Joined
·
20 Posts
What do I do?
I have Spy Bot, High Jack This, Adaware Se, Spysubtract and Norton System Worksm, and the CW shredder. Help me please. When I run the Adware it comes up with this log file that says Coolwebsearch but when i run the CW Shredder it doesn't find anything? Neither does Norton's, spybot or spysubtract. What TO DO? AHHHHHHHHHHHHHHHHHHHHHHHHH
Included Log Files are Ad-Aware, HJT, And CW Shredder
Ad=Aware Log File
ArchiveData(auto-quarantine- 2005-01-13 18-50-16.bckp)
Referencefile : SE1R25 11.01.2005
======================================================
COOLWEBSEARCH
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=RegValue : S-1-5-21-3530227025-2539077170-1886978122-1005\software\microsoft\internet explorer\main "HOMEOldSP"
obj[1]=RegValue : software\microsoft\internet explorer\main "HOMEOldSP"
obj[2]=Regkey : protocols\filter\text/plain
obj[3]=RegValue : protocols\filter\text/plain "CLSID"
obj[4]=Regkey : protocols\filter\text/html
obj[5]=RegValue : protocols\filter\text/html "CLSID"
obj[6]=Regkey : software\microsoft\windows\currentversion\uninstall\searchassistant uninstall
obj[7]=RegValue : software\microsoft\windows\currentversion\uninstall\searchassistant uninstall "DisplayName"
obj[8]=RegValue : software\microsoft\windows\currentversion\uninstall\searchassistant uninstall "UninstallString"
obj[9]=RegValue : software\microsoft\internet explorer\search "SearchAssistant"
obj[10]=RegValue : software\microsoft\internet explorer\main "Search Bar"
obj[11]=RegValue : software\microsoft\internet explorer\main "Use Custom Search URL"
obj[12]=RegValue : software\microsoft\internet explorer\main "Use Search Asst"
obj[13]=RegValue : software\classes\protocols\filter\text/html "CLSID"
CW SHREDDER Log Report
**** Run Keys ****
RUN: [HTpatch] C:\WINDOWS\htpatch.exe
RUN: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
RUN: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
RUN: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
RUN: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
RUN: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
RUN: [AGRSMMSG] AGRSMMSG.exe
RUN: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
RUN: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
RUN: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
RUN: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
RUN: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
RUN: [SiS Tray]
RUN: [CTHelper] CTHELPER.EXE
RUN: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /startup /scheduler
**** Browser Helper Objects ****
BHO: [Yahoo! Companion BHO] C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
BHO: [AcroIEHlprObj Class] C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
BHO: [] C:\PROGRA~1\SPYBOT~1\SDHelper.dll
BHO: [] C:\PROGRA~1\SPYBOT~1\SDHelper.dll
BHO: [CNisExtBho Class] C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
BHO: [CNisExtBho Class] C:\WINDOWS\system32\ghcd.dll
BHO: [CNavExtBho Class] C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
**** IE Toolbars ****
TOOLBAR: [Web assistant] C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
TOOLBAR: [&Yahoo! Companion] C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
TOOLBAR: [Norton AntiVirus] C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
**** IE Extensions ****
IEExt: [Yahoo! Login]
IEExt: [Messenger]
IEExt: [Messenger] C:\Program Files\Messenger\msmsgs.exe
**** Hosts File Entries ****
HOSTS: 127.0.0.1 localhost
HOSTS: 127.0.0.1 localhost
**** IE Settings ****
IEBypass: 127.0.0.1
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: about:blank
**** IE Context Menu (Right click) ****
IEContext: [Yahoo! Dictionary] file:///C:\Program Files\Yahoo!\Common/ycdict.htm
IEContext: [Yahoo! Search] file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
**** Layered Service Providers ****
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BB1E9D1B-E28B-4648-A7A0-CD85F8593DDC}] SEQPACKET 8
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BB1E9D1B-E28B-4648-A7A0-CD85F8593DDC}] DATAGRAM 8
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E7691295-E4C9-42B4-A317-54336593B2BA}] SEQPACKET 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E7691295-E4C9-42B4-A317-54336593B2BA}] DATAGRAM 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{03E3F243-9017-4CD5-98C8-111862DB3C5C}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{03E3F243-9017-4CD5-98C8-111862DB3C5C}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{11E89CCC-7894-4A18-B6E5-F94533A364C5}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{11E89CCC-7894-4A18-B6E5-F94533A364C5}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3DCFE92E-C6CA-4F48-BCC9-A281D2F2291C}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3DCFE92E-C6CA-4F48-BCC9-A281D2F2291C}] DATAGRAM 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{069AAABD-BE38-4B01-8F7A-2618D2F9B5E6}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{069AAABD-BE38-4B01-8F7A-2618D2F9B5E6}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A9DA7628-759F-4E36-8909-5AF916E6019E}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A9DA7628-759F-4E36-8909-5AF916E6019E}] DATAGRAM 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{155372E7-4995-4860-83EA-90D96DB9D44E}] SEQPACKET 6
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{155372E7-4995-4860-83EA-90D96DB9D44E}] DATAGRAM 6
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1A3204EF-7E6F-4004-A15A-B7226CEF0FFC}] SEQPACKET 7
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{1A3204EF-7E6F-4004-A15A-B7226CEF0FFC}] DATAGRAM 7
**** Blocked Control Panel Items ****
BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No
**** Downloaded Program Files ****
DirectAnimation Java Classes [file://C:\WINDOWS\Java\classes\dajava.cab]
Microsoft XML Parser for Java [file://C:\WINDOWS\Java\classes\xmldso.cab]
{33564D57-9980-0010-8000-00AA00389B71} [http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab]
{644E432F-49D3-41A1-8DD5-E099162EEEC5} [http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab] C:\WINDOWS\Downloaded Program Files\CONFLICT.1\rufsi.dll
{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} [https://www-secure.symantec.com/techsupp/activedata/SymAData.cab]
{E77C0D62-882A-456F-AD8F-7C6C9569B8C7} [https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab]
**** Windows Services ****
[Alerter] %SystemRoot%\System32\svchost.exe -k LocalService
[ALG] %SystemRoot%\System32\alg.exe
[AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs
[AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[BITS] %SystemRoot%\System32\svchost.exe -k netsvcs
[Browser] %SystemRoot%\System32\svchost.exe -k netsvcs
[ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
[ccProxy] "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"
[ccPwdSvc] "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
[ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
[CiSvc] %SystemRoot%\system32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[COMSysApp] C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
[CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch
[DeepsightExtractor] C:\Program Files\Symantec\DeepSight Extractor\ExtractorService.exe
[Dhcp] %SystemRoot%\System32\svchost.exe -k netsvcs
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[Dnscache] %SystemRoot%\System32\svchost.exe -k NetworkService
[ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINDOWS\System32\svchost.exe -k netsvcs
[FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs
[helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs
[HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter
[ImapiService] C:\WINDOWS\System32\imapi.exe
[lanmanserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[lanmanworkstation] %SystemRoot%\System32\svchost.exe -k netsvcs
[LmHosts] %SystemRoot%\System32\svchost.exe -k LocalService
[Messenger] %SystemRoot%\System32\svchost.exe -k netsvcs
[mnmsrvc] C:\WINDOWS\System32\mnmsrvc.exe
[MSDTC] C:\WINDOWS\System32\msdtc.exe
[MSIServer] C:\WINDOWS\System32\msiexec.exe /V
[navapsvc] "C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe"
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\System32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[Nla] %SystemRoot%\System32\svchost.exe -k netsvcs
[NProtectService] C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
[NtLmSsp] %SystemRoot%\System32\lsass.exe
[NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[NVSvc] %SystemRoot%\System32\nvsvc32.exe
[PlugPlay] %SystemRoot%\system32\services.exe
[Pml Driver HPZ12] C:\WINDOWS\System32\HPZipm12.exe
[PolicyAgent] %SystemRoot%\System32\lsass.exe
[ProtectedStorage] %SystemRoot%\system32\lsass.exe
[RasAuto] %SystemRoot%\System32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\System32\svchost.exe -k netsvcs
[RDSessMgr] C:\WINDOWS\system32\sessmgr.exe
[RemoteAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[RpcLocator] %SystemRoot%\System32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\System32\rsvp.exe
[SamSs] %SystemRoot%\system32\lsass.exe
[SAVScan] "C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe"
