I'm experiencing problems with IE 6 under windows 98. the startup page keeps
resetting to about:blank which shows a search page with a bunch of
categories. i used CWShredder 1.57.0 with up to date patterns to clean up
CWS and it said it got rid of the searchx strain. however, the problem
didn't go away. i tried running CWShredder again and again it reported
searchx to be present and that it cleaned it up. any idea how to acutally
get rid of it? thanks for any help,

gary

--
Gary Roach
ADB Services

Re: CWS searchx strain won't go away by Bill

Bill
Tue May 18 17:45:23 CDT 2004

I'm going to post two messages here, both from a thread in this same group,
and not very far away in time.

The second is from PABear - giving Mike Burgess' (old) recipe for removal of
about:blank.

However, read Mike Burgess' current advice first:
----------------------------------------------------------------------------------------
PA Bear,
FYI: the (CWS) infection for "About:Blank" seems to have morphed.

About the only method that seems to work now is to discover the culprit
dll, then install the "Recovery Console", boot to that, then
"attrib -r -h -s"
the culprit dll. Then "del <filename>.dll", then clean up the Registry with
CWShredder and Ad-Aware ... = PITA!

In some cases you can discover the culprit by running Defrag, there will
be a (culprit dll) filename noted in the log.
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 05-15-04]
Please post replies to this Newsgroup, email address is invalid
--
---------------------------------------------------------------------------------------------------

PA Bear writes:

[Posted numerous times in this newsgroup: http://snipurl.com/6hka]

Here is MVP Mike Burgess' fix for CWS.Searchx (a CWS.Aboutblank variant):

<paste>
Ok, here goes ... this is my "How To:" (Hint: print out the below)

[Tools and files needed]

Download: "RepairAppInit.reg" (XP\2K only!)
http://www.mvps.org/winhelp2002/RepairAppInit.reg
Do not do anything with this file yet, it will be needed later.

Download: CWShredder
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Unzip, but do not run it yet, it will be needed later.

Download: Ad-Aware
http://www.lavasoft.de/software/adaware/
Install, but do not run it yet, it will be needed later.

Download: Find-All.zip
http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
Unzip, but do not run it yet, it will be needed later.

Download: WINFILE.zip
http://www10.brinkster.com/expl0iter/freeatlast/WINFILE.zip
Unzip, but do not run it yet, it will be needed later.

Download: Registrar Lite [freeware]
http://www.resplendence.com/download
Install, but do not run it yet, it will be needed later.

[Step1]

Double-click the included "Find-All.bat" file from Find-All.zip.
Generates: "output.txt"
Note: if infected you will see:

Locked file(s) found...
C:\WINDOWS\System32\<filename> +++ File read error
Where "<filename>" is the hidden invisable installer.
Note: "+++ File read error" is not an error, this just identifies the
culprit.

[Step2]

Run "Registrar Lite" and navigate to:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
Double click on "AppInit_DLLs" entry (right pane)
The size will likely be something other than "1" (if infected)
IMPORTANT: Make a note of the filename and location (folder)

[Step3]

Rename the highlighted "Windows" key (left pane)
To rename: Right-click and select: Rename
(type) NoWindows


Double-click "AppInit_DLLs" again (right pane)
Clear (delete) the "Value" containing the .dll and click Ok.


IMPORTANT: Rename the "NoWindows" key (left pane)
To rename: Right-click and select: Rename
(type) "Windows" (no quotes) and close RegLite.

[Step 4]

Using Windows Explorer go to your root drive: (typically) "C:\"
Click File (up top) select: New > Folder
(type) "Junk" (no quotes)

Open Winfile

Navigate to System32 folder.
Click File (up top) select: Move

Copy and paste this into the 'From' box: C:\WINDOWS\System32\<filename>.dll
Copy and paste this into the 'To' box: C:\Junk\<filename>.dll

Note: where "<filename>" = culprit dll from "output.txt"

Click OK. Close Winfile
Open Windows Explorer and check in C:\Junk for the "<filename>.dll" file.

At this point see if you can rename the "<filename>.dll"
Do this several time, changing the name and extension each time.
Then see if you can "Move" to "A:\" (floppy)

[Step 5]

Locate: "RepairAppInit.reg" right-click and select: Merge
Ok the prompt

[Step 6]

Open Regedit (Start | Run (type) "regedit" (no quotes)
Use the Search function for the <filename>.dll
Click: Edit (up top) select: Find
(type) <filename>.dll, click: Find Next

Note: where "<filename>" = culprit dll from "output.txt"

Remove all instances found.Press "F3" to continue searching
until you see the "Completed" message.

Next repeat the above steps, subsitute the "secondary dll"
From: "text/html" as seen in the "output.txt"


[Step 7]

Run CWShredder and reboot.

[Step 8]
Run Ad-Aware

Reconfigure Ad-Aware for Full Scan:
Please update the reference file following the instructions here:
http://www.lavahelp.com/howto/updref/index.html

Launch the program, and click on the Gear at the top of the start screen.

Click the "Scanning" button.
Under Drives & Folders, select "Scan within Archives".
Click "Click here to select Drives + folders" and select your installed hard
drives.

Under Memory & Registry, select all options.
Click the "Advanced" button.
Under "Log-file detail", select all options.
Click the "Tweaks" button.

Under "Scanning Engine", select the following:
"Include additional Ad-aware settings in logfile" and
"Unload recognized processes during scanning."
Under "Cleaning Engine", select the following:
"Let Windows remove files in use after reboot."
Click on 'Proceed' to save these Preferences.
Please make sure that you activate IN-DEPTH scanning before you proceed.

After the above post a fresh log ...
--

Disclaimer: Renaming the "Windows" key modified some security settings.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

Right-click the "Windows" key, select: Permissions

[Example]
Before renaming the "Windows" key:

"Path"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
"Read":
*"Administrators
*Power Users
*Users"
"Write"
*"Administrators"

--
[Example]

After Renaming the key:

"Path"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
"Read":
***"Everyone"***
"Write"
*"Administrators
--

You need to check that and if 'Everyone' was added (as seen above)
You need to reset your original settings as follows:
Note: do this after removing the infection.

Right-click "Windows", select: Permissions
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

Click Advanced [button]
If the "inherit permissions" box is checked = Uncheck it.
Then select "COPY" on the prompt.

Select "Everyone Group" (if listed) and remove. (only the group)
You can individually view/edit each group settings.
Be sure "Administrators" and "System" have full control on all.
Note: Creator owner full control on Sub keys only.
"Power users" and "users" = "read control".
</paste>
--
HTH - Please Reply to This Thread

~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE), AH-VSOP

AumHa Forums
http://forum.aumha.org

What You Should Know About Spyware
http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx

----------------------------------------------------------------------------------
"Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
news:uupv08QPEHA.1048@tk2msftngp13.phx.gbl...
> I'm experiencing problems with IE 6 under windows 98. the startup page
> keeps
> resetting to about:blank which shows a search page with a bunch of
> categories. i used CWShredder 1.57.0 with up to date patterns to clean up
> CWS and it said it got rid of the searchx strain. however, the problem
> didn't go away. i tried running CWShredder again and again it reported
> searchx to be present and that it cleaned it up. any idea how to acutally
> get rid of it? thanks for any help,
>
> gary
>
> --
> Gary Roach
> ADB Services
>
>



Re: CWS searchx strain won't go away by Gary

Gary
Tue May 18 18:35:25 CDT 2004

Bill,

I saw that post but i think that's for XP. I'm running 98. when i tried
"find-all.bat" i got a bunch of errors and the output.txt file didn't list
any infection. i know that i've got CWS-searchx because CWShredder keeps
reporting it.

"Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
news:%23g5FQnSPEHA.2704@TK2MSFTNGP10.phx.gbl...
> I'm going to post two messages here, both from a thread in this same
group,
> and not very far away in time.
>
> The second is from PABear - giving Mike Burgess' (old) recipe for removal
of
> about:blank.
>
> However, read Mike Burgess' current advice first:
> --------------------------------------------------------------------------
--------------
> PA Bear,
> FYI: the (CWS) infection for "About:Blank" seems to have morphed.
>
> About the only method that seems to work now is to discover the culprit
> dll, then install the "Recovery Console", boot to that, then
> "attrib -r -h -s"
> the culprit dll. Then "del <filename>.dll", then clean up the Registry
with
> CWShredder and Ad-Aware ... = PITA!
>
> In some cases you can discover the culprit by running Defrag, there will
> be a (culprit dll) filename noted in the log.
> ____________________________________________________________
> Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
> Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
> http://www.mvps.org/winhelp2002/hosts.htm [updated 05-15-04]
> Please post replies to this Newsgroup, email address is invalid
> --
> --------------------------------------------------------------------------
-------------------------
>
> PA Bear writes:
>
> [Posted numerous times in this newsgroup: http://snipurl.com/6hka]
>
> Here is MVP Mike Burgess' fix for CWS.Searchx (a CWS.Aboutblank variant):
>
> <paste>
> Ok, here goes ... this is my "How To:" (Hint: print out the below)
>
> [Tools and files needed]
>
> Download: "RepairAppInit.reg" (XP\2K only!)
> http://www.mvps.org/winhelp2002/RepairAppInit.reg
> Do not do anything with this file yet, it will be needed later.
>
> Download: CWShredder
> http://www.spywareinfo.com/~merijn/files/hijackthis.zip
> Unzip, but do not run it yet, it will be needed later.
>
> Download: Ad-Aware
> http://www.lavasoft.de/software/adaware/
> Install, but do not run it yet, it will be needed later.
>
> Download: Find-All.zip
> http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
> Unzip, but do not run it yet, it will be needed later.
>
> Download: WINFILE.zip
> http://www10.brinkster.com/expl0iter/freeatlast/WINFILE.zip
> Unzip, but do not run it yet, it will be needed later.
>
> Download: Registrar Lite [freeware]
> http://www.resplendence.com/download
> Install, but do not run it yet, it will be needed later.
>
> [Step1]
>
> Double-click the included "Find-All.bat" file from Find-All.zip.
> Generates: "output.txt"
> Note: if infected you will see:
>
> Locked file(s) found...
> C:\WINDOWS\System32\<filename> +++ File read error
> Where "<filename>" is the hidden invisable installer.
> Note: "+++ File read error" is not an error, this just identifies the
> culprit.
>
> [Step2]
>
> Run "Registrar Lite" and navigate to:
> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
> Double click on "AppInit_DLLs" entry (right pane)
> The size will likely be something other than "1" (if infected)
> IMPORTANT: Make a note of the filename and location (folder)
>
> [Step3]
>
> Rename the highlighted "Windows" key (left pane)
> To rename: Right-click and select: Rename
> (type) NoWindows
>
>
> Double-click "AppInit_DLLs" again (right pane)
> Clear (delete) the "Value" containing the .dll and click Ok.
>
>
> IMPORTANT: Rename the "NoWindows" key (left pane)
> To rename: Right-click and select: Rename
> (type) "Windows" (no quotes) and close RegLite.
>
> [Step 4]
>
> Using Windows Explorer go to your root drive: (typically) "C:\"
> Click File (up top) select: New > Folder
> (type) "Junk" (no quotes)
>
> Open Winfile
>
> Navigate to System32 folder.
> Click File (up top) select: Move
>
> Copy and paste this into the 'From' box:
C:\WINDOWS\System32\<filename>.dll
> Copy and paste this into the 'To' box: C:\Junk\<filename>.dll
>
> Note: where "<filename>" = culprit dll from "output.txt"
>
> Click OK. Close Winfile
> Open Windows Explorer and check in C:\Junk for the "<filename>.dll" file.
>
> At this point see if you can rename the "<filename>.dll"
> Do this several time, changing the name and extension each time.
> Then see if you can "Move" to "A:\" (floppy)
>
> [Step 5]
>
> Locate: "RepairAppInit.reg" right-click and select: Merge
> Ok the prompt
>
> [Step 6]
>
> Open Regedit (Start | Run (type) "regedit" (no quotes)
> Use the Search function for the <filename>.dll
> Click: Edit (up top) select: Find
> (type) <filename>.dll, click: Find Next
>
> Note: where "<filename>" = culprit dll from "output.txt"
>
> Remove all instances found.Press "F3" to continue searching
> until you see the "Completed" message.
>
> Next repeat the above steps, subsitute the "secondary dll"
> From: "text/html" as seen in the "output.txt"
>
>
> [Step 7]
>
> Run CWShredder and reboot.
>
> [Step 8]
> Run Ad-Aware
>
> Reconfigure Ad-Aware for Full Scan:
> Please update the reference file following the instructions here:
> http://www.lavahelp.com/howto/updref/index.html
>
> Launch the program, and click on the Gear at the top of the start screen.
>
> Click the "Scanning" button.
> Under Drives & Folders, select "Scan within Archives".
> Click "Click here to select Drives + folders" and select your installed
hard
> drives.
>
> Under Memory & Registry, select all options.
> Click the "Advanced" button.
> Under "Log-file detail", select all options.
> Click the "Tweaks" button.
>
> Under "Scanning Engine", select the following:
> "Include additional Ad-aware settings in logfile" and
> "Unload recognized processes during scanning."
> Under "Cleaning Engine", select the following:
> "Let Windows remove files in use after reboot."
> Click on 'Proceed' to save these Preferences.
> Please make sure that you activate IN-DEPTH scanning before you proceed.
>
> After the above post a fresh log ...
> --
>
> Disclaimer: Renaming the "Windows" key modified some security settings.
>
> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
>
> Right-click the "Windows" key, select: Permissions
>
> [Example]
> Before renaming the "Windows" key:
>
> "Path"
> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
> "Read":
> *"Administrators
> *Power Users
> *Users"
> "Write"
> *"Administrators"
>
> --
> [Example]
>
> After Renaming the key:
>
> "Path"
> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
> "Read":
> ***"Everyone"***
> "Write"
> *"Administrators
> --
>
> You need to check that and if 'Everyone' was added (as seen above)
> You need to reset your original settings as follows:
> Note: do this after removing the infection.
>
> Right-click "Windows", select: Permissions
> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
>
> Click Advanced [button]
> If the "inherit permissions" box is checked = Uncheck it.
> Then select "COPY" on the prompt.
>
> Select "Everyone Group" (if listed) and remove. (only the group)
> You can individually view/edit each group settings.
> Be sure "Administrators" and "System" have full control on all.
> Note: Creator owner full control on Sub keys only.
> "Power users" and "users" = "read control".
> </paste>
> --
> HTH - Please Reply to This Thread
>
> ~Robear Dyer (PA Bear)
> MS MVP-Windows (IE/OE), AH-VSOP
>
> AumHa Forums
> http://forum.aumha.org
>
> What You Should Know About Spyware
> http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
>
> --------------------------------------------------------------------------
--------
> "Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
> news:uupv08QPEHA.1048@tk2msftngp13.phx.gbl...
> > I'm experiencing problems with IE 6 under windows 98. the startup page
> > keeps
> > resetting to about:blank which shows a search page with a bunch of
> > categories. i used CWShredder 1.57.0 with up to date patterns to clean
up
> > CWS and it said it got rid of the searchx strain. however, the problem
> > didn't go away. i tried running CWShredder again and again it reported
> > searchx to be present and that it cleaned it up. any idea how to
acutally
> > get rid of it? thanks for any help,
> >
> > gary
> >
> > --
> > Gary Roach
> > ADB Services
> >
> >
>
>



Re: CWS searchx strain won't go away by Bill

Bill
Tue May 18 19:14:50 CDT 2004

Hmm - ought to be easier in 98.

