CWShredder 1.59.1 update button
Posted 04 July 2004 - 05:15 PM
Then this popped up when I clicked the OK button:
I clicked the Fix button, and it was supposedly clean. I then ran Spybot S&D 1.3 and it discovered a CoolWebSearch variant, which it neutralized. I also reinstalled CWShedder from Major Geeks. I use Firefox, do not download any file sharing software, games, or music, and have been meticulous about scanning with Adaware, Spybot, and Spywareblaster, as well as CWShredder and Hijack This. Could this have been some sort of redirect from the bad guys with downloaded the trojan, or did I just screw something up? I still get the same pop ups when I click on the update button, but haven't clicked the link button and have thus far remained uninfected. I have the latest patches, and did a deep scan with Adaware and found nothing new.
Posted 04 July 2004 - 06:41 PM
Posted 05 July 2004 - 01:24 PM
Just thought Id let you know I went throught the sam thing yesterday. I was infected and believe i have ditched this @#%%.
I also had this happen to me yesterday. I was unable to run cwshredder and computer froze up. How did you get rid of this problem? Did I download something that wasn't the real cwshredder. I deleted it once and redownloaded it with the same results.
Posted 05 July 2004 - 01:37 PM
Posted 05 July 2004 - 01:45 PM
A mutation of this variant exists that attempts to close
CWShredder, HijackThis, Ad-Aware, Spybot S&D and the SpywareInfo forums when
they are opened.
It uses the filename IEXPLORER.EXE (note the extra 'R') and a different Registry value.
It drops a hosts file that blocks over two dozen anti-spyware sites.
CWShredder has been updated to circumvent this.
Simplicity is always brilliant.
Posted 05 July 2004 - 06:47 PM
I was unable to use the End Task. Nothing shut CWShredder down except turning the power off to the computer. I had none of the symptoms listed in the last post. Ad-Aware and Spybot ran just fine as well as Trojan Remover.
I think possibly SpywareBlaster kept it from infecting my computer. I have deleted CWShredder because I cannot make it run.