cws make me mad arggg

Discussion in 'Malware Help (A Specialist Will Reply)' started by xcheesemasterx, Aug 4, 2004.

  1. xcheesemasterx

    xcheesemasterx Private E-2

    ok so i have cws...that about:page thing and i've used just about everything to remove it. i have the latest windows update and i use ad-aware, spybot s&d, hijackthis!, ccleaner, cwshredder, spywareblaster, and aboutbuster. so can somebody PLEASE help me remove it. my HJT log is attached...
     

    Attached Files:

  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. xcheesemasterx

    xcheesemasterx Private E-2

    k thx :-D
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right now I do not see the typical O2 BHO hijacker dll so I'm not sure if it is just temporarily missing or it is fixed. Try the easy approach right now and let's see what happens.

    Run HijackThis and put check marks on the following lines (do not Fix yet):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html

    Now make sure all Internet Explorer and Windows Explorer sessions are terminated. The click Fix on HijackThis. Let me know if you are still being Hijacked. If so and it still looks similar to your previous HijackThis log, do not try to fix it using anything. Just post a new HijackThis log attachment. I do not believe the type you may have is fixable with About:Buster.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Chaslang, you think closing his browser and using a program like CCleaner might help too as it should delete the files in question?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could! The HijackThis lines will still have to be fixed though. But if the DLL, AppInit_DLL, or StreamingDevice DLL (the last two are always very hidden) is still there neither CCleaner or just having HijackThis fix the R0 &R1 registry entries will work.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds