Add me to the list of people who cant get rid of "CWS". I have a users laptop that is running Windows XP Pro, SP1, IE6, fully patched, and running Symantec Antivirus Corporate ver 8.1.
I have tried everything from CWShredder to Webroot's spysweeper and SpyBot Search and Destroy. I recently ran hijack this and i will post the logs if it will help.
My browser is hijacked and changes to about:blank, also if its related or not i am not sure but Symantec Antivirus pops up every 5 seconds and saying this....
Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Backdoor.Trojan
File: C:\WINDOWS\System32\winjn.
dll
Location: C:\WINDOWS\System32
Computer: JHOLST-LT
User: jahad1
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Thursday, July 22, 2004 3:33:41 PM
I have tried to delete this file and it says it is in use or i dont have permission. I am logged in as local admin. I have tried in safe mode but it is not present.
Here are the logs from hijackthis, i hope all this helps. Any help will greatly appreciated. Thanks in advance for your help.
Logfile of HijackThis v1.95.1
Scan saved at 3:22:38 PM, on 7/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\ibmpms
vc.exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\MS\SMS\CORE\BIN
\CLISVCL.E
XE
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
C:\WINDOWS\System32\QCONSV
C.EXE
C:\WINDOWS\MS\SMS\clicomp\
apa\Bin\sm
sapm32.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\Program Files\ThinkPad\ConnectUtil
ities\QCWL
ICON.EXE
C:\PROGRA~1\ThinkPad\PkgMg
r\HOTKEY\T
PHKMGR.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\WINDOWS\MS\SMS\CORE\BIN
\LAUNCH32.
EXE
C:\Program Files\ORiNOCO\WirelessClie
nt\Utility
\orinoco.e
xe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\ThinkPad\PkgMgr\HOTK
EY\TPONSCR
.exe
C:\Program Files\ThinkPad\PkgMgr\HOTK
EY_1\TpScr
ex.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\Novosoft\HANDY
B~1\hbagen
t.exe
C:\WINDOWS\MS\SMS\CLICOMP\
SWDist32\b
in\smsmon3
2.exe
\Cermusa_bdc_1\installs\Ut
ilities\FE
MME-BOT\hi
jackthis\H
ijackThis.
exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = file://C:\DOCUME~1\jahad1\
LOCALS~1\T
emp\sp.htm
l
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = file://C:\DOCUME~1\jahad1\
LOCALS~1\T
emp\sp.htm
l
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = file://C:\DOCUME~1\jahad1\
LOCALS~1\T
emp\sp.htm
l
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.
htm
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main\,HomeOldSP = about:blank
O2 - BHO: (no name) - {00000000-623A-11D4-BCDB-0
0500413177
1} - C:\WINDOWS\system32\VgIEHe
lper1-2-0-
47.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtil
ities\QCWL
ICON.EXE
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMg
r\HOTKEY\T
PHKMGR.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINDOWS\MS\SMS\CORE\BIN
\LAUNCH32.
EXE
O4 - HKLM\..\Run: [proxim_orinoco_11abg] C:\Program Files\ORiNOCO\WirelessClie
nt\Utility
\orinoco.e
xe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [Handy Backup 4.0] "C:\PROGRA~1\Novosoft\HAND
YB~1\hbage
nt.exe" -logon
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: Research (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {3E68E405-C6DE-49FF-83AE-4
1EE9F4C36C
E} (Office Update Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {62475759-9E84-458E-A1AB-5
D2C442ADFD
E} -
http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exeO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38044.4516550926O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = cermusa.francis.edu
O17 - HKLM\Software\..\Telephony
: DomainName = cermusa.francis.edu
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = cermusa.francis.edu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: Research (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {3E68E405-C6DE-49FF-83AE-4
1EE9F4C36C
E} (Office Update Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {62475759-9E84-458E-A1AB-5
D2C442ADFD
E} -
http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exeO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38044.4516550926O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = cermusa.francis.edu
O17 - HKLM\Software\..\Telephony
: DomainName = cermusa.francis.edu
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = cermusa.francis.edu