I went to a website, and got all sorts of spyware. I got rid of most of it, but when I go to access my Media Player, it comes up with an install for something called CHILK CHAT (I think I spelled that right).

I have to stop the installation process for my computer to still function.

Plus I am still getting popups.

Ideas?

Dani AI

Generated

Good, practical starting advice from . The following expands on that with targeted, hands‑on checks to find what actually spawns the "CHILK CHAT" installer when Windows Media Player is opened, and safe ways to remove it.

First, isolate and stop any further downloads. Unplug the machine from the network (or disable the NIC). Do not accept or run the installer dialog. Boot the PC into Safe Mode (no networking) so fewer things are running. Use a known-clean machine to fetch removal tools or rescue media if needed—do not download suspect executables on the infected box.

Next, identify the process that launches the installer. Run a process/handle viewer (for example, a Sysinternals tool) before opening Media Player. When the install dialog appears, use the tool’s window-target or process tree to find the exact process that created that window and note the full file path. That tells whether the trigger is WMP itself, an IE/ActiveX component, or another helper process.

Check these places (carefully): the Downloaded Program Files folder (%windir%\Downloaded Program Files) and Internet Explorer’s list of installed controls/add‑ons for recently added items; the usual startup locations (HKLM and HKCU Run keys and the Startup folder); scheduled tasks and the Hosts file (C:\Windows\System32\drivers\etc\hosts). Remove or unregister only items you can identify as malicious; if unsure, quarantine them and get a second opinion.

If the installer is tied to Media Player itself, repair or reinstall WMP (use Windows Add/Remove Components or the appropriate Microsoft repair procedure for your OS), then reset file associations and rebuild the Winsock/stack if network redirection persists. After cleaning, install all Windows updates, update AV/anti‑malware signatures, change important passwords, and create a fresh System Restore point. If the infection resists removal, consider scanning from a trusted rescue CD or doing a clean OS install.

When posting follow‑up, include the exact installer window title/text, the process name and full path that spawned it, and a short list of suspicious Startup/Downloaded items.

Recommended Answers

All 2 Replies

Cannot reply as I have logged off!

Just joking :evil:

Download CWShredder from here & run it. Select the fix button & it will fix everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including Iinternet Explorer, before running CWShredder. Reboot.

To help prevent this from happening again, install the patches for the vulnerabilities that this hijacker exploits by going here for your critical updates.

Download & instal Adaware from here
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot

Download & instal Spybot S&D from here. Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot

See if those help, if not, Download HijackThis from here & unzip it into it's own, permanent folder, (Not a temporary folder or the desktop & not directly on your hard drive).
If you have anything disabled in MsConfig, please re-enable it/them.
Start HJT & with all browser windows closed, press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file, copy the entire contents of the text file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.