I think i removed it. But will ospme one please confirm

Logfile of HijackThis v1.99.1
Scan saved at 10:57:17 PM, on 12/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InfoMyCa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Taylor\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://allaboutipods.forumsplace.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = FP Productions
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [WUSB54Gv2] C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131835076992
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: WUSB54Gv2SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv2.exe (file missing)

3
Contributors
4
Replies
5
Views
11 Years
Discussion Span
Last Post by tayspen

That's a clean log, tayspen :)

For future protection, I'd recommend that you install Microsoft Anti-Spyware beta; it does a good job of removing "nasties" and also provides real-time protection.

Ok, Thanks DMR

Here's a little tip on coolwebsearch and coolwwwsearch. If you suspect that you have them. The quickest and easiest way to rid yourself of them is to check the registry with a key word search:

Start --> Run --> regedit --> Ctrl+F --> type "coolw" in the search box (without the quotation marks.) --> Press Enter ------>

Now if it finds anything you can do one of two things. You can immediately hit delete and confirm. Or you can check to see if you are in a domains folder. If you are in a domains folder and you have been stopped by the search for coolw. You have found either coolwebsearch or coolwwwsearch. (There shouldn't be any other result even similar to this search.) But if you have been stopped in a domains folder then you can back up and delete the entire folder. It will recreate it's self the next time you open your browser, but without all of the pornographic material that was in it.
If you are not in a domain folder. You may just delete it.

To continue searching use can use the F3 key or click the find next option.

:::::::::::::::::::::::::::::
Warning What is deleted from the registry is permanently removed from your PC, and even though I have never found a result other than coolwwwsearch and coolwebsearch using the search coolw with the find option it may be possible you have a program that has something similiar. Please make sure that what you have found says either coolwwwsearch or coolwebsearch.

Here's a little tip on coolwebsearch and coolwwwsearch. If you suspect that you have them. The quickest and easiest way to rid yourself of them is to check the registry with a key word search:

Start --> Run --> regedit --> Ctrl+F --> type "coolw" in the search box (without the quotation marks.) --> Press Enter ------>

Now if it finds anything you can do one of two things. You can immediately hit delete and confirm. Or you can check to see if you are in a domains folder. If you are in a domains folder and you have been stopped by the search for coolw. You have found either coolwebsearch or coolwwwsearch. (There shouldn't be any other result even similar to this search.) But if you have been stopped in a domains folder then you can back up and delete the entire folder. It will recreate it's self the next time you open your browser, but without all of the pornographic material that was in it.
If you are not in a domain folder. You may just delete it.

To continue searching use can use the F3 key or click the find next option.

(Warning What is deleted from the registry is permanently removed from your PC, and even though I have never found a result other than coolwwwsearch and coolwebsearch using the search coolw with the find option it may be possible you have a program that has something similiar. Please make sure that what you have found says either coolwwwsearch or coolwebsearch.)

Hey thanks for the tip! I will test it out.

Thanks Again

-T