CWS Feads removal help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Btomarra, Oct 25, 2005.

  1. Btomarra

    Btomarra Private E-2

    Hello,

    I have try to run the removal tool and it hasn't worked. here is my problem. Pest Patrol has detected CWS Feads in the following registry key:

    hkey_local_machine\system\currentcontrolset\enum\root\legacy_0*008f*0010%0f*00e5*0003*0017*001a*0024*00b6*00c0*0028.

    It can't remove it. Now I am also getting a pest detected:CWS.Yexe which Pest Patrol does block.

    Will removing the registry key fix this? I have an HP Pavilion 7975 with Windows XP SP2. I have Norton Antivirus 2005 and Pest Patrol running on my machine.

    Thanks for any help you can give.
     
  2. Btomarra

    Btomarra Private E-2

    I just wanted to add to my above post that I have done all the steps for Spyware removal. CWShredder found no spyware, but it still pops up.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. Btomarra

    Btomarra Private E-2

    I have the hijackthis log attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One of your previous messages said:

    You never ran ALL the steps in the Sticky thread READ & RUN ME FIRST Before Asking for Support

    If you had I would see other software running, for example MS Antispyware. What other steps did you skip.

    First let's fix the crazywinnings problem:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixCrazy.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixCrazy.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge say yes.
    Now run IE, select Tools, Internet Options. Now select Security and then click the Trusted Sites circle. Then click the Sites button. Look for the 206.161.125.149 address in the Web sites box and select it. Then click Remove. Then at the bottom make sure there is a check mark in the box that says Require server verification...... blah blah. Now click OK. And OK again.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.quicksearch360.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.quicksearch360.com/sp2.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.quicksearch360.com/sp2.php

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot your PC and get a new HJT log after reboot and post it.
    Also tell me how things are looking now.
     
  6. Btomarra

    Btomarra Private E-2

    I'm sorry, but I printed that file and followed it line by line, step-by step. I only have Norton Antivitus and Pest Patrol running. I am new at this so any steps that may have been skipped are accidental.
     
    Last edited by a moderator: Oct 26, 2005
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See steps 4 & 6. It would appear that neither Spybot Search & Destroy or Microsoft Antispyware were run. They are rather hard to miss. Did you install and run Ad-Aware SE, what about CCleaner?

    Just complete the steps in my previous posts.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds