CWS.Olehelp
  • Résumé : CoolWebSearch - Variante CWS.Olehelp - Ensemble de hijackers d'un gang maffieux renvoyant vers le site coolwebsearch ou vers ses affiliés.
 
  • Mots-clés : CoolWebSearch, coolwwwsearch, cws, hijack, hijacker, hijacking, keymgr3.inf, drvupd.inf, svchost32.exe, astctl32.ocx, mswsc10.dll, msinfo.exe, ctfmon.exe, dnsrelay.dll, AddClass, AFF.IEDLL, AFF.MadFinder, AFF.WinShow, AlFaSearch, Bootconf, Ctfmon32, DataNotary, DNSRelay, Dnsrelay.2, Dnsrelay.3, DReplace, GoogleMS, IEFeats, LoadBAT, MSConfd, MSInfo, MSOffice, Msspi, MUpdate, OEMSysPNP, Oemsyspnp.2, Oemsyspnp.3, OSLogo, QTTasks, Svchost32, Svcinit, TapiCFG, TheRealSearch, Vrape, XPlugin, Aff.iedll, Aff.Winshow, Aff.Madfinder, Aff.Tooncomics

    get rid of, uninstall, remove, removal, suppression, effacer, effacement, supprimer, virer, détruire, désinstaller, désinstallation


CWS.Olehelp
 


CoolWebSearch - Variante CWS.Olehelp


De quoi s'agit-il ?
Ce parasite est une variante d'une famille de Hijackers furieux appelée CoolWebSearch et pilotée par un gang maffieux s'introduisant dans tous les ordinateurs.

Discussion générale et éradication des différentes variantes du hijacker CoolWebSearch:


Voir la fiche générale CoolWebSearch


Travaux originaux de Merijn (acquis pas Intermute le 19 Octobre 2004)
Révisions (18.10.2003 - Rév 1; 27.10.2003 - Rév 2; 12.11.2003 - Rév 3; 19.12.2003 - Rev 4; 17.01.2004 - Rev 5; 11.02.2004 - Rev 6; 7.4.2004 - Rev 7; 20.05.2004 - Rev 8)




CWS.Olehelp

Variant 25: CWS.Olehelp - Who wants some bookmarks?

Approx date first sighted: January 4, 2004
Log reference: http://forums.spywareinfo.com/index.php?showtopic=27573
Symptoms: IE hijacked to omega-search.com, lots and lots of bookmarks added to IE Favorites
Cleverness: 3/10
Manual removal difficulty: Involves a little bit of Registry editing, and deleting lots of files
Identifying lines in HijackThis log:
Running processes:
C:\WINDOWS\OLEHELP.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.omega-search.com/go/panel_search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.omega-search.com/go panel_search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.omega-search.com/go/panel_search.html
O4 - HKCU\..\Run: [olehelp] C:\WINDOWS\olehelp.exe
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\olehelp.exe

This variant is pretty simple. It autoruns a file named olehelp.exe at startup from the Registry, which changes the IE homepage/search page to omega-search.com, and adds a mind-boggling 107 bookmarks to the IE Favorites, of which 14 are porn.

Killing the autostart and deleting the file + bookmarks fixes this.

Rédigé en écoutant Ecoute