Welcome Guest ( Log In | Register )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide.
      
 
Reply to this topicStart new topic
How to remove the coolpics.com hijacker
Metallica
post Nov 5 2006, 01:47 PM
Post #1


Spyware Veteran
Group Icon
Posts: 19,461
From: Netherlands
OS: XP Pro & Vista Ultimate



1. Download this file - ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

If you find one of these lines in the resulting log:
"DisableRegistryTools"=dword:00000001
"DisableTaskMgr"=dword:00000001

under the header:
[HKCU\software\microsoft\windows\currentversion\policies\system]

Then download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C: ) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Coolpics Remover.
Save it in the same folder you made earlier (c:\BFU).

Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon and select coolpics.bfu
  • Press Execute and let it do it's job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot your computer and check if it worked.

This post has been edited by Metallica: Oct 21 2007, 05:54 AM
Reason for edit: ComboFix link updated - thanks tetonbob
Go to the top of the page
 
+Quote Post
admin
post Jul 12 2007, 04:19 PM
Post #2


Site Administrator
Group Icon
Posts: 16,831
From: 127.0.0.1
OS: Windows Vista Ultimate



This topic has been left open to allow specific questions and comments related ONLY to this guide. It's NOT for posting HJT logs, links to your logs, or any other general malware help. Replies not following these rules will be deleted. Thanks for your cooperation.
Go to the top of the page
 
+Quote Post
tetonbob
post Aug 11 2007, 10:26 AM
Post #3


Malware Expert
Group Icon
Posts: 127
OS: XP Pro, XP Home, Windows 2000



Was just doing some reading, and noticed something...

Link to ComboFix 404's, it's changed a while back. Current CF links are:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

They are case sensitive.

This post has been edited by tetonbob: Aug 11 2007, 10:28 AM
Go to the top of the page
 
+Quote Post
maayongadlaw
post Sep 30 2007, 03:22 AM
Post #4


New Member
*
Posts: 1
OS: windows XP



Thanx to metallica's instruction, i was able to remove coolpics virus in my computer. it really annoys me everytime i open my yahoo messenger. By the way my friends computer is infected by a virus which is similar to coolpics. It also disables his taskmanager and pops a weird characters in his Yahoo Messenger which looks like this  and so on followed by freewebtown.com instead of coolpics.com. My question is can BFU removed this kind of thing on my friends computer? Can I apply metallica's instruction to remove this kind of virus. Please help us with our problem. Thanx and sorry for my english!! tongue.gif
Go to the top of the page
 
+Quote Post
RatHat
post Sep 30 2007, 03:44 AM
Post #5


GeekU Mod
Group Icon
Posts: 4,282
From: Lake Mabprachan, Thailand
OS: XP SP2 ~ Vista Ultimate



maayongadlaw,

Please have your friend read this post then post a HijackThis Log in the Malware Forum.

Ask him/her to title the post Coolpics Clone? and I will keep an eye out for it.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts  
2 / 1,390 1st March 2006 - 04:03 PM
erlindosi started - last by Buckeye_Sam
No New Posts  
0 / 347 6th June 2006 - 04:31 PM
chicken_little started - last by chicken_little
No New Posts  
8 / 1,272 16th July 2006 - 04:48 AM
rickkay started - last by Rawe
No New Posts  
1 / 306 22nd February 2007 - 08:17 PM
whatismouse started - last by Piper
No New Posts  
1 / 925 19th April 2007 - 03:29 AM
indianpunk started - last by indianpunk

RSS Time is now: 21st August 2008 - 05:40 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.