web Search variants.

CWShredder? Version 2.1

Released: December 2004

Here is the link, once you click on the correct link, WAIT FOR THE DOWNLOAD TO START, do NOT click on anything else, the download takes a few moments to start.

CWShredder 2.12

Hope this helps.

Here is a link from the homepage CWShredder

585230296[/snapback]

That's the one I downloaded and tries toejam.

But there is a positive progress, meaning: I tried Spy Sweeper and that seems to work... At least, my home page is reset to http://www.google.com .

But I did not reboot so far, so let's just hope for the best. CWS isn't removed, Adaware still finds files from that stupid www.coolwebsearch.org thing.

The Norio Trojan is definitly removed, that's for sure. So the only problem remaining is CW:crazy:azy:

This is really irritating I can just see how mad you must be. I am really going to see if I can help, come hell or high water we must get rid of this thing. I tell you these people who make **** like this should be hung drawn and quartered, jeez they **** me off!! :crazy:

This is really irritating I can just see how mad you must be. I am really going to see if I can help, come hell or high water we must get rid of this thing. I tell you these people who make **** like this should be hung drawn and quartered, jeez they **** me off!! :crazy:

585230561[/snapback]

Even Spy Sweeper can't get rid of it... :(

It keeps on finding 2 'things', saying AdAware found: CWS_NS3 (CWS_NS3 has the ability to hijack your Web searches, home page, and Internet Explorer settings.) I can delete them through Spy Sweeper, but if I run it again, these two items are there again...

I blocked my homepage now on the default homepage, as Spy Sweeper recommended when you have a good idea you were hyjacked, which is: http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome So there goed my http://www.google.com as my used to be homepage...