[SBService] C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\System32\svchost.exe -k netsvcs
[seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[SharedAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[ShellHWDetection] %SystemRoot%\System32\svchost.exe -k netsvcs
[SNDSrvc] "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
[Speed Disk service] C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
[Spooler] %SystemRoot%\system32\spoolsv.exe
[SPTISRV] C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
[srservice] %SystemRoot%\System32\svchost.exe -k netsvcs
[SSDPSRV] %SystemRoot%\System32\svchost.exe -k LocalService
[stisvc] %SystemRoot%\System32\svchost.exe -k imgsvc
[SwPrv] C:\WINDOWS\System32\dllhost.exe /Processid:{37DB0F18-FF2E-47F9-BE47-2C15F16C4048}
[Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
[SymWSC] "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"
[SysmonLog] %SystemRoot%\system32\smlogsvc.exe
[TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[TermService] %SystemRoot%\System32\svchost -k DComLaunch
[Themes] %SystemRoot%\System32\svchost.exe -k netsvcs
[TrkWks] %SystemRoot%\system32\svchost.exe -k netsvcs
[UMWdf] C:\WINDOWS\system32\wdfmgr.exe
[upnphost] %SystemRoot%\System32\svchost.exe -k LocalService
[UPS] %SystemRoot%\System32\ups.exe
[VAIOMediaPlatform-MusicServer-AppServer] "C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application)"
[VAIOMediaPlatform-MusicServer-HTTP] "C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP"
[VAIOMediaPlatform-MusicServer-UPnP] C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
[VAIOMediaPlatform-PhotoServer-AppServer] C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
[VAIOMediaPlatform-PhotoServer-HTTP] "C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP"
[VAIOMediaPlatform-PhotoServer-UPnP] C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
[VSS] %SystemRoot%\System32\vssvc.exe
[W32Time] %SystemRoot%\System32\svchost.exe -k netsvcs
[WebClient] %SystemRoot%\System32\svchost.exe -k LocalService
[winmgmt] %systemroot%\system32\svchost.exe -k netsvcs
[WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs
[WmiApSrv] C:\WINDOWS\System32\wbem\wmiapsrv.exe
[wscsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[wuauserv] %systemroot%\system32\svchost.exe -k netsvcs
[WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs
[xmlprov] %SystemRoot%\System32\svchost.exe -k netsvcs
**** Custom IE Search Items ****
SEARCH: [SearchAssistant] about:blank
SEARCH: [SearchAssistant] about:blank
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SEARCH: [CustomSearch] http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
**** Complete IE Options ****
IEOPT: [NoUpdateCheck]
IEOPT: [NoJITSetup]
IEOPT: [Disable Script Debugger] yes
IEOPT: [Start Page] about:blank
IEOPT: [Show_ChannelBand] No
IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search]
IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [Search Page] about:blank
IEOPT: [Check_Associations] No
IEOPT: [FullScreen] no
IEOPT: [AutoSearch]
IEOPT: [Window_Placement] ,
IEOPT: [ShowedCheckBrowser] Yes
IEOPT: [NotifyDownloadComplete] yes
IEOPT: [AddToFavoritesExpanded]
IEOPT: [Use FormSuggest] yes
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Expand Alt Text] no
IEOPT: [Move System Caret] no
IEOPT: [NscSingleExpand]
IEOPT: [NoWebJITSetup]
IEOPT: [Page_Transitions]
IEOPT: [FavIntelliMenus] no
IEOPT: [UseThemes]
IEOPT: [Force Offscreen Composition]
IEOPT: [AllowWindowReuse]
IEOPT: [Friendly http errors] yes
IEOPT: [ShowGoButton] yes
IEOPT: [SmoothScroll]
IEOPT: [Enable AutoImageResize] yes
IEOPT: [Enable_MyPics_Hoverbar] yes
IEOPT: [Play_Animations] yes
IEOPT: [Play_Background_Sounds] yes
IEOPT: [Display Inline Videos] yes
IEOPT: [Show image placeholders]
IEOPT: [Print_Background] no
IEOPT: [LastCheckedHi]
IEOPT: [FormSuggest Passwords] yes
IEOPT: [FormSuggest PW Ask] yes
IEOPT: [Use Search Asst] no
IEOPT: [Toolbars_Placement] ;èAw_æ·aÿw©yjBnÅO±Sÿÿÿÿ
IEOPT: [Use Custom Search URL]
IEOPT: [HOMEOldSP] about:blank
IEOPT: [Search Page] about:blank
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk]
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Local Page] C:\WINDOWS\system32\blank.htm
IEOPT: [Anchor_Visitation_Horizon]
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width]
IEOPT: [Placeholder_Height]
IEOPT: [Start Page] about:blank
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
IEOPT: [Wizard_Version] 6.0.2524.0000
IEOPT: [Check_Associations] yes
IEOPT: [FullScreen] no
IEOPT: [HOMEOldSP] about:blank
IEOPT: [Use Search Asst] no
IEOPT: [Use Custom Search URL]
Attachments
-
9.9 KB Views: 20