• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
seetha

Problem removing CWS

2 posts in this topic

Hi all

 

im new here, and my machine seems to be infected with kinda some smart bug or something..Please help me outta this

 

let me try to give the full picture...

 

I've got Spybot S&D, spysweeper, Xoftspy AND pestpatrol installed...on top of ZA Security suite (talk about paranoia !!)...but seriously, there were SO many bugs in my pc…and I kept installin newer & newer spyware-removal appz in the hope I would get rid of them…

 

Problem is….I can see and feel my machine acting strange, but the spyware-removal appz don’t pick up any bugs..OR if they did pick up, they fail to remove them.

 

By “actin & feelin STRANGE”, I mean things like this – my quick-launch bar keeps disappearing repeatedly and the different shortcuts I have on my quick-launch bar gets re-arranged alphabetically…(Like, the “show desktop” button doesn’t stay as the left most…AND programs running in the system tray disappear too (Spybot resident, for eg)…

 

When I run a full scan with these spyware-removal appz, Xoftspy keeps picking up these two CWS variants – CWS.Aff.winshow and CWS.Mupdate…it tries to remove them, says they have been removed, but the next time I run a scan, the same two show up….

 

I tried the CWS shredder and it cleaned my machine…and it says my machine is clean…still Xoftspy keeps picking the two variants…another instance is the Spybot S&D scan picks up a “DSO Exploit” and fixes it…only to pop back on the next scan…I don’t know if these two are related or different infections…

 

I’ve tried the latest versions of all the appz involved, still the bugs remain…I even tried a coupla online scanners…(pc pitstop and the like) and somehow I feel the spyware-removal appz themselves are the spyware…or something, I don’t know what im talking about :-)

 

From what I read from other posts I understand the “Hijack this” log would be very useful in figurin out what the problem is…so, herewith I’ve attached my hijack this log….

 

BTW, I was checkin the “netstat” cmd in the “Run” dialog and FOUR of my TCP ports seems to have a connection established with coolwebsearch.com !!! ..the cmd window shows this :

 

“ D:\Documents and Settings\Seetha>netstat -o

 

Active Connections

 

Proto Local Address Foreign Address State PID

 

TCP bluebox:1026 coolwwwsearch.com:3006 ESTABLISHED 1288

TCP bluebox:1027 coolwwwsearch.com:3005 ESTABLISHED 1288

TCP bluebox:3005 coolwwwsearch.com:1027 ESTABLISHED 1520

TCP bluebox:3006 coolwwwsearch.com:1026 ESTABLISHED 1520 ”

 

(bluebox is my machine)

 

 

Is this info of any use ??

 

Anyways…here is my HIJACK THIS log file

 

 

Logfile of HijackThis v1.98.0

Scan saved at 4:25:36 PM, on 7/30/2004

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

D:\WINDOWS\System32\smss.exe

D:\WINDOWS\system32\csrss.exe

D:\WINDOWS\system32\winlogon.exe

D:\WINDOWS\system32\services.exe

D:\WINDOWS\system32\lsass.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\system32\spoolsv.exe

D:\WINDOWS\System32\alg.exe

D:\WINDOWS\System32\ZoneLabs\isafe.exe

D:\WINDOWS\System32\cisvc.exe

D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\system32\ZONELABS\vsmon.exe

D:\WINDOWS\System32\hkcmd.exe

D:\WINDOWS\System32\taskswitch.exe

E:\PROGRA~1\PESTPA~1\PPMemCheck.exe

E:\PROGRA~1\PESTPA~1\PPControl.exe

E:\PROGRA~1\PESTPA~1\CookiePatrol.exe

E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

D:\WINDOWS\System32\cidaemon.exe

D:\WINDOWS\System32\taskmgr.exe

D:\WINDOWS\System32\cidaemon.exe

D:\WINDOWS\explorer.exe

D:\Program Files\RConnect\RConnectDialer.exe

C:\S O U R C E\E X E\R E M O V A L\HijackThis\HijackThis 1.98.0.0.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vivisimo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://vivisimo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = vivisimo.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = B O O M S H A N K A R

