Recycle your Computers & Technology with us.

What is a coolweb trojan?

Posted By : Michael of Katharine Gibbs School - New York on November 1, 2004

Follow us on Facebook   Follow us on Twitter   Follow us on LinkedIn

Let Data Doctors be your personal IT department today

I cannot get rid of about:blank on my Windows 98 OS. I've tried CW Shredder, Adaware, Spybot, Norton Anti Virus, Track Eraser (all with the most current definitions). As nearly as I can tell, I'm not getting the hidden .dll file erased. When these software cleaners do their work, they get rid of the obvious .dll file, but since the hidden file is still there, about:blank is back in a matter of hours.

Can you help?

This question was answered on November 1, 2004. Much of the information contained herein may have changed since posting.


Hey what you have is a nasty coolweb trojan to get rid of it do the following, with hijack running and nothing else including IE explorer have hijack fix these.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

res://C:\WINDOWS\mctpy.dll/sp.html#27859

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

res://C:\WINDOWS\mctpy.dll/sp.html#27859

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

res://C:\WINDOWS\mctpy.dll/sp.html#27859

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

res://C:\WINDOWS\mctpy.dll/sp.html#27859

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

res://C:\WINDOWS\mctpy.dll/sp.html#27859

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {F202A8F9-7906-088C-A0E3-99FD4BE0B787} - (no file

O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no

file)

O13 - WWW Prefix: http://

O15 - Trusted Zone: *.05p.com

O15 - Trusted Zone: *.searchmiracle.com

O15 - Trusted Zone: *.scoobidoo.com

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=9eafaeb2a8e2a9518112bc6e0cedee1552dd4ecb1dd748bcf1cf4d42ced1394245b14c137e17952f3a6abadc3d36297b2b37:b70ac5aa8ec48e2e58a29296baabe1d6.

Reboot your computer This should be the end of your troubles.

About the author

Posted by Michael of Katharine Gibbs School - New York on November 1, 2004

Need Help with this Issue?

We help people with technology! It's what we do.
Contact or Schedule an Appointment with a location for help!