Do any of the methods of spotting the "culpret".dll file make any sense to
you?

It should still show as in use during a defrag or other operation on Win98.

What I read Mike Burgess' as saying is that the .DLL file is randomly named,
making it hard to spot.

HijackThis, and a post to a spyware forum, maybe with about:blank in the
subject header ought to get you some good attention, I'd think.

Have you run both Ad-aware--current version and definitions, and CWShredder
(1.57??) in Safe mode?



"Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
news:etyoBDTPEHA.3476@tk2msftngp13.phx.gbl...
> Bill,
>
> I saw that post but i think that's for XP. I'm running 98. when i tried
> "find-all.bat" i got a bunch of errors and the output.txt file didn't list
> any infection. i know that i've got CWS-searchx because CWShredder keeps
> reporting it.
>
> "Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
> news:%23g5FQnSPEHA.2704@TK2MSFTNGP10.phx.gbl...
>> I'm going to post two messages here, both from a thread in this same
> group,
>> and not very far away in time.
>>
>> The second is from PABear - giving Mike Burgess' (old) recipe for removal
> of
>> about:blank.
>>
>> However, read Mike Burgess' current advice first:
>> --------------------------------------------------------------------------
> --------------
>> PA Bear,
>> FYI: the (CWS) infection for "About:Blank" seems to have morphed.
>>
>> About the only method that seems to work now is to discover the culprit
>> dll, then install the "Recovery Console", boot to that, then
>> "attrib -r -h -s"
>> the culprit dll. Then "del <filename>.dll", then clean up the Registry
> with
>> CWShredder and Ad-Aware ... = PITA!
>>
>> In some cases you can discover the culprit by running Defrag, there will
>> be a (culprit dll) filename noted in the log.
>> ____________________________________________________________
>> Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
>> Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS
>> file
>> http://www.mvps.org/winhelp2002/hosts.htm [updated 05-15-04]
>> Please post replies to this Newsgroup, email address is invalid
>> --
>> --------------------------------------------------------------------------
> -------------------------
>>
>> PA Bear writes:
>>
>> [Posted numerous times in this newsgroup: http://snipurl.com/6hka]
>>
>> Here is MVP Mike Burgess' fix for CWS.Searchx (a CWS.Aboutblank variant):
>>
>> <paste>
>> Ok, here goes ... this is my "How To:" (Hint: print out the below)
>>
>> [Tools and files needed]
>>
>> Download: "RepairAppInit.reg" (XP\2K only!)
>> http://www.mvps.org/winhelp2002/RepairAppInit.reg
>> Do not do anything with this file yet, it will be needed later.
>>
>> Download: CWShredder
>> http://www.spywareinfo.com/~merijn/files/hijackthis.zip
>> Unzip, but do not run it yet, it will be needed later.
>>
>> Download: Ad-Aware
>> http://www.lavasoft.de/software/adaware/
>> Install, but do not run it yet, it will be needed later.
>>
>> Download: Find-All.zip
>> http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
>> Unzip, but do not run it yet, it will be needed later.
>>
>> Download: WINFILE.zip
>> http://www10.brinkster.com/expl0iter/freeatlast/WINFILE.zip
>> Unzip, but do not run it yet, it will be needed later.
>>
>> Download: Registrar Lite [freeware]
>> http://www.resplendence.com/download
>> Install, but do not run it yet, it will be needed later.
>>
>> [Step1]
>>
>> Double-click the included "Find-All.bat" file from Find-All.zip.
>> Generates: "output.txt"
>> Note: if infected you will see:
>>
>> Locked file(s) found...
>> C:\WINDOWS\System32\<filename> +++ File read error
>> Where "<filename>" is the hidden invisable installer.
>> Note: "+++ File read error" is not an error, this just identifies the
>> culprit.
>>
>> [Step2]
>>
>> Run "Registrar Lite" and navigate to:
>> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
>> Double click on "AppInit_DLLs" entry (right pane)
>> The size will likely be something other than "1" (if infected)
>> IMPORTANT: Make a note of the filename and location (folder)
>>
>> [Step3]
>>
>> Rename the highlighted "Windows" key (left pane)
>> To rename: Right-click and select: Rename
>> (type) NoWindows
>>
>>
>> Double-click "AppInit_DLLs" again (right pane)
>> Clear (delete) the "Value" containing the .dll and click Ok.
>>
>>
>> IMPORTANT: Rename the "NoWindows" key (left pane)
>> To rename: Right-click and select: Rename
>> (type) "Windows" (no quotes) and close RegLite.
>>
>> [Step 4]
>>
>> Using Windows Explorer go to your root drive: (typically) "C:\"
>> Click File (up top) select: New > Folder
>> (type) "Junk" (no quotes)
>>
>> Open Winfile
>>
>> Navigate to System32 folder.
>> Click File (up top) select: Move
>>
>> Copy and paste this into the 'From' box:
> C:\WINDOWS\System32\<filename>.dll
>> Copy and paste this into the 'To' box: C:\Junk\<filename>.dll
>>
>> Note: where "<filename>" = culprit dll from "output.txt"
>>
>> Click OK. Close Winfile
>> Open Windows Explorer and check in C:\Junk for the "<filename>.dll" file.
>>
>> At this point see if you can rename the "<filename>.dll"
>> Do this several time, changing the name and extension each time.
>> Then see if you can "Move" to "A:\" (floppy)
>>
>> [Step 5]
>>
>> Locate: "RepairAppInit.reg" right-click and select: Merge
>> Ok the prompt
>>
>> [Step 6]
>>
>> Open Regedit (Start | Run (type) "regedit" (no quotes)
>> Use the Search function for the <filename>.dll
>> Click: Edit (up top) select: Find
>> (type) <filename>.dll, click: Find Next
>>
>> Note: where "<filename>" = culprit dll from "output.txt"
>>
>> Remove all instances found.Press "F3" to continue searching
>> until you see the "Completed" message.
>>
>> Next repeat the above steps, subsitute the "secondary dll"
>> From: "text/html" as seen in the "output.txt"
>>
>>
>> [Step 7]
>>
>> Run CWShredder and reboot.
>>
>> [Step 8]
>> Run Ad-Aware
>>
>> Reconfigure Ad-Aware for Full Scan:
>> Please update the reference file following the instructions here:
>> http://www.lavahelp.com/howto/updref/index.html
>>
>> Launch the program, and click on the Gear at the top of the start screen.
>>
>> Click the "Scanning" button.
>> Under Drives & Folders, select "Scan within Archives".
>> Click "Click here to select Drives + folders" and select your installed
> hard
>> drives.
>>
>> Under Memory & Registry, select all options.
>> Click the "Advanced" button.
>> Under "Log-file detail", select all options.
>> Click the "Tweaks" button.
>>
>> Under "Scanning Engine", select the following:
>> "Include additional Ad-aware settings in logfile" and
>> "Unload recognized processes during scanning."
>> Under "Cleaning Engine", select the following:
>> "Let Windows remove files in use after reboot."
>> Click on 'Proceed' to save these Preferences.
>> Please make sure that you activate IN-DEPTH scanning before you proceed.
>>
>> After the above post a fresh log ...
>> --
>>
>> Disclaimer: Renaming the "Windows" key modified some security settings.
>>
>> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
>>
>> Right-click the "Windows" key, select: Permissions
>>
>> [Example]
>> Before renaming the "Windows" key:
>>
>> "Path"
>> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
>> "Read":
>> *"Administrators
>> *Power Users
>> *Users"
>> "Write"
>> *"Administrators"
>>
>> --
>> [Example]
>>
>> After Renaming the key:
>>
>> "Path"
>> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
>> "Read":
>> ***"Everyone"***
>> "Write"
>> *"Administrators
>> --
>>
>> You need to check that and if 'Everyone' was added (as seen above)
>> You need to reset your original settings as follows:
>> Note: do this after removing the infection.
>>
>> Right-click "Windows", select: Permissions
>> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
>>
>> Click Advanced [button]
>> If the "inherit permissions" box is checked = Uncheck it.
>> Then select "COPY" on the prompt.
>>
>> Select "Everyone Group" (if listed) and remove. (only the group)
>> You can individually view/edit each group settings.
>> Be sure "Administrators" and "System" have full control on all.
>> Note: Creator owner full control on Sub keys only.
>> "Power users" and "users" = "read control".
>> </paste>
>> --
>> HTH - Please Reply to This Thread
>>
>> ~Robear Dyer (PA Bear)
>> MS MVP-Windows (IE/OE), AH-VSOP
>>
>> AumHa Forums
>> http://forum.aumha.org
>>
>> What You Should Know About Spyware
>> http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
>>
>> --------------------------------------------------------------------------
> --------
>> "Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
>> news:uupv08QPEHA.1048@tk2msftngp13.phx.gbl...
>> > I'm experiencing problems with IE 6 under windows 98. the startup page
>> > keeps
>> > resetting to about:blank which shows a search page with a bunch of
>> > categories. i used CWShredder 1.57.0 with up to date patterns to clean
> up
>> > CWS and it said it got rid of the searchx strain. however, the problem
>> > didn't go away. i tried running CWShredder again and again it reported
>> > searchx to be present and that it cleaned it up. any idea how to
> acutally
>> > get rid of it? thanks for any help,
>> >
>> > gary
>> >
>> > --
>> > Gary Roach
>> > ADB Services
>> >
>> >
>>
>>
>
>



CWS searchx strain won't go away by rsteel

rsteel
Wed May 19 04:06:48 CDT 2004

Hi, I had the same problem & picked up the following from
another forum which solves the problem.
I copy & pasted it.

If you are not overly confident to do this, get someone
who knows their way around the PC to do it for you. It
should only btake a few minutes.

Good luck, this trojan is a pain in the butt!!

==========================================================

This helped me remove searchx (coolwebsearch variant)
One way to notice that you have searchx or perhaps
another coolwebsearch variant is to download hijackthis
and see if homeoldsp=about.blank is present.

Follow these directions to remove searchx:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Windows\AppInit_DLLs

You have to remove this key. The value of this key may
look blank for you, but it is not. They hide the value so
you can't see it. This registry key tells Windows to load
the trojan DLL every time ANY application is run giving
it complete control to do whatever it wants. So you need
to remove it so that the trojan DLL cannot load and keep
re-infecting your pc.

The way to remove the registry key is not obvious. If you
just delete it from regedit, since the trojan DLL is
loaded, it will re-add it right back. (Try it. Delete the
AppInit_DLLs registry key and hit F5. Notice that it's
added right back by the trojan). So what you have to do
is the following which worked for me.

1. Rename the HLM\Software\Microsoft\Windows
NT\CurrentVersion\Windows folder to Windows2.
2. Now delete the AppInit_DLLs key under the Windows2
folder.
3. Hit F5 and notice that AppInit_DLLs doesn't come back.
4. Rename the Windows2 folder back to Windows.

Now that AppInit_DLLs is gone, run the latest Adaware 6
to remove the trojan for good. Reboot your machine. Check
the registry and make sure AppInit_DLLs is still gone.
Your computer should be free of this for good now.

>-----Original Message-----
>I'm experiencing problems with IE 6 under windows 98.
the startup page keeps
>resetting to about:blank which shows a search page with
a bunch of
>categories. i used CWShredder 1.57.0 with up to date
patterns to clean up
>CWS and it said it got rid of the searchx strain.
however, the problem
>didn't go away. i tried running CWShredder again and
again it reported
>searchx to be present and that it cleaned it up. any
idea how to acutally
>get rid of it? thanks for any help,
>
>>.
>

Re: CWS searchx strain won't go away by Gary

Gary
Wed May 19 06:47:26 CDT 2004

I'm doing this for somebody whose computer i don't have access to. i'm
forwarding suggestions to him. should i suggest the defrag method? i've told
him to try cwshredder in safe mode but haven't heard back from him. if he
uses the defrag method, would he do it in safe mode? what inidcation would
he get to indicate that the "culprit" file was in use? you mention other
methods but the only one i know is from the post that says to use
find-all.bat. thanks for the help,

gary

"Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
news:uXpGPZTPEHA.1160@TK2MSFTNGP09.phx.gbl...
> Hmm - ought to be easier in 98.
>
> Do any of the methods of spotting the "culpret".dll file make any sense to
> you?
>
> It should still show as in use during a defrag or other operation on
Win98.
>
> What I read Mike Burgess' as saying is that the .DLL file is randomly
named,
> making it hard to spot.
>
> HijackThis, and a post to a spyware forum, maybe with about:blank in the
> subject header ought to get you some good attention, I'd think.
>
> Have you run both Ad-aware--current version and definitions, and
CWShredder
> (1.57??) in Safe mode?
>
>
>
> "Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
> news:etyoBDTPEHA.3476@tk2msftngp13.phx.gbl...
> > Bill,
> >
> > I saw that post but i think that's for XP. I'm running 98. when i tried
> > "find-all.bat" i got a bunch of errors and the output.txt file didn't
list
> > any infection. i know that i've got CWS-searchx because CWShredder keeps
> > reporting it.
> >
> > "Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
> > news:%23g5FQnSPEHA.2704@TK2MSFTNGP10.phx.gbl...
> >> I'm going to post two messages here, both from a thread in this same
> > group,
> >> and not very far away in time.
> >>
> >> The second is from PABear - giving Mike Burgess' (old) recipe for
removal
> > of
> >> about:blank.
> >>
> >> However, read Mike Burgess' current advice first:
>
>> -------------------------------------------------------------------------
-
> > --------------
> >> PA Bear,
> >> FYI: the (CWS) infection for "About:Blank" seems to have morphed.
> >>
> >> About the only method that seems to work now is to discover the culprit
> >> dll, then install the "Recovery Console", boot to that, then
> >> "attrib -r -h -s"
> >> the culprit dll. Then "del <filename>.dll", then clean up the Registry
> > with
> >> CWShredder and Ad-Aware ... = PITA!
> >>
> >> In some cases you can discover the culprit by running Defrag, there
will
> >> be a (culprit dll) filename noted in the log.
> >> ____________________________________________________________
> >> Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
> >> Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS
> >> file
> >> http://www.mvps.org/winhelp2002/hosts.htm [updated 05-15-04]
> >> Please post replies to this Newsgroup, email address is invalid
> >> --
>
>> -------------------------------------------------------------------------
-
> > -------------------------
> >>
> >> PA Bear writes:
> >>
> >> [Posted numerous times in this newsgroup: http://snipurl.com/6hka]
> >>
> >> Here is MVP Mike Burgess' fix for CWS.Searchx (a CWS.Aboutblank
variant):
> >>
> >> <paste>
> >> Ok, here goes ... this is my "How To:" (Hint: print out the below)
> >>
> >> [Tools and files needed]
> >>
> >> Download: "RepairAppInit.reg" (XP\2K only!)
> >> http://www.mvps.org/winhelp2002/RepairAppInit.reg
> >> Do not do anything with this file yet, it will be needed later.
> >>
> >> Download: CWShredder
> >> http://www.spywareinfo.com/~merijn/files/hijackthis.zip
> >> Unzip, but do not run it yet, it will be needed later.
> >>
> >> Download: Ad-Aware
> >> http://www.lavasoft.de/software/adaware/
> >> Install, but do not run it yet, it will be needed later.
> >>
> >> Download: Find-All.zip
> >> http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
> >> Unzip, but do not run it yet, it will be needed later.
> >>
> >> Download: WINFILE.zip
> >> http://www10.brinkster.com/expl0iter/freeatlast/WINFILE.zip
> >> Unzip, but do not run it yet, it will be needed later.
> >>
> >> Download: Registrar Lite [freeware]
> >> http://www.resplendence.com/download
> >> Install, but do not run it yet, it will be needed later.
> >>
> >> [Step1]
> >>
> >> Double-click the included "Find-All.bat" file from Find-All.zip.
> >> Generates: "output.txt"
> >> Note: if infected you will see:
> >>
> >> Locked file(s) found...
> >> C:\WINDOWS\System32\<filename> +++ File read error
> >> Where "<filename>" is the hidden invisable installer.
> >> Note: "+++ File read error" is not an error, this just identifies the
> >> culprit.
> >>
> >> [Step2]
> >>
> >> Run "Registrar Lite" and navigate to:
> >> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows]
> >> Double click on "AppInit_DLLs" entry (right pane)
> >> The size will likely be something other than "1" (if infected)
> >> IMPORTANT: Make a note of the filename and location (folder)
> >>
> >> [Step3]
> >>
> >> Rename the highlighted "Windows" key (left pane)
> >> To rename: Right-click and select: Rename
> >> (type) NoWindows
> >>
> >>
> >> Double-click "AppInit_DLLs" again (right pane)
> >> Clear (delete) the "Value" containing the .dll and click Ok.
> >>
> >>
> >> IMPORTANT: Rename the "NoWindows" key (left pane)
> >> To rename: Right-click and select: Rename
> >> (type) "Windows" (no quotes) and close RegLite.
> >>
> >> [Step 4]
> >>
> >> Using Windows Explorer go to your root drive: (typically) "C:\"
> >> Click File (up top) select: New > Folder
> >> (type) "Junk" (no quotes)
> >>
> >> Open Winfile
> >>
> >> Navigate to System32 folder.
> >> Click File (up top) select: Move
> >>
> >> Copy and paste this into the 'From' box:
> > C:\WINDOWS\System32\<filename>.dll
> >> Copy and paste this into the 'To' box: C:\Junk\<filename>.dll
> >>
> >> Note: where "<filename>" = culprit dll from "output.txt"
> >>
> >> Click OK. Close Winfile
> >> Open Windows Explorer and check in C:\Junk for the "<filename>.dll"
file.
> >>
> >> At this point see if you can rename the "<filename>.dll"
> >> Do this several time, changing the name and extension each time.
> >> Then see if you can "Move" to "A:\" (floppy)
> >>
> >> [Step 5]
> >>
> >> Locate: "RepairAppInit.reg" right-click and select: Merge
> >> Ok the prompt
> >>
> >> [Step 6]
> >>
> >> Open Regedit (Start | Run (type) "regedit" (no quotes)
> >> Use the Search function for the <filename>.dll
> >> Click: Edit (up top) select: Find
> >> (type) <filename>.dll, click: Find Next
> >>
> >> Note: where "<filename>" = culprit dll from "output.txt"
> >>
> >> Remove all instances found.Press "F3" to continue searching
> >> until you see the "Completed" message.
> >>
> >> Next repeat the above steps, subsitute the "secondary dll"
> >> From: "text/html" as seen in the "output.txt"
> >>
> >>
> >> [Step 7]
> >>
> >> Run CWShredder and reboot.
> >>
> >> [Step 8]
> >> Run Ad-Aware
> >>
> >> Reconfigure Ad-Aware for Full Scan:
> >> Please update the reference file following the instructions here:
> >> http://www.lavahelp.com/howto/updref/index.html
> >>
> >> Launch the program, and click on the Gear at the top of the start
screen.
> >>
> >> Click the "Scanning" button.
> >> Under Drives & Folders, select "Scan within Archives".
> >> Click "Click here to select Drives + folders" and select your installed
> > hard
> >> drives.
> >>
> >> Under Memory & Registry, select all options.
> >> Click the "Advanced" button.
> >> Under "Log-file detail", select all options.
> >> Click the "Tweaks" button.
> >>
> >> Under "Scanning Engine", select the following:
> >> "Include additional Ad-aware settings in logfile" and
> >> "Unload recognized processes during scanning."
> >> Under "Cleaning Engine", select the following:
> >> "Let Windows remove files in use after reboot."
> >> Click on 'Proceed' to save these Preferences.
> >> Please make sure that you activate IN-DEPTH scanning before you
proceed.
> >>
> >> After the above post a fresh log ...
> >> --
> >>
> >> Disclaimer: Renaming the "Windows" key modified some security settings.
> >>
> >> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows]
> >>
> >> Right-click the "Windows" key, select: Permissions
> >>
> >> [Example]
> >> Before renaming the "Windows" key:
> >>
> >> "Path"
> >> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows"
> >> "Read":
> >> *"Administrators
> >> *Power Users
> >> *Users"
> >> "Write"
> >> *"Administrators"
> >>
> >> --
> >> [Example]
> >>
> >> After Renaming the key:
> >>
> >> "Path"
> >> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows"
> >> "Read":
> >> ***"Everyone"***
> >> "Write"
> >> *"Administrators
> >> --
> >>
> >> You need to check that and if 'Everyone' was added (as seen above)
> >> You need to reset your original settings as follows:
> >> Note: do this after removing the infection.
> >>
> >> Right-click "Windows", select: Permissions
> >> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows]
> >>
> >> Click Advanced [button]
> >> If the "inherit permissions" box is checked = Uncheck it.
> >> Then select "COPY" on the prompt.
> >>
> >> Select "Everyone Group" (if listed) and remove. (only the group)
> >> You can individually view/edit each group settings.
> >> Be sure "Administrators" and "System" have full control on all.
> >> Note: Creator owner full control on Sub keys only.
> >> "Power users" and "users" = "read control".
> >> </paste>
> >> --
> >> HTH - Please Reply to This Thread
> >>
> >> ~Robear Dyer (PA Bear)
> >> MS MVP-Windows (IE/OE), AH-VSOP
> >>
> >> AumHa Forums
> >> http://forum.aumha.org
> >>
> >> What You Should Know About Spyware
> >> http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
> >>
>
>> -------------------------------------------------------------------------
-
> > --------
> >> "Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
> >> news:uupv08QPEHA.1048@tk2msftngp13.phx.gbl...
> >> > I'm experiencing problems with IE 6 under windows 98. the startup
page
> >> > keeps
> >> > resetting to about:blank which shows a search page with a bunch of
> >> > categories. i used CWShredder 1.57.0 with up to date patterns to
clean
> > up
> >> > CWS and it said it got rid of the searchx strain. however, the
problem
> >> > didn't go away. i tried running CWShredder again and again it
reported
> >> > searchx to be present and that it cleaned it up. any idea how to
> > acutally
> >> > get rid of it? thanks for any help,
> >> >
> >> > gary
> >> >
> >> > --
> >> > Gary Roach
> >> > ADB Services
> >> >
> >> >
> >>
> >>
> >
> >
>
>