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - e:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll

O2 - BHO: FCBHOBHO Class - {8B3868B4-EBA8-48FA-A19B-E1DFB99066FA} - e:\Program Files\FlashCapture\fcbho.dll

O3 - Toolbar: Vivisimo - {5538fb62-f725-4433-a965-91314e8d8e4d} - e:\Program Files\Vivisimo\Toolbar\toolbar1.dll

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - e:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll

O4 - HKLM\..\Run: [igfxTray] D:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [CoolSwitch] D:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [PPMemCheck] E:\PROGRA~1\PESTPA~1\PPMemCheck.exe

O4 - HKLM\..\Run: [PestPatrol Control Center] E:\PROGRA~1\PESTPA~1\PPControl.exe

O4 - HKLM\..\Run: [CookiePatrol] E:\PROGRA~1\PESTPA~1\CookiePatrol.exe

O4 - HKLM\..\Run: [Zone Labs Client] "e:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O8 - Extra context menu item: &Download with &DAP - E:\PROGRA~1\DAP\dapextie.htm

O8 - Extra context menu item: &Vivisimo Meta-Search - res://e:\Program Files\Vivisimo\Toolbar\toolbar1.dll/SEARCH.HTML

O8 - Extra context menu item: Customize Menu &4 - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

O8 - Extra context menu item: Download &all with DAP - E:\PROGRA~1\DAP\dapextie2.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Fill Forms &] - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O8 - Extra context menu item: Save F&lash with FlashCapture - res://e:\Program Files\FlashCapture\fciext.dll/FCIEXT.htm

O8 - Extra context menu item: Save Forms &[ - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://e:\Program Files\FlashCapture\fciext.dll/FCIEXT.htm (file missing)

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\Program Files\Messenger\MSMSGS.EXE

O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} -

O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} -

O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -

O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab

 

PLEASE LET ME KNOW WHAT IS WRONG WITH MY MACHINE AND HOW TO FIX IT….

 

 

Thank u guys

 

 

seetha

Share this post


Link to post
Share on other sites

Are you still having this problem? Sorry we didn't get to it sooner.

Make sure your Spybot S&D is updated (update 07/28/04) and then run a Search for Problems.

 

You apparently may have a CoolWebSearch infection, although I see no sign of it in your log.

 

Download Ad-aware from: http://www.lavasoft.de/res/aaw6.exe

 

Install the program and launch it.

 

First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.

 

Next, we need to configure Ad-aware for a full scan.

 

icon11.gif Click on the Gear icon (second from the left) to access the preferences/settings window

  • In the General window make sure the following are selected:
    • Automatically save log-file
    • Automatically quarantine objects prior to removal
    • Safe Mode (always request confirmation)

    [*]Click on the Scanning button on the left and select :

    • Scan Within Archives
    • Scan Active Processes
    • Scan Registry
    • Deep Scan Registry
    • Scan my IE favorites for banned URL’s
    • Scan my Hosts file
    • Under Click here to select drives + folders, choose:
      • All of your hard drives

icon11.gif Click on the Advanced button on the left and select:

  • Include additional process information
  • Include additional file information
  • Include environment information
  • Include additional object details

icon11.gif Click the Tweak button and select:

  • Under the Scanning Engine:
    • Unload recognized processes during scanning
    • Include basic Ad-aware settings in logfile
    • Include additional Ad-aware settings in logfile

    [*]Under the Cleaning Engine:

    • Let Windows remove files in use at next reboot

icon11.gif Click on Proceed to save the settings.

 

icon11.gif Click Start and on the next screen choose Activate in-depth Scan at the bottom of the page, and then choose:

  • Use Custom Scanning Options

icon11.gif Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.

 

icon11.gif Save the log file when it asks and then click Finish

 

icon11.gif When finished, mark everything for removal and get rid of it. (Right-click the window and choose Select All from the drop down menu and click Next).

 

icon11.gifReboot your computer.

 

Get the latest HijackThis (1.98.1) and post another log.

http://www.downloads.subratam.org/hijackthis.zip

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0