Unsolved
This post is more than 5 years old
12 Posts
0
8474
June 26th, 2004 07:00
CWS Hijack too /index.html#96676
cws hijack malware coolwebsearch got me too... tried it all delete cookies, history, nortons anti virus, msn software updates, ad ware, spybot, trojanhunter, hijackthis, manual regedit from ad ware plus SAFE MODE.... no go didn't stop this beast, seems to look okay on the first opening of IE but default broswer changes right back or after restarting computer... starting in SAFE MODE seems to stop the beast cws hijack malware coolwebsearch, call all my friends and our collective minds and even an IT tech guy could stop this beast. Will be looking into russelltexas / grinler fix but skimming over it looks confusing and advanced material... thanks for any suggestions dellbuds.
No Events found!


pskelley
933 Posts
0
June 26th, 2004 18:00
Hi freyford, If you would like us to take a look at your computer, we will need you to follow the directions below. Once your log is posted, please be patient. We are all volunteers with families and real jobs, and the logs being posted are many. We do work the logs in the order they come in. One of the experts here will assist you with your log as soon as possible. Thanks...pskelley
We need you to download and install an analysis and repair tool called Hijackthis.
Download the zipped file from here: http://tomcoyote.com/hjt
Or....If you prefer an .exe version (saves a lot of time for novices) download the file from here:
http://209.133.47.12/~merijn/files/HijackThis.exe
Please unzip Hijackthis.zip or move the hijackthis.exe file into a new folder you create in the root (first) level of the C: drive. Name this folder HJT for best and safest results. Don't place it on the Wallpaper, in a temp folder, or in the root level of the C: drive or the My Documents folder. It will create many backup files and they need to be stored in a unique Hijackthis folder. If it is properly placed it will look like this: C:\HJT\HijackThis.exe.
Hijackthis FAQ (Frequently Asked Questions) at: http://russelltexas.com/malware/faqhijackthis.htm
After downloading, and unzipping the hijackthis file into a safe folder you create (preferably a folder named HJT in the first level of the C: drive)...run Hijackthis, click on the 'scan' button and then 'save log' button.
Copy and paste the contents of the text file you save into a reply to this message. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste at http://www.tomcoyote.com/hjt
Special Notice! Hijackthis is a powerful tool that edits the brains of Windows (the Registry). DO NOT FIX anything in the Hijackthis log screen without assistance from the experts! Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system.
Stay in this thread for continuity. Reply to this message.
Thanks,
Pskelley
In Training at TomCoyote.com and Spywareinfo.com
Please be aware only the following DellForum members were trained at
TomCoyote.com and SpywareInfo.com to help with Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.
freyford
12 Posts
0
June 27th, 2004 00:00
Read the new Exploit Repair (manual methods) credit grinler... already had download hijackthis.exe to desktop trying to move it to new folder c:HJT but got a shortcut only.... been working on CWS with ad ware, thanks for the help.. #96676 ? who's is it?
Logfile of HijackThis v1.97.7
Scan saved at 6:28:45 PM, on 6/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\nttk.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\apieq.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\zipdog\Desktop\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {600611F8-A1B0-D89D-8BB5-0210A7FBD6F9} - C:\WINDOWS\system32\syshe.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [apieq.exe] C:\WINDOWS\apieq.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\RunOnce: [iesy32.exe] C:\WINDOWS\iesy32.exe
O4 - HKLM\..\RunOnce: [winmz.exe] C:\WINDOWS\winmz.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {776706AE-CACA-4EA3-93DF-BB83D9259DA9} (MailConfigure Class) - http://supportservices.msn.com/us/oeconfig/MailCfg.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37655.9501388889
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} (MS Investor Ticker) - http://fdl.msn.com/public/investor/v9.5/ticker.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v13/ticker.cab
Message Edited by freyford on 06-26-2004 08:49 PM
Texruss
2 Intern
•
3.4K Posts
0
June 27th, 2004 01:00
>Read the new Exploit Repair (manual methods) credit grinler... already had download hijackthis.exe to desktop trying to move it to new folder c:HJT but got a shortcut only...
Right button click on file, copy...go to new folder and right button paste it in. Delete all other copies.
