Remove cws.msconfig

Discussion in 'Malware Help (A Specialist Will Reply)' started by minorgeek2, Sep 14, 2006.

  1. minorgeek2

    minorgeek2 Private E-2

    Hello all,

    I think my system was infected by cws.msconfig. CWshredder is the only program that is finding this. I have gone through the Before You Post stuff and it continues to show up. I have tried deleting it but it reappears within a few seconds. I have used (SpyBot S&D, Ad-Aware SE, XoftSpy,ewido, Windows Defender, and Panda on-line scan) but none of these can find anything wrong. If anyone has any ideas on how to remove this please let me know.
     
  2. minorgeek2

    minorgeek2 Private E-2

    Here is my HJThis log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Not according to your log! And also if you had, you would have attach all the other requested logs! You may have done some of the steps but not all of them. In addition, you are even using MSconfig which we clearly specify in step 7 not to use.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. minorgeek2

    minorgeek2 Private E-2

    I'm sorry but I did not and do not see that part in step 7. I will go through it all again, but the problem I am having is with MSconfig, which I can not get rid of.


    7: HijackThis log posting

    Since so many new problems end in requiring a Hijack This! log anyway, it will be okay to post a HijackThis log if you are still having problems. But only if you have completed all the above steps and you must attach your log to your message. See: HOW TO: Attach Items To Your Post

    Also you must install HijackThis properly per the instructions in the below link. We are growing tired of saying this. If you do not listen, you are at risk of having problems if something is deleted and should not be. It will be YOUR FAULT if you do not install HijackThis properly.

    Depending on which OS you have, you may need an application like WinZip to extract hijackthis.exe from the downloaded ZIP file.


    ***** MAKE SURE YOU CLICK THE BELOW LINK AND FOLLOW DIRECTIONS! TOO MANY PEOPLE ARE SKIPPING IT! *****

    Downloading, Installing, and Running HijackThis


    *** IMPORTANT NOTE*** Once you have HijackThis installed in the proper location, as per Downloading, Installing, and Running HijackThis. Double-Click on "My Computer", Double-Click on "(C:)"; navigate to "C:\Program Files\HJT", Right-Click on "hijackthis.exe", select "Rename", rename to "analyse.exe" ( do not rename to analyse.exe.exe ) click inside the window to complete the renaming operation, close Windows Explorer. Done.

    This is extremely important as there is a new variant of Virtumonde (Vundo), aka "Winfixer", that will not be detected unless you do the above
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read what the step says and follow the directions. I'll highlight it for you below just like it says in step 7.
    You are skipping it! It's pretty hard to miss the large red print instructions.

    When you click the link, read the second sentence and tell me what you see.

    Your problem is not with MSconfig. It is with CWS.msconfig which are totally unrelated.


     
  6. minorgeek2

    minorgeek2 Private E-2

    10-4, I see that but it is and was set for "Normal Startup" and you are correct I did skip that one.
     
  7. minorgeek2

    minorgeek2 Private E-2

    OK, I followed the procedure and here are the attachments. Panda did not give me an option to see the report but it did run clean with nothing found.
     

    Attached Files:

  8. minorgeek2

    minorgeek2 Private E-2

    Here is the HJThis, hopefully in the proper format.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmmm! Not according to HijackThis which shows:

    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    This only shows when MSconfig is used to control something. Let's try some steps below but first we need to stop Ewido and Ad-Aware's Ad-Watch or they may block the changes. So shutdown both of them first before continuing. By the way you really should not use both Ewido and Ad-watch! If Ewido is a trial version you should uninstall it. Also I see XoftSpy in your installed programs list. Is this also installed and is it a free or paid version?


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot and attach a new log from HJT.

    I don't see any real malware. You do have a few items for your laptop missing per the below in your HJT log:
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: atmgrtok - atmgrtok.dll (file missing)
     
  10. minorgeek2

    minorgeek2 Private E-2

    Here it is. yeah that seems to be the problem. No matter what I do with that file, set to Normal boot, remove in safe mode and then replaced with downloaded copy, it keeps coming back and CW has a problem with it and says it is CWS.msconfig. I removed those other programs scan programs and yes they were the free copies. Here is another copy with what you had me add to Reg.
     

    Attached Files:

  11. minorgeek2

    minorgeek2 Private E-2

    Sorry Chas, I forgot to reboot before running the new scan. Here it is.
     

    Attached Files:

  12. minorgeek2

    minorgeek2 Private E-2

    Chas,

    In AdWatch under tools there is a selection to "Lock Start-up section" could that be holding the MSConfig file to the Auto. I changed it, deleted everything for MSConfig then replaced it and it seems to be OK now. CWshredder is not finding any problems and Ad-Watch is not logging anything for that now. It is missing from the reg though.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was the reason why I was having you shutdown Ad-Watch and Ewido. I new they would block the fixing of that line. You should uninstall Windows Defender to avoid conflicts with Ad-Watch and the excess use of system resources.

    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds