New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1180
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin   Your Favorite ForumsFavForums 

CWShredder Enigma!Help! Take 2. 35dayswithnoanyresponse
Goto page 1, 2  Next
 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Spyware Tools
View previous topic :: View next topic  
Author Message
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Thu May 20, 2004 4:43 pm    Post subject: CWShredder Enigma!Help! Take 2. 35dayswithnoanyresponse
Reply with quote

Hello!

I just did big spring cleaning and it took me a good while, because all this stuff is quite new to me. I clicked "Scan only" on CWShredder and it gave me strange list of things. Spybot SD, Ad-aware, CWShredder(Fix says I'm perfectly free of CW) and HijackThis already did good job. What this list is about? Do these things remain on my comp? Or it's something ells? I don't understand this. I am new here and will appreciate if someone could explain me what is about and how can I fix it if I have to? I put here this report.

Found Hosts file: C:\WINDOWS\system32\drivers\etc\hosts (135 bytes, R)
Shell Registry value: HKLM\..\WinLogon [Shell] Explorer.exe
UserInit Registry value: HKLM\..\WinLogon [UserInit] C:\WINDOWS\system32\userinit.exe,
CWS.Oslogo (if value is 2) Registry value: Domains: *.coolwebsearch.com [*] dword:4
CWS.Oslogo (if value is 2) Registry value: Domains: *.coolwwwsearch.com [*] dword:4
CWS.Googlems.2 (if value is 2) Registry value: Domains: *.xxxtoolbar.com [*] dword:4
CWS.Googlems.4 (if value is 2) Registry value: Domains: *.teensguru.com [*] dword:4
Registry value: DefaultPrefix (should be http://) [] http://
Registry value: WWW Prefix (should be http://) [www] http://
Registry value: Mosaic Prefix (should be http://) [mosaic] http://
Registry value: Home Prefix (should be http://) [home] http://
Found Win.ini file: C:\WINDOWS\win.ini (925 bytes, A)
Found System.ini file: C:\WINDOWS\system.ini (227 bytes, A)
- END OF REPORT -

Thank you for your time and help!
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Thu May 20, 2004 7:24 pm    Post subject:
Reply with quote

Hi fimoulia,

CWShredder is reporting the existance of 4 CoolWebSearch variants on your system (CWS....). These are malware programs that take control of your browser and force you to sites you don't want to go.

All the other stuff is just CWShredder telling you that it has checked those vital areas of Windows (hosts file, WinLogon, web registry entries, and both major system files win.ini & system.ini).

Run CWShredder again and click on the NEXT button and let it remove these hijackers from your system.

Run hijackthis again and copy and past you log here. The tools you use don't always remove everything, and often manual removal is needed. The log will help us assist. Very Happy
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Thu May 20, 2004 9:09 pm    Post subject:
Reply with quote

Hello satchick,

Thank you very much for taking time and trouble to be here with me!

I did as you said and here is my log. You can see that it's pretty clean. 017 - are my ISP DNS servers. I ran CWShredder few times already about that in the past and now and it doesn't stop saying that my system is clean from any sign of CWS, exept this scan report. That's why I call it "Enigma". No Idea Question

Logfile of HijackThis v1.97.7
Scan saved at 02:27:07, on 21/05/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\StartupMonitor.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE
C:\Security Tools\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = ?
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc.../swdir.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar.../cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/sho...wflash.cab
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) - http://download.microsoft.com/download/...earadj.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup144.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?319
O17 - HKLM\System\CCS\Services\Tcpip\..\{025B81E8-08A9-46E6-83B4-CC1E466FABFE}: NameServer = 193.74.208.65,194.119.228.67
O17 - HKLM\System\CS1\Services\Tcpip\..\{025B81E8-08A9-46E6-83B4-CC1E466FABFE}: NameServer = 193.74.208.65,194.119.228.67
O17 - HKLM\System\CS2\Services\Tcpip\..\{025B81E8-08A9-46E6-83B4-CC1E466FABFE}: NameServer = 193.74.208.65,194.119.228.67
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Fri May 21, 2004 8:18 am    Post subject:
Reply with quote

CWShredder will post this message at the top of its final screen when its done (if your system is clean of what it detects):
Quote:
Done!
Your system was completely clean.


Below is a report for my system (which is clean of malware).

Quote:
Windows XP (5.01.2600 SP1)
Windows dir: C:\WINDOWS
Windows system dir: C:\WINDOWS\system32

Found Hosts file: C:\WINDOWS\system32\drivers\etc\hosts (3077 bytes, A)
Shell Registry value: HKLM\..\WinLogon [Shell] Explorer.exe
UserInit Registry value: HKLM\..\WinLogon [UserInit] C:\WINDOWS\system32\userinit.exe,
Registry value: DefaultPrefix (should be http://) [] http://
Registry value: WWW Prefix (should be http://) [www] http://
Registry value: Mosaic Prefix (should be http://) [mosaic] http://
Registry value: Home Prefix (should be http://) [home] http://
Found Win.ini file: C:\WINDOWS\win.ini (714 bytes, A)
Found System.ini file: C:\WINDOWS\system.ini (402 bytes, A)

- END OF REPORT -


If yours looks like this now and you get that message at the top, then your OK. Otherwise, there is a problem!