> been working on CWS with ad ware, thanks for the help.. #96676 ? who's is it?
Who is the author of the CWS exploit? Unknown...many CWS folks are programmers in Russia and Canada.
Continue with Grinler's tutorial....you can also fix check in Hijackthis these Trojans:
O4 - HKLM\..\RunOnce: [iesy32.exe] C:\WINDOWS\iesy32.exe
O4 - HKLM\..\RunOnce: [winmz.exe] C:\WINDOWS\winmz.exe
Reboot to Safe Mode, show Hidden files and delete those files in Windows Explorer.
FAQ 8 and 9 on this page: http://www.russelltexas.com/malware/faqhijackthis.htm
All the best,
Texruss
www.russelltexas.com
Spyware Fighter Wilders Forum
Slyware Warrior Tom Coyote Forum
Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at
TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get
*;-)
Texruss
2 Intern
•
3.4K Posts
0
June 27th, 2004 02:00
Please do not open Internet Explorer during any portion of this process.
Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows
Step 1:
Click on Start, the Control Panel, then Administrative Programs, then Services. Look for a service called Network Security Service. Double click on the that service and click stop. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.
Step 2:
Press control-alt-delete to get into the task manager and end the follow processes if they exist:
apieq.exe
Step 3:
I now need you to delete the following files:
C:\WINDOWS\apieq.exe
C:\WINDOWS\iesy32.exe
C:\WINDOWS\winmz.exe
The file from the services above.
Also delete any files that have the same name as these files but end with a dll. You should see them right next to each other.
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
Step 4:
Then run hijackthis and fix these entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
O4 - HKLM\..\Run: [apieq.exe] C:\WINDOWS\apieq.exe
"
O4 - HKLM\..\RunOnce: [iesy32.exe] C:\WINDOWS\iesy32.exe
O4 - HKLM\..\RunOnce: [winmz.exe] C:\WINDOWS\winmz.exe
Step 5:
In the next step we are going to remove a service that gets installed by this malware. The service will always start with __NS_Service. For the purposes of this step, we will assume that it is called NS_Service_3 but may be called something differently on your computer.
Go to Start>Run and type regedit.
Press enter.
Navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\__NS_Service_3
If __NS_Service_3 exists , right click on it and choose delete from the menu.
Now navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_Service_3
If LEGACY___NS_Service_3
exists then right click on it and choose delete from the menu.
Reboot and post a last log.
HTH,
Texruss
freyford
12 Posts
0
June 27th, 2004 02:00
No problem moved hijackthis into it's own folder c:HJT, deleted desk top version. Not sure what you need for me to delete now, following grinler but I'm not a computer expert... seems like all these files must be deleted? R0 R1 02 04 seem like CWS?
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {600611F8-A1B0-D89D-8BB5-0210A7FBD6F9} - C:\WINDOWS\system32\syshe.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [apieq.exe] C:\WINDOWS\apieq.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\RunOnce: [iesy32.exe] C:\WINDOWS\iesy32.exe
O4 - HKLM\..\RunOnce: [winmz.exe] C:\WINDOWS\winmz.exe
Message Edited by freyford on 06-26-2004 10:10 PM
Texruss
2 Intern
•
3.4K Posts
0
June 27th, 2004 03:00
Yes...you are doing fine...a .dll may not be there. Kill all the files with the red names in any location....red means bad in my posts....green is good. *;-)
Texruss
freyford
12 Posts
0
June 27th, 2004 03:00
WELL HAVE SOME QUESTIONS.... I'M DOING IT BUT... XP PRO. THANK YOU. thank you thank you.
Please do not open Internet Explorer during any portion of this process.
Please make sure that you can view all hidden files. Instructions on how to do this can be found here:
How to see hidden files in Windows DONE
Step 1: DONE
Click on Start, the Control Panel, then Administrative Programs (TOOLS) , then Services. Look for a service called Network Security Service. Double click on the that service and click stop. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below. HAD TO SEARCH C:WINDOWS\NTTK.EXE FOUND DELETED
Step 2: FOUND & DONE
Press control-alt-delete to get into the task manager and end the follow processes if they exist:
apieq.exe
Step 3: ?
now need you to delete the following files:
C:\WINDOWS\apieq.exe DONE
C:\WINDOWS\iesy32.exe COULDN'T FIND BUT FOUND IT AFTER FILE SEARCH IN WINDOWS/PREFETCH IESYS32.EXE-37dzco5f.PF ? RIGHT FILE?