Anyway, when this scan is finished I'm going to reboot the system once more to see if that changes anything. :cry:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Just another reason (aside from many others) not to use Edge. Firefox 153.0b5 DEx64 has a similar feature added recently in prior builds that I will turn off at some point when I get around to it. It's the new "Something looks suspicious" page that pops up here and there. It cleverly hides itself between web pages that I've actually visited; as a result, you know, of selecting a web page and telling the browser where to go. The interesting thing is that it does not produce these warnings from pages that I, as the only intelligent user of the browser in my system, have ever directed the browser to open! What seems to be happening is that the browser looks at all the goofy ad links on a web page I do actually open and selects one that "looks suspicious" and then creates the "something looks suspicious" web page, which is neatly inserted, as mentioned, between web pages my RB ("real brain") has directed the browser to load in a session. The thing is, I usually look at links I am considering to follow before I ask the browser to load them, and in cases I have noticed where the link does indeed look suspicious, most of the time I will choose to not follow the link at all. Doesn't everyone do this or something similar? I am picky about what I voluntarily load... (I don't like links that start off fine, with a site designaiton that seems normal enough but then is followed by indecipherable alphanumeric strings many, many lines long, etc. I tend to reject those because they look suspicious. They may not be, but I don't care... I'll stay with Firefox, of course, if for no other reason than they usually let you turn off the junk you don't like. And because it isn't Edge... But at some point Microsoft will come to realize that putting your bookmarks on the left side is a Good Thing for a lot of people, just as Microsoft discovered when it had the bright idea of nailing the Windows taskbar to the bottom of the screen, when for decades Microsoft browsers had left that placement up to the user. They have finally reversed the obscenity of that decision. Finally.
    • Google was using the old CATPCHAs data to train their LLMs. What is the say they won't use this camera data of users to train their LLM? these companies need some strict regulations!
    • Depends on what you need. Might be a bit clearer on what you plan to do with it. Sort of a waste if you get the newest and greatest, but don't know how to use it.
    • NTLite 2026.06.11200 by Razvan Serea NTLite is a Windows configuration tool that allows you to modify your existing Windows install or an image yet to be deployed, remove Windows components, configure and integrate, speed up the Windows deployment process. Reduce Windows footprint on your RAM and storage drive memory. Remove components of your choice, guarded by compatibility safety mechanisms, which speed up finding that sweet spot. Windows Unattended feature support, providing many commonly used options on a single page for easy setup. Easily integrate a single or multiple drivers, update or language packages. Package integration features smart sorting, enabling you to seamlessly add packages for integration and the tool will apply them in the appropriate order, keeping hotfix compatibility in check. One of the important new features of NTLite (compared to its predecessors) is the ability to modify an already installed the operating system, by removing unnecessary components. Supports Windows 11, 10, 8.1 and 7, x86 and x64, live and image. Server editions of the same versions, excluding support for component removals and feature configuration. ARM64 image support in the alpha stage. Does not support Checked/Debug, Embedded, IoT editions, nor Vista or XP. NTLite 2026.06.11200 changelog: New Secure Boot Migration support: Verification, certificate staging, and boot-manager/sector update across the Image, Updates, Apply, and Create-ISO pages (2023 CA migration, optional 2011 revocation, Anti-rollback, Boot sector choice etc) Secure Boot Host Readiness: Live host Secure Boot migration monitor and Servicing-task control Option under Image page - C:\Windows row, or load the host as the target - Updates - Secure Boot Image: 'Sort mounted images first' option for the image list in Menu-Settings UI: Hover description card for Components and Unattended pages, selectable text and quick access to Compatibility options Command line: Relay commands into the already-running instance Enables controlling already running NTLite via ntlite.exe Use /NewInstance to launch an additional instance using CLI operations (premium) UI: 'New instance' option via main menu instead of a secondary ntlite.exe prompt Apply: Hide individual Apply-page notes with a per-note dismiss (X), critical excluded Settings: 'Unsigned RDP file launch warnings' tweak (RDP client), bypassing the April 2026 security-update prompt on RDP connections Upgrade Image: Live OS and deployed image editing now unlocked on free/test licenses, same licensing as images Image: 'Recompress' option in manual dialog Remove Editions to shrink the WIM in one session Image: SWM part size set inline on the Apply page and image dialogs, split-size popup retired Image: Relative 'Last change' dates; editions grouped by build time to reduce noise Image: 'Forget - Missing' on the Edit-cache menu to mass drop entries whose folder is gone Components: Root groups reorganized - user-facing groups first, system/critical last Components: Show filter options to view components by Template or App-type, since Apps are now merged into groups Presets: Delete confirmation now lists the multi-selected preset names UI: Design update propagated to the rest of the tool UI: Filter and search match words in any order and partially, better results filtering Components Unattended: Input-locale language derives from the user locale, with an independent keyboard picker, enables combinations previously unavailable Unattended: Input-locale now allows for a user value override Unattended: Localization OOBE WinPE now can be copied with the new WinPE Copy OOBE localization toggle, enter locale settings once for both stages Updates: Downloader greys and locks updates the image already carries (hotfix and MSIX) Updates: Resume interrupted update downloads Command line: Many upgrades, see /?, now prints help to the console or redirected output UI-Translation: Finnish language added, also thanks for Chinese Traditional (Matt), French (tistou77), Italian (clarensio), Russian (RDS), Swedish (1FF), Vietnamese (Vu Anh Vu) Fix Components: Containers removal breaking Apps deployment Components: Microsoft Account had leftovers when Easy Migrate is kept Image: Export to an existing WIM improvements, Append renamed to Merge Image: Improved 26H1 live removal support Image: No more 'X:\ not accessible' popup for certain drives during image scan Presets: Manual image refresh picks up presets added/removed outside the app Tweaks: Disabled visual-effect animations no longer return after first logon on a new profile Tweaks: Live Visual Effects toggles (animations, drag full windows, font smoothing) now apply correctly Download: NTLite 2026.06.11200 | 20.5 MB (Free, paid upgrade available) Link: NTLite Home Page | NTLite Features | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Ah. La Fontana De Incontinentia ! Bella ! Bella !
  • Recent Achievements

    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
    • First Post
      carols23 earned a badge
      First Post
    • One Month Later
      Tom Willson earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      +Edouard
      257
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      93
    5. 5
      macoman
      67
  • Tell a friend

    Love Neowin? Tell a friend!