Secure Most Provide you most reliable security utilities!
Home Articles File Center Privacy Contact us Links
Now Position: Home>Tech Articles>How to Remove Annoying Spyware and Adware
How to Detect and Remove CoolWebSearch?
CoolWebSearch Description:

CoolWebSearch is a name given to a wide range of different browser hijackers. Though the code is very different between variants, they are all used to redirect users to coolwebsearch.com and other sites affiliated with its operators.

The script at this site can only detect one of the variants listed here, namely CoolWebSearch/DNSRelay.

CoolWebSearch/DataNotary : earliest known variant, hijacking to datanotary.com. Drops a CSS stylesheet file in the Windows folder and sets it to be used as the user stylesheet for all web pages viewed in IE. The stylesheet includes embedded JavaScript code which tries to guess when the user is viewing porn sites.

CoolWebSearch/BootConf : drops a user CSS file in the same way as DataNotary, but pointing at www.coolwebsearch.com. Also hijacks the home page and all search settings to point to coolwebsearch, and hacks the DNS Hosts file to redirect access of MSN address-bar search to coolwebsearch.com. The site names are obfuscated using URL-encoding (%XX) to make them difficult to read. A program bootconf.exe is set up to run on every startup, resetting the hijack. Finally coolwebsearch.com is added to the Trusted Sites list, along with msn.com, whom coolwebsearch are also impersonating.

CoolWebSearch/MSInfo : another user-CSS-hijacker, this time pointed at true-counter.com, currently redirecting to global-finder.com.

CoolWebSearch/SvcHost : a Hosts file hijacker, which works in a rather unusual way (probably to avoid being detected by anti-hijacker tools). Its targeted sites (Yahoo Search, MSN Search and all countries' versions of Google) are set in the Hosts file to point to localhost' (127.0.0.1). Since the local host (the computer the browser is running on) is most often not running a web server, this results in an error page; it is this error page that is then hijacked to the CWS site slawsearch.com.

CoolWebSearch/PnP : a search hijacker that hides inside the 慽nf' folder usually used for storing device driver information. Its hijacker file oemsyspnp.inf is run on each startup, using a slightly different install command each time. This command cycles through install sections 'RunOnce', 'AudioPnP', 'VideoPnp', 'IdePnP' and 'SysPnP', though quite why is unknown as it does the same thing regardless of which section is used, namely hijacking home page and search settings to point at www.adulthyperlinks.com and www.allhyperlinks.com. It also adds activexupdate.com to the IE safe Sites' list, for unknown purpose (this is not the same as the Trusted Sites Zone).

CoolWebSearch/MSSPI : a search results hijacker implemented as a Winsock2 Layered Service Provider (a fairly low-level networking component, which is tricky to remove). Targets Google, Yahoo and Altavista, opening advertising from unipages.cc.

CoolWebSearch/DNSRelay : an address bar search hijacker implemented as an IE URL Search Hook. As well as search phrases, entering any site name into the address bar without a leading http://' or www' will result in a search aimed at activexupdate.com, a CWS site redirecting through yellow2.com to allhyperlinks.com.

CoolWebSearch Automatic Removal:

Using Spyware Doctor to remove CoolWebSearch AUTOMATICALLY!

Sponsored Links:

CoolWebSearch Manual Removal:
DataNotary, BootConf, MSInfo variants

For these variants, start by opening Tools->Internet Options->Accessibility and make sure the 'user style sheet' option is turned off.

You should then be able to delete the user stylesheet from the Windows folder. With DataNotary it is called 'default.css'; with MSInfo it is called 'oslogo.bmp'; with Bootconf it may be either.

MSInfo variant only

Next, open the file 'win.ini' from the Windows folder in a text editor. Delete the line un=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\msinfo.exe?and save. (This line may change a little on different systems, but will always point to msinfo.exe.) Delete the 'MSInfo' folder inside 'Common Files' in the 'Program Files' folder.

BootConf, SvcHost variants

Next, open the registry (Start->Run->regedit), find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, and delete the bootconf.exe or svchost.exe entry. You can then delete the bootconf.exe or svchost32.exe file from the System folder (which is inside the Windows folder, and called 'System32' on Windows NT/2000/XP)

BootConf, SvcHost, MSInfo variants

From the System folder, open the drivers->etc folders and find the file named 'HOSTS', with no extension. Either edit it to remove the hijacker entries, or simply delete the file.

PnP variant

Open the registry (Start->Run->regedit) and find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Delete the 'SysPnP' entry, and the 'oemsysinf.pnp' file from the 'inf' folder (which is inside the Windows folder).

MSSPI variant

Removing a Layered Service Provider by hand is tricky and if you get it wrong you'll lose your internet connection. If you really want to try, open the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSock2 \Parameters\Protocol_Catalog9\Catalog_Entries, delete the subkeys starting with the path of msspi.dll, renumber the remaining subkeys, and set the Num_Catalog_Entries value in the Protocol_Catalog9 key to match the highest numbered subkey left.

Normally it is better to get a program (eg. CWShredder, HijackThis or LSPFix to remove an LSP for you.

Having done that, open the registry and check the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run for an 'msupdate' entry; delete it if you find it. Restart the computer and you should be to delete msspi.dll in the System folder (which is inside the Windows folder, and called 'System32' on Windows NT/2000/XP), along with msupdate.exe if you have it.

DNSRelay variant

Open a DOS command prompt window (from Start->Programs->Accessories) and enter the following commands:

cd "%WinDir%\System"
regsvr32 /u dnsrelay.dll

Restart and you should be able to delete the file 'dnsrelay.dll' in the System folder (which is inside the Windows folder, and called 'System32' on Windows NT/2000/XP).

All variants

After having removed the software, use Internet Options->Programs->Reset Web Settings to remove the bogus home page and search settings.

More Removal Instructions for Adware/Spyware Programs - 'C'
Remove C2.lop Remove Catch Cheat Spy 1.4
Remove Call Online Two Remove Chat Watch
Remove ChatBlocker Remove Chota
Remove Clearsearch Remove Click Till U Win
Remove Click2FindNow Remove ClickTheButton
Remove ClickToSearch Remove ClientMan
Remove ClientMan.bho1 Remove ClientMan.bho2
Remove ClockSync Remove CnsMin
Remove Coder Dialer Remove COM
Remove Com Policy Remove Comet Cursor
Remove Comload Remove CommonName
Remove CommonName.winnet Remove Computer Snooper
Remove ComputerSpy Remove Conducent
Remove ConfigSys Remove Content Monitor
Remove Coolbar Remove Coolsavings
Remove CoolWebSearch Remove CoolWebSearch.Alfasearch
Remove CoolWebSearch.control Remove CoolWebSearch.cpan
Remove CoolWebSearch.ctrlpan Remove CoolWebSearch.DNSE
Remove CoolWebSearch.DNSErr Remove CoolWebSearch.ehttp
Remove CoolWebSearch.excel10 Remove CoolWebSearch.explorer32
Remove CoolWebSearch.iefeatsl Remove CoolWebSearch.iefeatslupdate
Remove CoolWebSearch.image Remove CoolWebSearch.keymgrldr
Remove CoolWebSearch.ld Remove CoolWebSearch.madfinder
Remove CoolWebSearch.mssearch Remove CoolWebSearch.mstaskm
Remove CoolWebSearch.msupdate Remove CoolWebSearch.msupdater
Remove CoolWebSearch.mtwirl32 Remove CoolWebSearch.notepad32
Remove CoolWebSearch.olehelp Remove CoolWebSearch.qttasks
Remove CoolWebSearch.quicken Remove CoolWebSearch.soundmx
Remove CoolWebSearch.sys Remove CoolWebSearch.time
Remove CoolWebSearch.winproc32 Remove CoolWebSearch.xplugin
Remove CoolWebSearch.xpsystem Remove Coulomb Dialer
Remove Covenanteyes Remove CrackedEarth
Remove Crocopop Remove CrossKirk
Remove CustomToolbar Remove Cyber Informer
Remove Cyber Predator Remove Cyber Snoop 4.0
Remove Cydoor Remove Cytron
More Removal Instructions for Adware/Spyware Programs
Sign up for free up-to-date messages about your PC's security & privacy:
              Email
Confirm email
     Your Name    
 Anti-Keylogger  Password Pecovery
 Anti-Spam  PC Monitoring
 Anti-Spyware  Personal Firewall
 Anti-Virus  System Tools
 Online Privacy    
PQ DVD to iPod Video Suite
PQ DVD to iPod Video Suite (PQ DVD to iPod + iPod Video Converter) is a One-Click, All-In-One solution to convert DVD, Tivo, DivX, MPEG, WMV, AVI, RealMedia and many more to iPod Video ...
Kaspersky Internet Security
Internet Security processes all incoming and outgoing data on your computer, including email, Internet traffic and network interaction, without the need for additional security applications ...
Cucusoft MPEG/AVI to DVD/VCD/SVCD Converter Pro
It enables you to convert and burn any video file directly to VCD, DVD, SVCD, MPEG1 and MPEG2 format. Pro version included all the features of the lite version ...
FREE Spyware Scan! SpyNoMore
SpyNoMore scans, cleans and blocks spyware as well as any other good anti-spyware product, but with one big advantage, Custom Fix (patent pending). Spyware programs are growing more sophisticated by the day ...
Copyright ©2003-2009 SecureMost.com. All other trademarks are the sole property of their respective owners.