C:\WINDOWS\winmz.exe COULDN'T FIND BUT FOUND IT AFTER FILE SEARCH IN WINDOWS/PREFETCH WINMZ.EXE-OADF7955.pf ? RIGHT FILE?
The file from the services above.
Also delete any files that have the same name as these files but end with a dll. You should see them right next to each other. NONE FOUND
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
Step 4: WAITING ON ABOVE ANSWERS? BUT BELOW " MEANS ALL INBETWEEN ? ONLY ALL THE o4 - HKLM'S ? WHAT ABOUT THE o2 BHO'S ?
Then run hijackthis and fix these entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ovpbc.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ovpbc.dll/sp.html#96676
O4 - HKLM\..\Run: [apieq.exe] C:\WINDOWS\apieq.exe
"
O4 - HKLM\..\RunOnce: [iesy32.exe] C:\WINDOWS\iesy32.exe
O4 - HKLM\..\RunOnce: [winmz.exe] C:\WINDOWS\winmz.exe
Step 5:
In the next step we are going to remove a service that gets installed by this malware. The service will always start with __NS_Service. For the purposes of this step, we will assume that it is called NS_Service_3 but may be called something differently on your computer.
Go to Start>Run and type regedit.
Press enter.
Navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\__NS_Service_3
If __NS_Service_3 exists , right click on it and choose delete from the menu.
Now navigate to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY___NS_Service_3
If LEGACY___NS_Service_3
exists then right click on it and choose delete from the menu.
Reboot and post a last log.
HTH,
Texruss
Message Edited by freyford on 06-26-2004 11:35 PM
Message Edited by freyford on 06-26-2004 11:38 PM
Message Edited by freyford on 06-26-2004 11:42 PM
freyford
12 Posts
0
June 27th, 2004 03:00
Message Edited by freyford on 06-26-2004 11:42 PM
freyford
12 Posts
0
June 27th, 2004 05:00
STEP 3? ABOVE IS THE FILES IN WINDOWS/PREFETCH THE RIGHT ONE(s)?
I've written into your post my questions? Unsure ?
freyford
12 Posts
0
June 27th, 2004 06:00
Well I just skip the 2 windows/prefetch files didn't know to delete and completed the rest of texruss directions. rebooted and have new log file... posted ran spybot 1.3 and the latest tonights adware and delete all. So... haven't tried my Internet Explorer yet, want to rid myself of this hijacker. THANKS TXRUSS
When this has finally past... HOW DO I NEVER GET THIS AGAIN?! At the time of surfing, I think a pop-up started it all. All of my software Nortons Anti virus, Microsoft Updates, IE explorer, Microsoft XP Pro firewall up, Adware, Spybot were all up to date and running. How do I protect for the future?
The Adware still found this CoolwebSearch stuff? Is this bad? How would I delete it?
CoolWebSearch Object recognized!
Type : File
Data : a0059791.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 89 KB
Created on : 6/19/2004 1:15:38 AM
Last accessed : 6/27/2004 7:45:56 AM
Last modified : 6/19/2004 1:15:38 AM
CoolWebSearch Object recognized!
Type : File
Data : a0059792.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 9 KB
Created on : 6/18/2004 9:00:27 PM
Last accessed : 6/27/2004 7:45:56 AM
Last modified : 6/18/2004 9:00:27 PM
CoolWebSearch Object recognized!
Type : File
Data : a0059793.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 9 KB
Created on : 6/24/2004 7:48:04 PM
Last accessed : 6/27/2004 7:45:56 AM
Last modified : 6/24/2004 7:48:04 PM
CoolWebSearch Object recognized!
Type : File
Data : a0059794.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 9 KB
Created on : 6/7/2004 11:17:31 PM
Last accessed : 6/27/2004 7:45:56 AM
Last modified : 6/7/2004 11:17:31 PM
CoolWebSearch Object recognized!
Type : File
Data : a0059795.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 89 KB
Created on : 6/22/2004 8:29:17 PM
Last accessed : 6/27/2004 7:45:56 AM
Last modified : 6/22/2004 8:29:17 PM
CoolWebSearch Object recognized!
Type : File
Data : a0059796.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 26 KB
Created on : 6/25/2004 7:25:16 AM
Last accessed : 6/27/2004 7:45:56 AM
Last modified : 6/25/2004 7:25:20 AM
CoolWebSearch Object recognized!
Type : File
Data : a0059797.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 69 KB
Created on : 6/7/2004 1:01:36 AM
Last accessed : 6/27/2004 7:45:57 AM
Last modified : 6/7/2004 1:01:36 AM
CoolWebSearch Object recognized!
Type : File
Data : a0059798.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 89 KB
Created on : 6/22/2004 8:29:17 PM
Last accessed : 6/27/2004 7:45:57 AM
Last modified : 6/22/2004 8:29:17 PM
CoolWebSearch Object recognized!
Type : File
Data : a0059799.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 69 KB
Created on : 6/8/2004 11:42:06 AM
Last accessed : 6/27/2004 7:45:57 AM
Last modified : 6/8/2004 11:42:06 AM
CoolWebSearch Object recognized!
Type : File
Data : a0059800.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 9 KB
Created on : 6/23/2004 8:41:56 AM
Last accessed : 6/27/2004 7:45:57 AM
Last modified : 6/23/2004 8:41:56 AM
CoolWebSearch Object recognized!
Type : File
Data : a0059801.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 69 KB
Created on : 6/19/2004 1:47:37 PM
Last accessed : 6/27/2004 7:45:57 AM
Last modified : 6/19/2004 1:47:37 PM
CoolWebSearch Object recognized!
Type : File
Data : a0059802.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP465\
FileSize : 69 KB
Created on : 6/23/2004 10:56:42 PM
Last accessed : 6/27/2004 7:45:57 AM
Last modified : 6/23/2004 10:56:42 PM
Logfile of HijackThis v1.97.7
Scan saved at 12:07:33 AM, on 6/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {776706AE-CACA-4EA3-93DF-BB83D9259DA9} (MailConfigure Class) - http://supportservices.msn.com/us/oeconfig/MailCfg.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37655.9501388889
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} (MS Investor Ticker) - http://fdl.msn.com/public/investor/v9.5/ticker.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v13/ticker.cab
Message Edited by freyford on 06-27-2004 02:20 AM
Message Edited by freyford on 06-27-2004 03:02 AM
Texruss
2 Intern
•
3.4K Posts
0
June 27th, 2004 14:00
See if you can maintain a new home page. Your log looks clear if it isn't hiding.
The CWS files are in System Restore folder...here's how to remove it:
Flush your Restore Points for XP. That means disabling the Restore Point, rebooting to flush it, then re-enabling a new Restore Point. The reason why we need to do this is to purge the bad files hidden in System Restore which can't be cleaned by your antivirus programs.
See FAQ 12 here: http://www.russelltexas.com/malware/faqhijackthis.htm
You look clean (hopefully) and hearty congratulations! Now to stay that way:
Cleanup Programs and Preventative Procedures
(the four free programs in Items 2, 3, and 4 bolded below are a MUST in my opinion)
1. Spybot Search&Destroy, Ad-aware Run weekly - or after a heavy internet session. Download at the following link.
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...go slow on the directions for the custom setup of Adaware and print it out as a hard copy. It will take five minutes to set up the custom scanning options for Adaware, but it's worth it as these settings will be retained and you won't have to re-enter them again.
http://www.cjwd.demon.co.uk/spybot-adaware.html
Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.
I also like to run Windows Disk Cleanup after cleaning with those two tools and also on a weekly basis as a regular tool. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).
Reboot and click on Start/Run/ type: cleanmgr
If you have problems with Disk Cleanup hanging and not completing see this page for XP users:
http://support.microsoft.com/default.aspx?scid=kb;en-us;812248
Or try this fix: http://www2.whidbey.net/djdenham/DeleteOldFiles.htm
From MS Help: "Disk Cleanup helps free up space on your hard drive. Disk Cleanup searches your drive, and then shows you temporary files, Internet cache files, and unnecessary program files that you can safely delete. You can direct Disk Cleanup to delete some or all of those files."
