OK guys, here 's how I fixed it. It's been 3 days now since I haven't seen the Coolsearch page back. I think it's safe to say that I got rid of these motherf*ckers. I am pretty proud of me especially since as you will see or already know I am far from being an expert in computing rather the opposite, an " if ain't broken don't fix it" kind of guy who usually only downloads updates when forced to ahaha... I was lucky enough not to get one of the nastier strains that constantly display pop ups and slow down your machine to a crawl.
Now I just wish the FBI would take care of the scumbags behind this.
But let's get to the meat. Again this experience is a good example of how breakthroughs can happen just when you are about to give up and throw in the towel. I had followed the Symantec instructions and followed the advice given on the Dell website but still the spyware would reload itself the next day . Even if upon reboot it appeared to have disappeared. I was pretty much resigned to living with it or reformat , a pretty grim prospect since I still have no idea of how to reformat a HD. I nonetheless kept searching for clues on Google.
This is when I came about a post making mention of the values in HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Styles
"User Stylesheet"="%Windir%\Web\tips.ini"
the program points to that file, which cannot be found. The Symantec instructions are to delete this value. The poster as far as I understand advised to delete the file itself too "tips.ini". I could not find that but send all the tips file in the bin :eek: :eek: But I don't think that file was the culprit.
I think the breakthrough came when I read about the file soundmx.exe that some say is used by the program to reload itself. When searching for soundmx.exe the results were all Hijack this logs from people infected with adware searchcounter. I too happen to have this program in my start up items and did not recall ever seeing it before. What a coincidence. So I unchecked it too.
Symantec also mentions HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer
"ReconfLast"=dword:07D30C01
as one of the registry entries altered by the program . But they don't say what to do with it. I tried to delete the values but it would not let me do it so I added a digit to the series. Heck who knows ?
I also had 3 Active X controls files in IE temp files, status and dates of creation unknown. All the legit files have that info so I got rid of those too. It's probably unrelated but worth a look at.
So I started first by cleaning cache and history, deleted the host file line (see Symantec instructions) then changed all the altered values in the registry deleting the fntldr.exe, Coolsearch and adware search counter files in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU
then followed with the above.
Hopefully this should provide some clues if you have the misfortune to be infected. I am not sure what did it , IMO the soundmx.exe file. I am trying to find a way to completely erase it from my machine as it is still on my startup list but unchecked. I am concerned some more hidden components could still be affecting my system though. I had 2 weird crashes in 3 days so maybe I will run Spy bot and more likely than not DL MS updates.