CWS.Homearch removal-read priors but...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bubba12345, Apr 4, 2007.

  1. Bubba12345

    Bubba12345 Private E-2

    Hello

    I think I obeyed the rules on posting. I still cannot remove CWS.homesearch after following steps 0-6a. All the scans find things even after running Z A Secuirity Suite for the last year. Now using Bellsouth (AVG?) and I keep getting an alert for CWS.Homesearch popping up. ARGH!!! Spybot and Adaware SE do not find a thing. Bellsouth Internet Security seems to indicate it might be a registry issue but I don't see it that probably doesn't mean much. I've looked through the prior posts...Any help--PLEASE?

    Step 0-5 Norton quarantine files were detected even though Norton was removed a year ago. I did not even realize they were still there. Found by Counterspy. Set msconfig to normal, enabled view of hidden files, downloaded tools, booted to safe, ran Ccleaner, ran spybot not using tea- timer-nothing found, ran counterspy, have latest Java version, ran bitdefender and Pandascan-logs attached. Panda finds 5 spyware issues and tells me to buy their stuff. Like a genius, I didn't save the scan log but I am running it now in normal and will post it ASAP. I will also complete 6B after that step is posted.

    I really appreciate any help you may have on this...
     

    Attached Files:

  2. Bubba12345

    Bubba12345 Private E-2

    Here's the Panda scan log and my Bellsouth scan showing a register issue.

    ANY help is greatly appreciated
     

    Attached Files:

  3. Bubba12345

    Bubba12345 Private E-2

    AND here are the Getrunkey and shownew txt files
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Not useful! It does not say what or where it found anything.

    Do you have a log that show what you are having a problem with?

    Is your HJT log from normal boot mode or safe mode?

    You may be running multiple antivirus applications which we specified in step 3 of the READ ME that you must not do. I say "may be" because I see Authentium and I see BellSouth Internet Security. Is Authentium part of Bellsouth's stuff?


    You should uninstall CounterSpy now since we don't need it anymore !

    I don't see any problems in any of your logs other than the fact that you still have part of Symantec Antivirus trying to run:
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

    And you also still have the Symantec folders and quarantine on your PC!
     
  5. Bubba12345

    Bubba12345 Private E-2

    OK sorry--I realize that the Bellsouth is unuseful- I guess that's why I'm here. It does not identify what or where the issue is other than in the registry as the log I posted shows. To be specific, the Bellsouth "system" notiies me that CWS. Homesearch is present and has not been deleted/disinfected-whatever and then they offer no help to fix said problem.
    The log is showing a register issue but that doesn't not help you-got it.

    No specific log where a problem is shown that I know of.

    HJT log is normal boot--I'll post a new log

    Uninstalled bellsouth stuff(AVG) and have no idea what Authentium is or how to remove-not in add/remove programs. Suggestions? I am unaware if I am running anything else of any kind

    Removed Counterspy

    On synmantec, how do I remove if I no longer have it on my system? the info I saw only talks about removing those files USING Norton(which no longer is on my system). I emptied the recycle bin manually per the directions in safe mode...

    Lastly do I fix that last line 023 or wait?
     
  6. Bubba12345

    Bubba12345 Private E-2

    Here are both normal and safe HJT logs
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was from safe mode. You can tell that by looking at your first log and what you just posted now.

    Look in Add/Remove programs for Authentium or Command AV and uninstall if found. Attach a new log from ShowNew.

    You need to get a new antivirus and a new firewall installed ASAP. See steps 2 & 3 of the below link and give AVG and ZoneAlarmFree a try. When you install ZoneAlarm Free, do not install the Security Suite.

    How to Protect yourself from malware!

    Install these NOW, if you have not already installed another antivirus and firewall.

    Then run this CWShredder make sure NO BROWSERS are running before you run this tool. Let me know if it finds anything.

    For Services (which is what the O23 lines are) the fix is not always that straight forward.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Lic NetConnect service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteCLTNetCnService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot, attach a new HJT log.
     
  8. Bubba12345

    Bubba12345 Private E-2

     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I requested a new HJT log! You did not attach one.

    Are you having any current problems?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed you did not upgrade Sun Java as requested in step 6 of the READ ME.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  11. Bubba12345

    Bubba12345 Private E-2

    Yes, I did download Jre-6u1 but I wasn't sure it intalled properly. Doing it again and will attach HJT log after reboot
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you uninstalled the old Sun Java first.

    You still did not say if you are having any current problems!
     
  13. Bubba12345

    Bubba12345 Private E-2

    I think we got it! Seems that by using AVG rather than Bellsouth the warning bubble goes away at least... I really have not seen another issue since installing AVG rather than the Bellsouth Suite. Here is the HJT log as requested
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay a little minor tweaking remains!


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Bubba12345

    Bubba12345 Private E-2

    Done and Thanks so much!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds