• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
thoneter

Another CWS victim

4 posts in this topic

It's been 4 days of trying to remove CWS. I've followed a few of the other posts and the fixes offered have not worked for me! I'm running spysweeper, spybot S&D and adaware. All of them are current on apps and defs. Adaware detects the cws and removes but it keeps coming back. I had spyhunter loaded but from what I've read it loads spyware.

 

I will reboot and wait for a response! I have HJT logs but what I've seen posted the log files are no good after you've rebooted with the CWS spyware. Thanks for forum. And like everyone else I will grovel and beg for your assistence! Terry

Share this post


Link to post
Share on other sites

Hello thoneter,

I may not be a great assistance yet but I can help with your CWS problem. Download CWShredder from this page, extract it, and run it. It should kill all forms of the CWS virus. After this is done post a HJT log and wait for a helper to come assist.

Share this post


Link to post
Share on other sites

Thanks for trying! I've already ran shredder and it found nothing to remove. I'd already ran adaware, spybot and spysweeper b4 I ran shredder. This CWS is a persistent little bugger! TT

Share this post


Link to post
Share on other sites

The following is the HJT log!

 

"Logfile of HijackThis v1.97.7

Scan saved at 9:36:40 AM, on 6/25/2004

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\atievxx.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe

C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE

C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe

C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\regedit.exe

C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.EXE

C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe

D:\Download\SpyWare\HijackThis.exe

C:\Program Files\Messenger\msmsgs.exe

 

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe

O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\SpyHunter\PopupBlocker\EnigmaPopupStop.exe

O4 - HKCU\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...flash.cab"

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0