Yes I have CWShredder

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bowerscheri, May 12, 2004.

  1. bowerscheri

    bowerscheri Private E-2

    I also ran the look2kill you told me to and it said no infection found but I proceeded anyway. Still did not work.

    I deleted the 3 lines you said to and reran scans following are the results:

    Done!
    Removed from your system:
    - Hosts file redirections
    Windows 2000 (5.00.2195 SP4)
    CWShredder v1.57.0
    Written by Merijn - merijn@spywareinfo.com
    For any additional help with this program or removing CWS, visit:
    http://forums.spywareinfo.com/
    For information and documentation on the Coolwebsearch
    trojan and its variants, visit:
    http://www.spywareinfo.com/~merijn/cwschronicles.html
    For donations to help support CWShredder, visit:
    http://www.spywareinfo.com/~merijn/donate.html

    From Ad-Aware This shows up everytime I run this scan and it is usually 3 to 9 files found.

    Vendor:Tracking Cookie
    Category:Data Miner
    Object Type:File
    Size:264 Bytes
    Location:c:\documents and settings\user\cookies\user@0[2].txt
    Last Activity:5-12-2004 1:56:57 PM
    Risk LevelLow
    Comment:
    Description:This cookie is known to collect information that may be used either for targeted advertising, or tracking users across a particular website, such as page views or ad click-thrus.

    From Spybot S & D I get this everytime I run the scan.

    FastClick: Tracking cookie or cookie of tracking site (File, nothing done)
    C:\Documents and Settings\user\Cookies\user@fastclick[2].txt
    IGetNet: Redirected host IE Auto Search = 207.36.196.189 (Redirected host, nothing done)


    What is that redirected host???? Does any of this mean anything???

    From Hijack This

    Inline log removed!

    Also, did you want me to remove quicktime and realone player? If so should I do it in the add/remove section or the regedit??

    Thank you so much.
     
    Last edited by a moderator: Aug 6, 2007
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Too many questions...

    Re-read my FAQ on spyware, especially the part about cookies. Dont sweat the cookies too much. I have been infecting a sytem for testing purposes and many of these delte some cookies, then ignore cookies related to the spyware they removed, and ignore many others like porn cookies. Cookies as spyware is overrated.

    Yes, you can kill real and quicktime, free up some memory.

    I think I also mentioned to start going to Google and look things up. Only took me 30 seconds to find what Igetnet is. Its very difficult for us to know what people have installed, you need to be more attentive to what you install and what you allow on the new, so you know what most of these are.
    http://www.igetnet.com/
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    On my way out, saw

    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

    In the other post, its WinZip, not needed.

    Also saw Microsoft Office stuff, not needed unless you rely on it.

    Note the file paths, see what looks familiar, you will recognize a lot of things, get them out first, so we do not have to guess or look up what you may have installed :)
     
  4. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    Agreed with MA help us to help you ;)

    This should all go
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchexe.com/searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search-all.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://searchexe.com/passthrough/in...ts.yahoo.com/b1
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    This is definitely Spyware
    O4 - HKLM\..\Run: [zzb] c:\WINNT\System32\zzb.exe
    So you need to fix it with HJT then on reboot go into safe mode and delete it, you will need to show hidden files and folders ;)

    These look very suspicious
    O4 - HKLM\..\Run: [MTAHOVCJ] C:\WINNT\MTAHOVCJ.exe
    O4 - HKLM\..\Run: [DGW] C:\WINNT\DGW.exe
    O4 - HKLM\..\Run: [ipmtmd] C:\WINNT\ipmtmd.exe

    If you dont know what they are then you probably need to fix and delete them

    Theres possibly more but i havent really got time at the moment
     
  5. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    forgot to post this one

    O4 - HKLM\..\Run: [rreg] C:\Program Files\Common Files\System\rreg.exe

    you need to fix that and delete the file on reboot


    Best bet is to Use Google to filter out the bad stuff, nothing beats the satisfaction of fixing problems yourself ;)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! You watch mine, I'll watch yours! :)

    Agreed it should be deleted too.

    Any idea what this is:

    O4 - HKLM\..\Run: [BEILORVY] C:\WINNT\BEILORVY.exe
     
    Last edited: May 12, 2004

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds