 annabellem
join:2004-08-27 Ottawa, ON
| HJT Log
Hi. I have CWS.Searchx on my computer which seems to like to re-install itself after it has been deleted, as we all know. I have read and researched everything possible and have seen the different ways of deleting it, but would prefer some personal help so i do it right the first time. I do have Ad-Aware, Spybot Search&Destroy, and CWShredder and have used all of them. My problem still goes unsolved. This is my Hijack This log file, copied and pasted, can you please advise me on what to do at this point? Also, I am only 16 and am not completely computer literate, so please consider this when giving me instructions. 
Logfile of HijackThis v1.98.2 Scan saved at 11:08:15 PM, on 27/08/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ISS\BlackICE\blackd.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\system32\CTHELPER.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe c:\progra~1\intern~1\iexplore.exe C:\progra~1\kiwial~1\partner\msbb.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\ISS\BlackICE\blackice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\explorer.exe C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = »google.ca/ O2 - BHO: (no name) - {04A63F8A-4F1E-7A80-5FFE-1FB8EA9F3412} - C:\PROGRA~1\HECKSA~1\audiodefy.exe (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Base Copy] C:\PROGRA~1\Thedoes\Junk vga.exe O4 - HKLM\..\Run: [Ping bend 16 love] C:\Documents and Settings\All Users\Application Data\Intra gpl ping bend\intercurb.exe O4 - HKLM\..\Run: [msbb] c:\progra~1\kiwial~1\partner\msbb.exe O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: BlackICE PC Protection (2).lnk = C:\Program Files\ISS\BlackICE\blackice.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - »messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - »www.wildtangent.com/install/jvm/···3805.exe O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - »messenger.zone.msn.com/binary/Mi···eper.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - »a1540.g.akamai.net/7/1540/52/200···ller.exe O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - »messenger.zone.msn.com/binary/Me···ient.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - »sc.groups.msn.com/controls/Photo···Upld.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - »messenger.zone.msn.com/binary/So···down.cab
Thanks. My email is canadianmonkee@hotmail.com if you need to contact me that way. |
|
  b11ngO0
join:2004-08-02 Canada
| Here's the automated hijackthis log analyzer.
»hijackthis.de/index.php?langselect=english
I'll analyze your hijackthis log. Free of charge.
Fix these. O4 - HKLM\..\Run: [msbb]c:\progra~1\kiwial~1\partner\msbb.exe C:\progra~1\kiwial~1\partner\msbb.exe
Peace.
b11ng00 |
|
  darkstar2778 Premium join:2004-01-20 Florida clubs:
| Search for "CWS.Searchx" in the topic search for this Security Forum. You'll find a bunch of links where the experts have posted on this problem. Here are a few:
»CWS.searchx is coming back!
»HTL log - CWS.SearchX found on computer
»HELP!!! CWS.searchx keeps coming back...part 2
You may have already tried that, but its about the most I can help here. |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| reply to annabellem What program is telling you that CWS.searchx is on your PC because I don't see any signs of it. However, you do have a LOP hijacker (thanks to MessengerPlus that bundles LOP with it). I suggest you get rid of Messenger Plus and use something spyware/parasite free like Trillian or just plain Messenger - it isn't worth the headaches.
Make a copy of these instructions as the next steps need to made in safe mode with IE closed.
Reboot your PC into safemode
How to start the computer in Safe mode »service1.symantec.com/SUPPORT/ts···_doc_nam
Scan and checkmark these items, then press *fix checked.
O2 - BHO: (no name) - {04A63F8A-4F1E-7A80-5FFE-1FB8EA9F3412} - C:\PROGRA~1\HECKSA~1\audiodefy.exe (file missing)
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Base Copy] C:\PROGRA~1\Thedoes\Junk vga.exe
O4 - HKLM\..\Run: [Ping bend 16 love] C:\Documents and Settings\All Users\Application Data\Intra gpl ping bend\intercurb.exe
O4 - HKLM\..\Run: [msbb] c:\progra~1\kiwial~1\partner\msbb.exe .................... Stay in safe mode and delete the following
C:\PROGRAM FILES\HECKSA (folder, name starts with those letters)
C:\PROGRAM FILES\Thedoes (folder)
c:\program files\kiwial(folder - starts with those letters)
If you don't know what this program is, delete it too (looks very suspicious and a lot like the LOP hijacker pattern of random folder/file names) C:\Documents and Settings\All Users\Application Data\Intra gpl ping bend (folder)
Reboot back into normal mode and scan once more with HijackThis and post a new log please to see what may remain. -- It takes a disaster to make a woman out of a female Gladiator Security Forum Proud Member of ASAP (Alliance of Security Analysis Professionals) »www.a-sap.org/ |
|
 annabellem
join:2004-08-27 Ottawa, ON
| reply to annabellem thanks a lot CalamityJane for your help. i am about to try what you've suggested. i don't have the CWS.searchx on my computer right now because i am constantly using the CWShredder to get rid of it and i posted that after i got rid of it for about the 10th time. and the kiwi program is my music downloading program... it hasnt caused any problems for me yet, but if you can suggest a better one, please do. |
|
 annabellem
join:2004-08-27 Ottawa, ON | reply to annabellem ok. so i just finished following all the instrucions and it all ran smoothly... the only thing i didnt delete was kiwialpha. any further advise on what to do now? should i post my new hijack this report log? |
|
  John2g Qui Tacet Consentit Premium join:2001-08-10 England
| You should read this re: C:\progra~1\kiwial~1\partner\msbb.exe
»www.winpatrol.com/db/freesample/msbb.html -- Better to remain silent and be thought a fool, than to speak and remove all doubt. |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| Ok - your Kiwi Program may have come bundled with spyware..and the offending file is msbb.exe actually within the *Partners* folder in your Kiwi Program. Look in there and see what you find. It reminds me of MessengerPlus spyware it adds, it calls LOP one of it's *partners* *sponsors*. Same thing ....usually adware or spyware.