As far as your HJT log, just have it fix this entry:
R3 - Default URLSearchHook is missing

and your HJT log is clean. Smile
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Fri May 21, 2004 11:08 am    Post subject:
Reply with quote

Hello satchik,

This is how my CWShredder logs look now. Remain the same. There is some problem.

Quote:
Done!
Your system was completely clean.


Quote:
Windows XP (5.01.2600 SP1)
Windows dir: C:\WINDOWS
Windows system dir: C:\WINDOWS\system32

Found Hosts file: C:\WINDOWS\system32\drivers\etc\hosts (135 bytes, -)
Shell Registry value: HKLM\..\WinLogon [Shell] Explorer.exe
UserInit Registry value: HKLM\..\WinLogon [UserInit] C:\WINDOWS\system32\userinit.exe,
CWS.Oslogo (if value is 2) Registry value: Domains: *.coolwebsearch.com [*] dword:4
CWS.Oslogo (if value is 2) Registry value: Domains: *.coolwwwsearch.com [*] dword:4
CWS.Googlems.2 (if value is 2) Registry value: Domains: *.xxxtoolbar.com [*] dword:4
CWS.Googlems.4 (if value is 2) Registry value: Domains: *.teensguru.com [*] dword:4
Registry value: DefaultPrefix (should be http://) [] http://
Registry value: WWW Prefix (should be http://) [www] http://
Registry value: Mosaic Prefix (should be http://) [mosaic] http://
Registry value: Home Prefix (should be http://) [home] http://
Found Win.ini file: C:\WINDOWS\win.ini (925 bytes, A)
Found System.ini file: C:\WINDOWS\system.ini (227 bytes, A)

- END OF REPORT -

Thanks again!
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Fri May 21, 2004 11:14 am    Post subject:
Reply with quote

If its detecting these:
CWS.Oslogo (if value is 2) Registry value: Domains: *.coolwebsearch.com [*] dword:4
CWS.Oslogo (if value is 2) Registry value: Domains: *.coolwwwsearch.com [*] dword:4
CWS.Googlems.2 (if value is 2) Registry value: Domains: *.xxxtoolbar.com [*] dword:4
CWS.Googlems.4 (if value is 2) Registry value: Domains: *.teensguru.com [*] dword:4

Then hitting the FIX button instead of the SCAN ONLY button should fix them. Did you do this? And if so, did they come back?

Go to windows update and make sure you have all the latest critical updates. Please let me know the answers to the above.
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Fri May 21, 2004 11:54 am    Post subject:
Reply with quote

satchick...

I have all the latest critical updates from Microsoft.

I open CWShredder (it's in special folder for small security programs on C:/). Then I look for updates. Says I have the latest version 1.57.0. I hit "Fix". It runs and then says: Done! Your system was completely clean. I exit, reboot, open again and hit "Scan only". And then I have this log which I've posted. And it's all the time like that. These 4 bad entries are always there.

Thanks.
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Fri May 21, 2004 12:10 pm    Post subject:
Reply with quote

OK, I will seek council about this with the experts here. Smile
Back to top
View users profile Send private message Send email
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Fri May 21, 2004 3:02 pm    Post subject:
Reply with quote

fimoulia, a security expert here says that, that is a normal scan log for CWShredder. Even saw their own log and its just like yours!

As long as you got the 'Done! Your system was completey clean.' message as you did, then you're good to go. Very Happy
Back to top
View users profile Send private message Send email
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1904

PostPosted: Fri May 21, 2004 3:30 pm    Post subject:
Reply with quote

Can confirm this is so. Had same problem myself.....clean machine, 'dirty' CWS log report. All A-OK, though. No harm in asking as you did, better safe than sorry.
Back to top
View users profile Send private message
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Fri May 21, 2004 5:39 pm    Post subject:
Reply with quote

satchick!!! Perfect job! Thanks A LOT! Feels much better. Bananas

Mariner! What can I say? Thanks again! Thumbs Up
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Fri May 21, 2004 6:01 pm    Post subject:
Reply with quote

Were happy to have helped. Very Happy
Back to top
View users profile Send private message Send email
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 825
Location: Canada

PostPosted: Fri May 21, 2004 7:55 pm    Post subject:
Reply with quote

--
Back to top
View users profile Send private message Send email
Mosaic1

Site Moderator
Site Moderator



Joined: Jan 15, 2004
Posts: 4947
Location: USA

PostPosted: Sat May 22, 2004 3:15 am    Post subject:
Reply with quote

To explain, those entries mean that those sites have been placed on your Restricted sites list , probably by a security program you installed.
Back to top
View users profile Send private message
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Sat May 22, 2004 7:10 am    Post subject:
Reply with quote

Restricted CWS sites lists of Spybot S&D or SpywareBlaster are veeeeeeeeeery long. Why only these 4 in the report? And satchick's "clean" log? He doesn't run Spybot S&D and SpywareBlaster with its RS lists?
...sorry for bother.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Spyware Tools All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops