This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CWS INFESTATION?

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK, msdos.exe deleted. Adaware scan found 0 critical objects, 17 negligible objects, deleted these and second scan was clean. Spybot S&D found no immediate threats.
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "weathercast Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.homesearch Browser Hijacker" found in File System! Action Taken: No Action Taken. Object "ipinsight Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "netpal Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\WINNT\system32\NLNP13.dll tagged as "not-a-virus:AdWare.IGetNet". Action Taken: No Action Taken. File C:\WINNT\system32\ctbv2.dll tagged as "not-a-virus:AdWare.Sahat.g". Action Taken: No Action Taken. File C:\WINNT\system32\ezStubi.dll tagged as "not-a-virus:AdWare.EZula.a". Action Taken: No Action Taken. File C:\WINNT\system32\CometTB.dll tagged as "not-a-virus:AdWare.Win32.Comet.ad". Action Taken: No Action Taken.
Ok, can I see the entries from the full log for the following:
hotbar
kazaa
weathercast
homesearch
ipinsight
netpal
exactsearchbar
istbar
smartfinder
whenu
exactsearchbar


We will remove them manually since Ad-aware and Spybot do not seem to be picking some of these up for some reason.
Here they are: Tue Oct 04 18:49:11 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken. Tue Oct 04 18:49:12 2005 => Offending Key found: HKLM\Software\kazaa !!! Tue Oct 04 18:49:12 2005 => Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Oct 04 18:49:12 2005 => Offending Key found: HKCU\Software\kazaa !!! Tue Oct 04 18:49:12 2005 => Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\weather.exe Tue Oct 04 18:49:14 2005 => System found infected with weathercast Spyware/Adware (weather.exe)! Action taken: No Action Taken. Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\appsj.exe Tue Oct 04 18:49:14 2005 => System found infected with cws.homesearch Browser Hijacker (appsj.exe)! Action taken: No Action Taken. Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\Inf\ipinsigt.pnf Tue Oct 04 18:49:14 2005 => System found infected with ipinsight Spyware/Adware (ipinsigt.pnf)! Action taken: No Action Taken. Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\system32\netpals.dll Tue Oct 04 18:49:14 2005 => System found infected with netpal Spyware/Adware (netpals.dll)! Action taken: No Action Taken. Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\system32\ezstubi.dll Tue Oct 04 18:49:14 2005 => System found infected with exactsearchbar Spyware/Adware (ezstubi.dll)! Action taken: No Action Taken. Tue Oct 04 18:49:17 2005 => Offending Folder found: C:\Documents and Settings\leo.quigley\Application Data\lycos\sidesearch Tue Oct 04 18:49:17 2005 => Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Oct 04 18:49:17 2005 => Offending Folder found: C:\Documents and Settings\leo.quigley\Favorites\sites about Tue Oct 04 18:49:17 2005 => Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Oct 04 18:49:17 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Favorites\search the web.url Tue Oct 04 18:49:17 2005 => System found infected with smartfinder Spyware/Adware (search the web.url)! Action taken: No Action Taken. Tue Oct 04 18:49:17 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Favorites\only sex website.url Tue Oct 04 18:49:17 2005 => System found infected with smartfinder Spyware/Adware (only sex website.url)! Action taken: No Action Taken. Tue Oct 04 18:49:17 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Favorites\seven days of free porn.url Tue Oct 04 18:49:17 2005 => System found infected with smartfinder Spyware/Adware (seven days of free porn.url)! Action taken: No Action Taken. Tue Oct 04 18:49:19 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\temporary internet files\search.html Tue Oct 04 18:49:19 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken. Tue Oct 04 18:49:20 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\Temporary Internet Files\search.html Tue Oct 04 18:49:20 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken. Tue Oct 04 18:49:23 2005 => Offending file found: C:\WINNT\system32\ezstubi.dll Tue Oct 04 18:49:23 2005 => System found infected with exactsearchbar Spyware/Adware (C:\WINNT\system32\ezstubi.dll)! Action taken: No Action Taken.
Please run Notepad and paste the following text into a new file:

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\kazaa]

[-HKEY_CURRENT_USER\Software\kazaa]


Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.

Next, please enable viewing of hidden files as follows:
  • Go to My Computer, and click on the "Tools" menu
  • Click "Folder options"
  • Select the "View" tab
  • Make sure "Show hidden files and folders" is selected
  • Make sure "Hide extensions for known file types" is unchecked
  • Make sure "Hide protected operating system files (recommended)" is unchecked
Delete the following files and folders (if found):
C:\WINNT\weather.exe <–This file
C:\WINNT\appsj.exe <–This file
C:\WINNT\Inf\ipinsigt.pnf <–This file
C:\WINNT\system32\netpals.dll <–This file
C:\WINNT\system32\ezstubi.dll <–This file
C:\Documents and Settings\leo.quigley\Application Data\lycos\sidesearch <–This folder and its contents
C:\Documents and Settings\leo.quigley\Favorites\sites about <–This folder and its contents
C:\Documents and Settings\leo.quigley\Favorites\search the web.url <–This file
C:\Documents and Settings\leo.quigley\Favorites\only sex website.url <–This file
C:\Documents and Settings\leo.quigley\Favorites\seven days of free porn.url <–This file
C:\Documents and Settings\leo.quigley\Local Settings\temporary internet files\search.html <–This file

Reboot your computer and post a new MWav log.
Found them all except the last one. No sign of it in the location given. Here's the log from the bottom window: File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\WINNT\system32\NLNP13.dll tagged as "not-a-virus:AdWare.IGetNet". Action Taken: No Action Taken. File C:\WINNT\system32\ctbv2.dll tagged as "not-a-virus:AdWare.Sahat.g". Action Taken: No Action Taken. File C:\WINNT\system32\CometTB.dll tagged as "not-a-virus:AdWare.Win32.Comet.ad". Action Taken: No Action Taken. And here are the relevant lines from the full log: Tue Oct 04 22:58:36 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken. Tue Oct 04 22:58:45 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\temporary internet files\search.html Tue Oct 04 22:58:45 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken. Tue Oct 04 22:58:46 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\Temporary Internet Files\search.html Tue Oct 04 22:58:46 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken.
Download: CCleaner (freeware)
http://www.majorgeeks.com/download4191.html
Once installed, run CCleaner click the Windows
Select the following:
[external image: Posted Image]
Next: click Options click the Settings tab
Uncheck: "Only delete files older than 48 hrs.", click Ok
Then click Run Cleaner (bottom right) then Exit.

Delete the last 3 files found in the log, then run a new MWav scan and post the log. Almost there.
Cleaner didn't have a checkbox for Old Prefetch Data. Otherwise, done as requested and here is the new log: File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Wed Oct 05 08:41:38 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken.
Please download the Registry Search tool by clicking on the "hard drive" icon three quarters of the way down this page. Save it to the desktop and run it. If you get an alert from your antivirus about scripting, choose to allow the script to run. Search for b195b3b3-8a05-11d3-97a4-0004aca6948e and click OK. Post the logfile from the tool here for me.
REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "b195b3b3-8a05-11d3-97a4-0004aca6948e" 05/10/2005 17:29:54 ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B195B3B3-8A05-11D3-97A4-0004ACA6948E}] [HKEY_USERS\S-1-5-21-220523388-152049171-854245398-1001\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser] "{B195B3B3-8A05-11D3-97A4-0004ACA6948E}"=hex:b3,b3,95,b1,05,8a,d3,11,97,a4,00,\

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI