PDA

View Full Version : As Intended: CoolWWWSearch false positive?



voltra
2008-12-31, 18:04
Hi, just scanned after updating and Spybot found this:

--- Report generated: 2008-12-31 12:48 ---

Hint of the Day: Click the bar at the right of this to see more information! ()


CoolWWWSearch: [SBI $7281762E] IE Search page (Registry change, nothing done)
HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Main\Search Page=about:blank

CoolWWWSearch: [SBI $7281762E] IE Search page (Registry change, nothing done)
HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Main\Search Bar=about:blank


--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-08-11 unins000.exe (51.49.0.0)
2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 Update.exe (1.6.0.7)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDShred.exe (1.0.2.3)
2008-10-22 advcheck.dll (1.6.2.13)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-14 DelZip179.dll (1.79.11.1)
2007-04-02 aports.dll (2.1.0.0)
2008-06-19 sqlite3.dll
2008-10-22 TOOLS.DLL (2.1.6.8)
2008-06-03 Includes\Cookies.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-09-02 Includes\Dialer.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-12-09 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-16 Includes\PUPS.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-12-10 Includes\Spyware.sbi (*)
2008-11-04 Includes\Adware.sbi (*)
2008-12-29 Includes\TrojansC.sbi (*)
2008-12-29 Includes\Trojans.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-12-29 Includes\SecurityC.sbi (*)
2008-12-16 Includes\PUPSC.sbi (*)
2008-12-29 Includes\MalwareC.sbi (*)
2008-12-22 Includes\KeyloggersC.sbi (*)
2008-12-22 Includes\HijackersC.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-12-29 Includes\AdwareC.sbi (*)
2008-12-10 Includes\SpywareC.sbi (*)
2007-12-24 Plugins\TCPIPAddress.dll
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll



I was clean a couple of days ago with last week's database, and I haven't really done anything since then so I was wondering if these are false positives. I'm using Windows ME.

voltra
2009-01-03, 16:51
I uninstalled some Yahoo! stuff before this happened, including a tool bar IIRC. Could that be causing this detection?

voltra
2009-01-03, 17:32
Also, in Spybot the registry entries also say (is not) next to them. So they actually look like this:

HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Main\Search Page=about:blank (is not)

HKEY_USERS.DEFAULT\Software\Microsoft\Internet Explorer\Main\Search Bar=about:blank (is not)

Not sure why the log I posted earlier doesn't say that. Sorry for posting again, couldn't edit the older posts.

Yodama
2009-01-05, 07:41
hello,

SBI $7281762E tells me that your search sites are directed to

couldnotfind.com
which belongs to Integrated Search Technologies which is a known hijacker.
You should fix this issue.

voltra
2009-01-08, 20:00
Not sure how I got that, but I'll go ahead and fix it. Thanks for the help.