![]() |
| ||
| Desktop Popups (AHH!) and CWS Infection (Related problems?) I have 2 critical problems that I need help with :o 1) Okay. I use Firefox as my main browser. I gave up on Internet Explorer after it kept redirecting every other website I entered into others. That used to be the extent of the problem. But now, I get popups even when I don't have Firefox open :eek: . This is a problem for me because I play games, specifically Battlefield 2. Popups automatically minimize the game, which is becoming irksome. I would appriciate any advise on how to stop the popups! (Perhaps deleting internet explorer, I never get popups from firefox) I've tried some various popup blockers, but none have worked, and anyways it would probably be better to attack the source then stem the flow. 2) I have a full subscription to spy sweeper. I also have search and destroy and Ad-Aware. Every time I run Spy Sweeper I find CWS -AboutBlank, CWS_MSAS, and CWS_NS3 detected. Ad-Aware also detects them. So following standard protocol, I went and downloaded CWShredder, and updated my comp w/'Critical' updates. I ran CWShredder, and not only did it not fix it but it didnt even detect CWS! :( So now I have no idea what to do. I have Hijack This, but I'm not sure what keys I should delete/fix. So here is my log. Logfile of HijackThis v1.99.1 Scan saved at 2:08:41 PM, on 6/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\PROGRA~1\Iomega\System32\AppServices.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\RealVNC\VNC4\WinVNC4.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\WinAce\WinAce.exe C:\DOCUME~1\FARTMO~1\LOCALS~1\Temp\~AceTemp\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {C3BC80CE-EDB4-4C07-9F3F-07461E1DDF67} - C:\WINDOWS\system32\akd.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_19_0.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\Creative NOMAD Jukebox Zen Xtra\Diagnostics\diagent.exe" startup O4 - HKCU\..\Run: [window.exe] C:\WINDOWS\system32\window.exe O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O8 - Extra context menu item: Web Search - C:\WINDOWS\ex.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_8742.dll' missing O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/I...ve/HS_live.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_44.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1094678549858 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab O16 - DPF: {B9F3009B-976B-41C4-A992-229DCCF3367C} (CoAxTrack Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab O18 - Protocol: start - (no CLSID) - (no file) O18 - Filter: text/html - {7F09F1A8-FD53-4373-91D9-EC05ADA354BA} - C:\WINDOWS\system32\akd.dll O18 - Filter: text/plain - {7F09F1A8-FD53-4373-91D9-EC05ADA354BA} - C:\WINDOWS\system32\akd.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing) O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe (file missing) Any Help would be appriciated greatly!! (I have no where else to turn! :sad: ) If I ever catch whoever wrote CWS... :twisted: ... |
| ||
| Re: Desktop Popups (AHH!) and CWS Infection (Related problems?) Hi Ibex, I see that this is your first post; welcome to the site. :) Unfortunately, the CWS infection is actually an entire family of infections, and many of the newer variants can be quite difficult to remove. In addition to that, you log indicates other infections as well. HijackThis alone isn't going to be able to fully clean the infections, so please do the following in order to get things cleaned up a bit: 1. Run at least two or three of the following online anti-virus/anti-spyware scans and let them fix what they can: http://www.kaspersky.com/scanforvirus.html http://housecall.trendmicro.com/ http://us.mcafee.com/root/mfs/default.asp?cid=9914 http://www.pandasoftware.com/active...n_principal.htm http://www.ravantivirus.com/scan/ http://www.bitdefender.com/scan/licence.php 2. Download, install, and run the following (free) detection and removal tools (use each program's online update function before running them to make sure you have the most current updates installed). After each utility completes its fixes, reboot before continuing on to the next utility; have the utilities fix all of the problematic/malicious items they find: ewido Security Suite - http://www.ewido.net/en/download/ Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en Ad Aware SE Personal - http://www.lavasoftusa.com/ SpyBot Search & Destroy - http://www.safer-networking.org/ 3. Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up) - Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types". - For every user account listed under C:\Documents and Settings, delete the entire contents of these folders (but not the folders themselves): Important: One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if any data that you care about is living in those Temp folders, you need to move it to a safe location now, or it will be erased along with everything else! 1. Cookies 2. Local Settings\Temp 3. Local Settings\History 4. Local Settings\Temporary Internet Files - Delete the entire content of your C:\Windows\Temp folder. - Delete the entire content of your C:\Windows\Prefetch folder. Note- If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed. Windows will allow you to delete the versions of those files which exist in sub-folders within the main Temp/Temorary folders, but might not let you delete the versions of those files that exist in the main Temp folders themselves; this is normal and OK. - Empty your Recycle Bin. - Reboot normally, run HijackThis again, and post the new log it generates. |
| All times are GMT -4. The time now is 9:02 pm. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC