Jump to content


Problem removing CWS

  • Please log in to reply
1 reply to this topic

#1 seetha



  • Full Member
  • Pip
  • 3 posts

Posted 30 July 2004 - 06:04 AM

Hi all

im new here, and my machine seems to be infected with kinda some smart bug or something..Please help me outta this

let me try to give the full picture...

I've got Spybot S&D, spysweeper, Xoftspy AND pestpatrol installed...on top of ZA Security suite (talk about paranoia !!)...but seriously, there were SO many bugs in my pc…and I kept installin newer & newer spyware-removal appz in the hope I would get rid of them…

Problem is….I can see and feel my machine acting strange, but the spyware-removal appz don’t pick up any bugs..OR if they did pick up, they fail to remove them.

By “actin & feelin STRANGE”, I mean things like this – my quick-launch bar keeps disappearing repeatedly and the different shortcuts I have on my quick-launch bar gets re-arranged alphabetically…(Like, the “show desktop” button doesn’t stay as the left most…AND programs running in the system tray disappear too (Spybot resident, for eg)…

When I run a full scan with these spyware-removal appz, Xoftspy keeps picking up these two CWS variants – CWS.Aff.winshow and CWS.Mupdate…it tries to remove them, says they have been removed, but the next time I run a scan, the same two show up….

I tried the CWS shredder and it cleaned my machine…and it says my machine is clean…still Xoftspy keeps picking the two variants…another instance is the Spybot S&D scan picks up a “DSO Exploit” and fixes it…only to pop back on the next scan…I don’t know if these two are related or different infections…

I’ve tried the latest versions of all the appz involved, still the bugs remain…I even tried a coupla online scanners…(pc pitstop and the like) and somehow I feel the spyware-removal appz themselves are the spyware…or something, I don’t know what im talking about :-)

From what I read from other posts I understand the “Hijack this” log would be very useful in figurin out what the problem is…so, herewith I’ve attached my hijack this log….

BTW, I was checkin the “netstat” cmd in the “Run” dialog and FOUR of my TCP ports seems to have a connection established with coolwebsearch.com !!! ..the cmd window shows this :

“ D:\Documents and Settings\Seetha>netstat -o

Active Connections

Proto Local Address Foreign Address State PID

TCP bluebox:1026 coolwwwsearch.com:3006 ESTABLISHED 1288
TCP bluebox:1027 coolwwwsearch.com:3005 ESTABLISHED 1288
TCP bluebox:3005 coolwwwsearch.com:1027 ESTABLISHED 1520
TCP bluebox:3006 coolwwwsearch.com:1026 ESTABLISHED 1520 ”

(bluebox is my machine)

Is this info of any use ??

Anyways…here is my HIJACK THIS log file

Logfile of HijackThis v1.98.0
Scan saved at 4:25:36 PM, on 7/30/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\RConnect\RConnectDialer.exe
C:\S O U R C E\E X E\R E M O V A L\HijackThis\HijackThis

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vivisimo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://vivisimo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = vivisimo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = B O O M S H A N K A R
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - e:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: FCBHOBHO Class - {8B3868B4-EBA8-48FA-A19B-E1DFB99066FA} - e:\Program Files\FlashCapture\fcbho.dll
O3 - Toolbar: Vivisimo - {5538fb62-f725-4433-a965-91314e8d8e4d} - e:\Program Files\Vivisimo\Toolbar\toolbar1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - e:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CoolSwitch] D:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [PPMemCheck] E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] E:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "e:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Download with &DAP - E:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Vivisimo Meta-Search - res://e:\Program Files\Vivisimo\Toolbar\toolbar1.dll/SEARCH.HTML
O8 - Extra context menu item: Customize Menu &4 - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all with DAP - E:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms &] - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save F&lash with FlashCapture - res://e:\Program Files\FlashCapture\fciext.dll/FCIEXT.htm
O8 - Extra context menu item: Save Forms &[ - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://e:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://e:\Program Files\FlashCapture\fciext.dll/FCIEXT.htm (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} -
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} -
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zone...ee/cm/ICSCM.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab


Thank u guys


#2 cnm


    Mother Lion of SWI

  • Administrators
  • PipPipPipPipPip
  • 25,317 posts

Posted 07 August 2004 - 10:52 AM

Are you still having this problem? Sorry we didn't get to it sooner.
Make sure your Spybot S&D is updated (update 07/28/04) and then run a Search for Problems.

You apparently may have a CoolWebSearch infection, although I see no sign of it in your log.

Download Ad-aware from: http://www.lavasoft.de/res/aaw6.exe

Install the program and launch it.

First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.

Next, we need to configure Ad-aware for a full scan.

Posted Image Click on the Gear icon (second from the left) to access the preferences/settings window
  • In the General window make sure the following are selected:
    • Automatically save log-file
    • Automatically quarantine objects prior to removal
    • Safe Mode (always request confirmation)
  • Click on the Scanning button on the left and select :
    • Scan Within Archives
    • Scan Active Processes
    • Scan Registry
    • Deep Scan Registry
    • Scan my IE favorites for banned URL’s
    • Scan my Hosts file
    • Under Click here to select drives + folders, choose:
    • All of your hard drives
Posted Image Click on the Advanced button on the left and select:
  • Include additional process information
  • Include additional file information
  • Include environment information
  • Include additional object details
Posted Image Click the Tweak button and select:
  • Under the Scanning Engine:
    • Unload recognized processes during scanning
    • Include basic Ad-aware settings in logfile
    • Include additional Ad-aware settings in logfile
  • Under the Cleaning Engine:
    • Let Windows remove files in use at next reboot
Posted Image Click on Proceed to save the settings.

Posted Image Click Start and on the next screen choose Activate in-depth Scan at the bottom of the page, and then choose:
  • Use Custom Scanning Options
Posted Image Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.

Posted Image Save the log file when it asks and then click Finish

Posted Image When finished, mark everything for removal and get rid of it. (Right-click the window and choose Select All from the drop down menu and click Next).

Posted Image Reboot your computer.

Get the latest HijackThis (1.98.1) and post another log.
Microsoft MVP Windows Security 2005-2006
How camest thou in this pickle? -- William Shakespeare:(1564-1616)
The various helper groups here

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of

Support SpywareInfo Forum - click the button
PayPal - The safer, easier way to pay online!