Unsolved

This post is more than 5 years old

6 Posts

7376

July 21st, 2004 18:00

CWS Exploit fix attempted, Windows is still sick

Thanks for any help!

I have run HJT and the repair tool given from MajorGeeks after having been diagnosed with CWS Exploit by pskelly. I have posted my HJT log that I just ran herein so you can see what is still there.

Continuing symptoms:  When I launch a Microsoft software application the Windows Installer wizard starts up and attempts to re-install Microsoft XP Small Business. I have to click Cancel to allow the program to launch. My operations have slowed to a crawl ( opening a new file or running a program).  My internet access is restored to previous function and email is all working fine now. I no longer show symptoms of a browser hijack.

 Is there more stuff to delete using HJT? I only deleted the files that referenced dll. file as instructed.

HJT log :

Logfile of HijackThis v1.98.0
Scan saved at 12:18:11 PM, on 7/21/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Canon\VDC\AuVdc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\HPJETDSC.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Symantec\ACT\SideACT.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Symantec\ACT\act.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\MsiExec.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [HP JetDiscovery] HPJETDSC.EXE
O4 - Startup: SideACT!.lnk = C:\Program Files\Symantec\ACT\SideACT.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

 

Many, many thanks!

Canuck

933 Posts

July 21st, 2004 21:00

Hi Canuck, Please return to the thread you started, don't begin a new thread for the same problem.  I have asked the resident expert to look at your log today for final advice and he will be looking in that thread.  Please post this log in that thread.

(another thread running, please do not respond to this thread)

0 events found

No Events found!

Top