Persistent problems with CoolWebSearch and DyFuCA

Status
Not open for further replies.
I've been battling against spyware etc for about a month now. In fact, I've followed realblackstuff's instructions at https://www.techspot.com/vb/topic17297.html 16 times now! Also, I'm only visiting trusted websites and using Firefox instead of IE, so I don't reckon I'm getting reinfected.

Earlier today, within minutes of opening Firefox, my PC was locked up, no response to Ctrl-Alt-Del, and so I had to stick a pencil in the reboot slot. I ran realblackstuff's instructions again and Ad-Aware came up with 10 critical objects, only 8 of which it could remove. This is becoming a familiar pattern. Although it offers to remove the remaining 2 critical objects after the next reboot, it never finds them again, and in time, all the problems return.

Here are the two that couldn't be removed today (this is taken from the Ad-Aware log):

Deep scanning and examining files (c:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Object "A0055962.CPY" found in this archive.

CoolWebSearch Object Recognized!
Type : File
Data : FS30.CAB
Category : Malware
Comment : Object "A0055962.CPY" found in this archive.
Object : c:\_RESTORE\ARCHIVE\


Object "A0056642.CPY" found in this archive.

DyFuCA Object Recognized!
Type : File
Data : FS44.CAB
Category : Malware
Comment : Object "A0056642.CPY" found in this archive.
Object : c:\_RESTORE\ARCHIVE\

There's been no suspicious changes to my HijackThis log since realblackstuff gave it a clean bill of health.

Well, any help would be very gratefully received.

Thanks.
 
You have overlooked the ONE critical point:
You need to switch System Restore OFF before you do your 'spring-cleaning'. That deletes your restore-points. These rotten files are stored inside one of your restore points, where no program has any access.
Only by deleting those points, i.e. switch System Restore OFF, can you get rid of them.
Then switch it back on again.
 
Thanks

Aha - I think that's finally sorted it. Thanks very much indeed Sir Blackstuff.
I thought the instruction to disable system restore only applied to XP users - I'm using ME.
Cheers.
 
ME introduced the system restore function, which is next to useless if you ask me :) I always turn it off.
 
Status
Not open for further replies.
Back