I check all the selected categories and click OK at the end of Disk Cleanup.
If you have any problems with Disk Cleaner completing...XP users can fix it here:
http://support.microsoft.com/default.aspx?scid=kb;en-us;812248
Or try this fix: http://www2.whidbey.net/djdenham/DeleteOldFiles.htm
2. Proactive programs: Spywareblaster & Spywareguard, first sets kill bits to stop known bad MSIE ActiveX scripts from installing, second acts like your AV to stop browser hijacks and installing of known baddies.
3. IE-Spyad, puts 4000 bad sites in your restricted (banned) sites list, to stop you accidentally getting sent to a bad site, it has optional list of "bad" adult sites to install as well.
Links for these at: http://www.cjwd.demon.co.uk/compsafetyonline.html
4. MVPS Hosts file at: http://mvps.org/winhelp2002/hosts.htm
The MVPS Hosts file replaces your current HOSTS file with one that prevents your computer from connecting to hostile sites by redirecting them to 127.0.0.1 which is your local computer. This is an easy way to prevent one of the most common hijackings computer users will face on the Internet! Do it now.
5. Don't forget keeping Windows updated. The automatic updates frequently fail so run it manually once a week or when new updates are publicized.
Windows Live Update Page
http://v4.windowsupdate.microsoft.com/en/default.asp
Free Windows Security CD (for those who qualify):
www.microsoft.com/security/protect/cd/order.asp
You can also start Windows Update by running Internet Explorer, pulling down Tools on top Menu bar and selecting Windows Update. Install ALL critical updates! Always!
If LiveUpdate fails (and it is prone to on MANY machines) download each patch manually from the MS advisory pages and install manually. Works for me!
6. Keep your antivirus updated.
Free AVG Antivirus for home users: http://www.grisoft.com
7. Beg, borrow, or buy a Software Firewall if at all possible. I use Norton Internet Security 2004 and it has saved my bacon more times than I can count. For a free software firewall turn on the fairly lame firewall in Windows XP (I say it is lame because it does not monitor or block outgoing traffic...only incoming...a serious omission if the threat occurs inside your network). Hopefully with the upcoming Service Pack 2 this flaw will be addressed.
http://www.microsoft.com/technet/community/columns/5min/5min-101.mspx#XSLTsection125121120120
A better choice for now for a free software firewall is Zone Alarm.
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp
8. Practice safe computer habits. Don't click on strange email attachments thinking your AV will defend you. Usually it will. Sometimes it won't when a new virus hits the Net and definitions take hours to create by the AV vendors. There is only one defense that works 100% for the safe protection of your machine's personal data and that is timely and accurate backups of your files. Hard drives die, viruses ruin your files, and other bad things can happen (fire, theft, etc..). Offsite backups are the best.
9. Don't forget our great analysis tool Hijackthis. We have a lot of gratitude we need to show towards the author Merijn. I hope he does great things in his future endeavors and is richly rewarded for his time and expertise in providing this super program.
Hijackthis (to analyse your system and submit a log file to expert forums):
http://tomcoyote.com/hjt
(for Hijackthis logs...please copy to and run Hijackthis.exe into a new folder you create in the root level of the C: drive. Name this folder HJT for best and safest results). (don't put in a Local Settings Temp folder, or the Windows desktop, etc...as it needs a safe folder to keep backup logs). Also when XP and W2K users post here and place it in the Local Settings, the log usually shows their full name since their Windows user profile is commonly named with their full name. We try not to disturb your privacy. *;-)
See this link for graphical instruction: http://russelltexas.com/malware/faqhijackthis.htm
Forums for help and analysis of your Hijackthis logfile:
http://forums.us.dell.com/supportforums
http://forums.tomcoyote.com
http://www.spywareinfo.com/forums
http://www.wilderssecurity.com
http://www.computercops.us/forums.html
http://forums.net-integration.net
http://boards.cexx.org
http://www.bleepingcomputer.com
Good luck and safe computing!
Texruss
www.russelltexas.com
Spyware Fighter Wilders Forum
Slyware Warrior Tom Coyote Forum
Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-) BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.
freyford
12 Posts
0
June 27th, 2004 23:00