Try renaming msbb.exe to msbb.old. That will stop it from running. Scan it here:
Jotti's malware scan 2.24 »virusscan.jotti.dhs.org/
Copy the report at the end and paste it into your reply back here. -- It takes a disaster to make a woman out of a female Gladiator Security Forum Proud Member of ASAP (Alliance of Security Analysis Professionals) »www.a-sap.org/ |
|
 annabellem
join:2004-08-27 Ottawa, ON | reply to annabellem i forgot to add that i deleted the entire partners folder... sorry. thanks again |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| Ok, well your log looks clean right now. I don't see any sign of CWS.searchx. Next time, just scan with CHWshredder and post the report (don't *fix). Then immediately scan with HijackThis and post a new log. If you have no other signs than the detection by CWShredder, I am thinking it may be a false positive. Make sure you have the lastest version of Coolwebsearch (ver. 1.59.1). If not delete the one you have and download the new version here: »computercops.biz/zx/Merijn/cwshredder.zip
Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?
One of the best features of Windows ME or XP is the System Restore option, however if a malware infects a computer with this operating system it can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after malware removal.
To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.
(winXP)
1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK.
2. Reboot.
3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK.
How to Turn On and Turn Off System Restore in Windows XP »support.microsoft.com/default.as···s;310405
Next, we highly recommend you get some extra protection to prevent future infections. Here are some things you can do and some free programs to help .
»Security »How do I prevent browser hijacks and spyware?
I also highly recommend to get the free tool, Microsoft Baseline Security Analyzer (MBSA) from Microsoft to analyze your PC security for prevention purposes.
MBSA Version 1.2.1 will scan for common system misconfigurations on Windows 2000, Windows XP, and Windows Server 2003 systems. This program will identify the system security weaknesses in your browser and operating system and provides easy instructions to correct them. This includes any missing critical Windows security updates, system vulnerabilities and your IE Browser security settings. Get the download here: Microsoft Baseline Security Analyzer »www.microsoft.com/technet/securi···ome.mspx
You might also consider an alternative browser and use IE only when needed for sites that require ActiveX and are trusted (like Windows update or the online virus scanners). I use Firefox for 99% of my everyday surfing (using it right now in fact). It's free and very easy to setup, understand and use without many of the vulnerabilities that IE has. Or feel free to search around for info on other alternative browsers.
Firefox »www.mozilla.org/products/firefox/ -- It takes a disaster to make a woman out of a female Gladiator Security Forum Proud Member of ASAP (Alliance of Security Analysis Professionals) »www.a-sap.org/ |
|
 annabellem
join:2004-08-27 Ottawa, ON
| reply to annabellem hey. i really appreciate all the help you've given me. i moved to my dad's before i could finish fixing everything (my parents are divorced so i move every month [minus my computer]) so i was here for dinner today and CWSearch was back except it hadn't infected any files. what i've done is re-removed it and cleared my system restore (something i didn't manage to do before i left) and i'm hoping that that has taken care of the problem. i thought i would just post my new hijackthis log and ask you to look it over and double check that nothing is still lurking on my system. thanks 
Logfile of HijackThis v1.98.2 Scan saved at 8:24:13 PM, on 03/09/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ISS\BlackICE\blackd.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Messenger Plus! 2\MsgPlus.exe C:\WINDOWS\system32\CTHELPER.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\ISS\BlackICE\blackice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = »www.google.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: BlackICE PC Protection (2).lnk = C:\Program Files\ISS\BlackICE\blackice.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - »messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - »www.wildtangent.com/install/jvm/···3805.exe O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - »messenger.zone.msn.com/binary/Mi···eper.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - »a1540.g.akamai.net/7/1540/52/200···ller.exe O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - »messenger.zone.msn.com/binary/Me···ient.cab O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - »sc.groups.msn.com/controls/Photo···Upld.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - »messenger.zone.msn.com/binary/So···down.cab |
|
 MrTopher
join:2002-08-29 Portage, MI
·AT&T Yahoo
| reply to annabellem "C:\Program Files\Messenger Plus! 2\MsgPlus.exe Nasty running process. (MsgPlus.exe) Messenger Plus! (Spyware) This is a nasty process! You should fix it and try to delete it manually! "
unless you setup your IE to have its pages be about:NavigationFailure, go ahead and fix
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
Also, if you use wildtangent this should be okay, but if not go ahead and fix: O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - »www.wildtangent.com/install/jvm/
Fix this: O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - »a1540.g.akamai.net/7/1540/52/20030530/.. |
|