# How to get rid of Coolweb trojan

**URL:** <https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343>\
**Category:** Factual Questions\
**Created:** [September 19, 2005, 11:38am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343 "2005-09-19T11:38:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cosmosdan](https://avatars.discourse-cdn.com/v4/letter/c/a6a055/32.png) [@cosmosdan](https://boards.straightdope.com/u/cosmosdan)\
**Post date:** [September 19, 2005, 11:38am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/1 "2005-09-19T11:38:45Z")

</div>

I have got a version of the Coolweb trojan that I can’t get rid of. I’ve tried CWshredder and several other recommended spyware removers. I can’t use Internet explorer and useing Firefox for the moment. Whenever I click a link in Outlook it tries to use IE. Opens for a secound and begins to load and then closes. Macafee then gives me a message that says \*\*Windows/eacdf/dll \*\* was infected with **Startpage-DU.dll** trojan and was deleted. I’ve tried several programs from safe mode. Still there. Ewido Security suite finds it in my registry but cannot remove it.  
Any help appreciated.

---

<div class="post-metadata">

**Author:** ![Dragwyr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dragwyr/32/2855_2.png) [@Dragwyr](https://boards.straightdope.com/u/Dragwyr)\
**Post date:** [September 19, 2005, 11:44am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/2 "2005-09-19T11:44:33Z")

</div>

> [@cosmosdan](#):
>
> I have got a version of the Coolweb trojan that I can’t get rid of. I’ve tried CWshredder and several other recommended spyware removers. I can’t use Internet explorer and useing Firefox for the moment. Whenever I click a link in Outlook it tries to use IE. Opens for a secound and begins to load and then closes. Macafee then gives me a message that says \*\*Windows/eacdf/dll \*\* was infected with **Startpage-DU.dll** trojan and was deleted. I’ve tried several programs from safe mode. Still there. Ewido Security suite finds it in my registry but cannot remove it.  
> Any help appreciated.

Download [cwshredder](http://www.intermute.com/spysubtract/cwshredder_download.html).

---

<div class="post-metadata">

**Author:** ![Dragwyr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dragwyr/32/2855_2.png) [@Dragwyr](https://boards.straightdope.com/u/Dragwyr)\
**Post date:** [September 19, 2005, 11:46am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/3 "2005-09-19T11:46:34Z")

</div>

My mistake. I neglected to see that you already tried cwshredder. I guess my next suggestion would be to make sure you have the latest version of cwshredder as that trojan keeps mutating and older versions of cwshredder don’t work on the new varients.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [September 19, 2005, 12:09pm UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/4 "2005-09-19T12:09:33Z")

</div>

For persistent sopyware infections, download [HijackThis](http://www.spywareinfo.com/~merijn/files/hijackthis.zip), unzip it to a folder (other than the temporary internet folder), scan and post the log in a new thread at the [Malware Removal forum at SpywareInfo.com](http://forums.spywareinfo.com/index.php?showforum=18) . They’ve got some crackerjack advisors that can walk you through the removal process.

---

<div class="post-metadata">

**Author:** ![Patty\_O\_Furniture](https://avatars.discourse-cdn.com/v4/letter/p/96bed5/32.png) [@Patty\_O\_Furniture](https://boards.straightdope.com/u/Patty_O_Furniture)\
**Post date:** [September 19, 2005, 3:13pm UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/5 "2005-09-19T15:13:56Z")

</div>

Remember to temporarily disable Windows System Restore before running the shredder or the next time you reboot, Windows will restore the files deleted by the shredder.

---

<div class="post-metadata">

**Author:** ![samclem](https://avatars.discourse-cdn.com/v4/letter/s/a9a28c/32.png) [@samclem](https://boards.straightdope.com/u/samclem)\
**Post date:** [September 20, 2005, 12:10am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/6 "2005-09-20T00:10:44Z")

</div>

Without trying to sound like I’m shilling for something, I’m one of those wussies who decided to buy a program to do what can be done for free if one were so inclined.

I bought Pest Patrol when I had a browser hijacker that neither spybot nor adaware could get rid of. But $35 seemed reasonable to me.

After running both adaware and spybot, I ran my Pest Patrol, figuring it might help rid me of the one item I was interested in.

Wow! They found about 35 entries that were on my machine that were NOT found by either spybot or adaware.

While they didn’t get rid of the browser hijacker on the first run, (it was very new), they did in about a week.

Again, the advice you’ve been given by others in earlier posts are great. I’m just telling you about my experience if you’ve got the $35 or so to spend.

With kids in my house on the computer, it saves me a lot of grief.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [September 20, 2005, 12:24am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/7 "2005-09-20T00:24:36Z")

</div>

I’m a cheapskate, so I’d try Panda Activescan (an online virus scanner) - it also scans for other kinds of malware now; between Panda Activescan, Grisoft AVG, Trend Housecall, CWShredder, Hijackthis and Spybot (and also not forgetting occasional use of Safe Mode), I’ve not yet encountered an infection that I couldn’t eventually fix.

I’ve seen some really devious ones that consist of paired processes; either one of which will immediately resurrect the other if you use task manager to kill it. Running a selective startup might be necessary to get booted into a system where they aren’t actually running, so you can delete them.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 20, 2005, 12:28am UTC](https://boards.straightdope.com/t/how-to-get-rid-of-coolweb-trojan/322343/8 "2005-09-20T00:28:12Z")

</div>

Be sure to run CWShredder in Safe Mode. Some versions of CWS will reinfect under normal mode.
