RE: IE default Page

From: Ed Wittmann (wittmann_at_sae.org)
Date: 07/16/04

  • Next message: Joe Stewart: "Re: Malware(?) inserting porn links into registration/profile data for unsuspecting users"
    Date: Fri, 16 Jul 2004 12:48:38 -0400
    To: <incidents@securityfocus.com>
    
    

    I work at a major retailer's tech bench part time - we see boatloads of
    this stupid thing, usually accompanied by what is defined as a backdoor
    trojan, per housecall.antivirus.com's virus scanner.

    1 - 2 services (usually Network Security Service, and/or Security
    Agent) followed by the viral infection noted above.

    This is how I got rid of it:

    boot into safe mode with networking as the user account (not the
    Adminstrator account)
    kill off those services (regedit and delete the references after you
    stop the services)
    run hijackthis and kill whatever you see that doesn't belong
    run virus scanning (Trendmicro's housecall works real well for this)
    delete (not clean) the affected files
    run hijackthis and kill whatever you see that doesn't belong
    run a good spyware checker (we've been using Spy Sweeper) and delete
    everything else you see
    remove the spyware-installing apps (usually wintools or p2p
    networking)
    done.

    it's almost not worth it in terms of time to fix. re-format is a surer,
    and quicker, fix.

    >>> "Hagen, Eric" <ehagen@DenverNewspaperAgency.com> 16-Jul-04 11:21:54
    AM >>>
    I use "HijackThis" and have had success beating it. For most of my
    intensive Adware removal, I copy HiJackThis and CWShredder to the hard
    disk
    and then reboot the machine in safe mode. Then I manually kill all of
    the
    processes that it will allow me to kill... then run Hijackthis and
    cwshredder and take note of where the files are. I then go in and
    manually
    delete those files. CoolWebSearch hasn't been nearly as much problem
    for
    us as "TVMedia" and "WinTools" or a few of the other ones that have
    multiple
    threads and/or system services that watch the system processes and
    restart
    each other when one of them is killed. WinTools is an amazingly
    resilient
    program that uses this method with 2 processes PLUS a system service
    all
    watching each other.

    Interestingly enough, aren't they one of the companies who sued
    Symantec
    when they tried to add CWS as a "virus" to their definitions. After
    all,
    it's an "advertising engine" not a "virus" and they (like GMT and
    Gator)
    have been aggressive in pressing legal action against anyone who tries
    to
    "automatically" remove their "program".

    Eric

    -----Original Message-----
    From: wnorth [mailto:wnorth@verizon.net]
    Sent: Thursday, July 15, 2004 6:46 PM
    To: incidents@securityfocus.com
    Subject: IE default Page

    Interesting bug going around, coolwebsearch, has anyone been successful
    in
    removing this virus from a system? It looks like it recreates the DLL
    under
    c:\windows\system32 and renames it after a few reboots. It's pretty
    annoying
    and I haven't been able to fully contain it.

    Thoughts? Suggestions? I've used highjackthis, cwshredder and a few
    spyware
    detectors, but nothing is really fixing the problem.

    Thanks,

    -Wes


  • Next message: Joe Stewart: "Re: Malware(?) inserting porn links into registration/profile data for unsuspecting users"

    Relevant Pages

    • Re: res://zeeyh.dll/index.html#37049
      ... Parasites, spyware malware basics: ... Spybot S&D requires special attention, as does HijackThis ... Other tutorials for Spybot S&D ... Virus Cleaner - free virus & worm removal tool ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Newbie -- how to make a broadband safe and secure???
      ... >any virus software before I went to do a Google search, ... Install and run Spybot. ... Install and run HijackThis. ...
      (alt.computer.security)
    • Re: ie redirects
      ... Check for Spyware - How-to ... as does HijackThis (Only more so. ... Other tutorials for Spybot S&D ... Virus Cleaner - free virus & worm removal tool ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: ccLogviewer error message
      ... possibly a virus. ... From a different, clean machine download Stinger ... and HijackThis from http://aumha.org/freeware.htm. ... Do not install drivers from Windows Update. ...
      (microsoft.public.windowsxp.general)
    • Re: Windows XP using 100% CPU without any applications running
      ... adware or any virus and cleaned up registry. ... > If you’re still having problems after running these then run HijackThis ... Download it and the ... > Symantec Online Virus and Security Scan: ...
      (microsoft.public.windowsxp.general)