This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CWS INFESTATION?

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please run Notepad and paste the following text into a new file:

REGEDIT4

[[HKEY_USERS\S-1-5-21-220523388-152049171-854245398-1001\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{B195B3B3-8A05-11D3-97A4-0004ACA6948E}"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B195B3B3-8A05-11D3-97A4-0004ACA6948E}]


Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.

Reboot your computer and run a new MWav log.
New log: File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Wed Oct 05 19:55:46 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken. Can you just confirm that the heading "Quote" is not part of what I should be including in the fix.reg file?
REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "b195b3b3-8a05-11d3-97a4-0004aca6948e" 05/10/2005 21:35:45 ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-220523388-152049171-854245398-1001\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser] "{B195B3B3-8A05-11D3-97A4-0004ACA6948E}"=hex:b3,b3,95,b1,05,8a,d3,11,97,a4,00,\
Doh, had an extra character in there. Please run Notepad and paste the following text into a new file:

REGEDIT4

[HKEY_USERS\S-1-5-21-220523388-152049171-854245398-1001\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{B195B3B3-8A05-11D3-97A4-0004ACA6948E}"=-


Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.

Reboot your computer and run a new MWav log. Sorry for the mixup!
OK, this looks good. This is all that's left after removing 'invalid object' entries: File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
How does this look?

Logfile of HijackThis v1.99.1
Scan saved at 23:13:43, on 05/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\explorer.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Configuration Utility.lnk = C:\Program Files\LINKSYS\Configuration Utility\config.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.btopenworld.com/
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gatesh-tr.northy.nhs.uk,xghnt
O17 - HKLM\System\CS1\Services\Tcpip\..\{3216F52D-8BB1-4C30-A975-DB1DDBFDD405}: NameServer = 194.101.13.2,194.101.13.40
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
Congratulations, your log is clean. Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. :P
  • On a regular basis, please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows, including the latest version of Internet Explorer. This can patch many of the security holes through which attackers can gain access to your computer.
  • In order to protect yourself against spyware, you should consider installing and running the following free programs:
    • Ad-Aware SE. A tutorial on using Ad-Aware to remove spyware from your computer may be found here. You have this installed currently. Please keep it updated and run it on a regular basis.
    • Spybot-Search & Destroy. A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features. You have this installed currently. Please keep it updated and run it on a regular basis.
    • SpywareBlaster. A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.
    • SpywareGuard. A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.
    Keeping these programs up-to-date and running them regularly can prevent a great deal of spyware hassle.
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here.
  • Also make sure to run your antivirus software regularly, and to keep it up-to-date.
Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. :D
Glad to hear it and thanks! Since this issue appears resolved … this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
an email with the address of the thread. This applies only to the original topic starter. Any emails without the subject "Reopen" will be deleted without being looked at.

Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI