Options

CWS Home Search Assistant .........active.txt problem

I have recently picked up "CWS Home Search assistant" in spyware doctor that I like everyone else cannot get rid of. I read through the guide listed on this site of how to remove it and have came across a few things that arent listed. I would like to mention that I never get any pop ups from this site, I have simply just detected it on my spyware program. I went to RUN and typed the services.msc and wasnt able to find specific file names that matched the ones recommended, so as instructed I downloaded the Services.vbs file and ran it. I didnt find ANY file that had unusual characters behind a service name. I booted into safe mode and still nothing. Should I go ahead with the rest of the guide or what do I do from here? Thanks for your assistance.

Comments

  • edited April 2006
    Here is my vbs log I forgot to include, and my HJT log:

    These are the Current Active Services:

    Adobe Active File Monitor V4: AdobeActiveFileMonitor4.0
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe

    Application Layer Gateway Service: ALG
    C:\WINDOWS\System32\alg.exe

    Windows Audio: AudioSrv
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Computer Browser: Browser
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Cryptographic Services: CryptSvc
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    DHCP Client: Dhcp
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Error Reporting Service: ERSvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    COM+ Event System: EventSystem
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Fast User Switching Compatibility: FastUserSwitchingCompatibility
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Help and Support: helpsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    HID Input Service: HidServ
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Server: lanmanserver
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Workstation: lanmanworkstation
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Network Connections: Netman
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Network Location Awareness (NLA): Nla
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Task Scheduler: Schedule
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Secondary Logon: seclogon
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    System Event Notification: SENS
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Windows Firewall/Internet Connection Sharing (ICS): SharedAccess
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Shell Hardware Detection: ShellHWDetection
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Themes: Themes
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Distributed Link Tracking Client: TrkWks
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Windows Time: w32time
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Windows Management Instrumentation: winmgmt
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Security Center: wscsvc
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    Automatic Updates: wuauserv
    C:\WINDOWS\system32\svchost.exe -k netsvcs

    Wireless Zero Configuration: WZCSVC
    C:\WINDOWS\System32\svchost.exe -k netsvcs

    AVG7 Alert Manager Server: Avg7Alrt
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

    AVG7 Update Service: Avg7UpdSvc
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

    CA ISafe: CAISafe
    C:\WINDOWS\system32\ZoneLabs\isafe.exe

    DCOM Server Process Launcher: DcomLaunch
    C:\WINDOWS\system32\svchost -k DcomLaunch

    Terminal Services: TermService
    C:\WINDOWS\System32\svchost -k DComLaunch

    DNS Client: Dnscache
    C:\WINDOWS\System32\svchost.exe -k NetworkService

    Event Log: Eventlog
    C:\WINDOWS\system32\services.exe

    Plug and Play: PlugPlay
    C:\WINDOWS\system32\services.exe

    TCP/IP NetBIOS Helper: LmHosts
    C:\WINDOWS\System32\svchost.exe -k LocalService

    WebClient: WebClient
    C:\WINDOWS\System32\svchost.exe -k LocalService

    Machine Debug Manager: MDM
    "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"

    IPSEC Services: PolicyAgent
    C:\WINDOWS\System32\lsass.exe

    Protected Storage: ProtectedStorage
    C:\WINDOWS\system32\lsass.exe

    Security Accounts Manager: SamSs
    C:\WINDOWS\system32\lsass.exe

    Retrospect Express HD Launcher: RetroExpLauncher
    C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe

    Remote Procedure Call (RPC): RpcSs
    C:\WINDOWS\system32\svchost -k rpcss

    Print Spooler: Spooler
    C:\WINDOWS\system32\spoolsv.exe

    Windows Image Acquisition (WIA): stisvc
    C:\WINDOWS\System32\svchost.exe -k imgsvc

    Windows User Mode Driver Framework: UMWdf
    C:\WINDOWS\system32\wdfmgr.exe

    TrueVector Internet Monitor: vsmon
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe -service


    HJT LOG:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097769273671
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
  • edited April 2006
    Anyone?
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited April 2006
    One of our Spyware Guru's should be along soon. :)

    In the meantime, try downloading CWShredder v2.19 and give that a shot.

    Also, you HijackThis log looks a little on the thin side - are you sure you copied everything from the log? Post a new one after you try CWShredder.
  • edited April 2006
    profdlp wrote:
    One of our Spyware Guru's should be along soon. :)

    In the meantime, try downloading CWShredder v2.19 and give that a shot.

    Also, you HijackThis log looks a little on the thin side - are you sure you copied everything from the log? Post a new one after you try CWShredder.



    OK................I ran CWShredder and when it got to the part where it scans for CWS.HomeSearchAssistant it reads "not found". Im not sure why, but it does. The only place that Im showing CWS Home Search Assistant is in spyware doctor when I run a scan. Here is a copy of my new HJT log:

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\ZoneLabs\isafe.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zo3nealarm.exe
    C:\Documents and Settings\***MYNAME***.DCRS1R51\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097769273671
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


    I would like to also add that I have ran all scans such as HJT, 2 antivirus programs, Asquared, spybot and spyware blaster, and 2 registry error programs. Ever since this has happened Zone alarm pro wont run at startup or wont display correctly. I cant use any of the options on it due to this. Here is what it looks like and also a copy of what spyware doctor is showing. I get NO pop up screens or redirects, I simply detect it on spyware doctor.
  • edited April 2006
    Here are the screen shots. The zone alarm is big I know, but I wanted you to see all of it. Like I mentioned, the primary problem Im having is determining what to do since I cant find any of the bogus services and all of mine appear to be genuine.
  • edited April 2006
    I just removed zone alarm pro and re installed it and its fine for now.
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited April 2006
    It wouldn't be the first time that a security program gave a false positive on something. I hope things stay "OK" for you. :)
  • edited April 2006
    The only thing that has really happened was google got hijacked and it would redirect me to a foreign google page no matter how I tried to enter it and a lot of pages were comming up unavailable, but other then that I havnt noticed the other stuff.

    Oh...............btw...........when I try to remove it on spyware doctor I get a message saying that something has been removed from the memory and needs to shut down and restart to prevent damage or something of that nature. Anyways, it then shuts down and restarts and begins scanning again.
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited April 2006
    JOEYZ wrote:
    The only thing that has really happened was google got hijacked and it would redirect me to a foreign google page no matter how I tried to enter it...
    Did you check under "preferences" at Google?
    Oh...............btw...........when I try to remove it on spyware doctor I get a message saying that something has been removed from the memory and needs to shut down and restart to prevent damage or something of that nature. Anyways, it then shuts down and restarts and begins scanning again.
    If a program is in use it can't be completely deleted. It sounds like Spyware Doctor is trying to reboot in a (quasi) Safe Mode to finish the removal. Did you let the second scan run all the way through?
  • edited April 2006
    Yeah............I let it run all the way through. Anytime that it runs and shows up as having the CWS infection I click on "remove" and then it reboots and starts scanning again only to come back to the screen where it says "remove".
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited April 2006
    Does it give you any idea where the CWS files are located? If so, try booting up in Safe Mode and maually deleting them. You should clear your browser cache and empty your temp folder, too. (As much as possible - there will be a few that can't be dumped; this is normal.) Do this (again, in Safe Mode) for all users on the computer.

    The temp folder(s) are located here:

    C:\Documents and Settings\username\Local Settings\Temp
  • edited April 2006
    Nah..............it wont tell me and even if it does remve it which it did once, like so many other people experienced............it just comes right back once you reboot.
  • edited May 2006
    Ok..........I expanded the spyware doctor log and it lists the file locations of 2 imfections. The problem is...........one of these is my firewall? What do I do now? Attached is a copy of the log.
  • TroganTrogan London, UK
    edited May 2006
    Those are not malicious files. Like prof said earlier, Spyware Doctor is finding False Positives. Try to get Spyware Doctor to ignore those findings, if possible.

    There's nothing to worry about! :)
  • edited May 2006
    Those are not malicious files. Like prof said earlier, Spyware Doctor is finding False Positives. Try to get Spyware Doctor to ignore those findings, if possible.

    There's nothing to worry about! :)


    Can you explain a little further. Why is it comming up with that name specifically if its false? Ive always used other spyware programs such as adaware, spybot, ect.................that dont list stuff like this. I know that it is now after searching the files, but Im curious about what is making it show up positive..............ya know. Thanks by the way guys. I appreciate it.
  • TroganTrogan London, UK
    edited May 2006
    Its most likely to do with the scanning engine used by Spyware Doctor. SD thinks that those files are malicious so flags them for removal.
Sign In or Register to comment.