Re: CWS searchx strain won't go away by Bill

Bill
Wed May 19 10:05:04 CDT 2004

Thanks very much, rsteel--this does sound promising!

"rsteel@hotmail.com" <anonymous@discussions.microsoft.com> wrote in message
news:f16b01c43d80$9db74b40$a001280a@phx.gbl...
> Hi, I had the same problem & picked up the following from
> another forum which solves the problem.
> I copy & pasted it.
>
> If you are not overly confident to do this, get someone
> who knows their way around the PC to do it for you. It
> should only btake a few minutes.
>
> Good luck, this trojan is a pain in the butt!!
>
> ==========================================================
>
> This helped me remove searchx (coolwebsearch variant)
> One way to notice that you have searchx or perhaps
> another coolwebsearch variant is to download hijackthis
> and see if homeoldsp=about.blank is present.
>
> Follow these directions to remove searchx:
>
> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
> NT\CurrentVersion\Windows\AppInit_DLLs
>
> You have to remove this key. The value of this key may
> look blank for you, but it is not. They hide the value so
> you can't see it. This registry key tells Windows to load
> the trojan DLL every time ANY application is run giving
> it complete control to do whatever it wants. So you need
> to remove it so that the trojan DLL cannot load and keep
> re-infecting your pc.
>
> The way to remove the registry key is not obvious. If you
> just delete it from regedit, since the trojan DLL is
> loaded, it will re-add it right back. (Try it. Delete the
> AppInit_DLLs registry key and hit F5. Notice that it's
> added right back by the trojan). So what you have to do
> is the following which worked for me.
>
> 1. Rename the HLM\Software\Microsoft\Windows
> NT\CurrentVersion\Windows folder to Windows2.
> 2. Now delete the AppInit_DLLs key under the Windows2
> folder.
> 3. Hit F5 and notice that AppInit_DLLs doesn't come back.
> 4. Rename the Windows2 folder back to Windows.
>
> Now that AppInit_DLLs is gone, run the latest Adaware 6
> to remove the trojan for good. Reboot your machine. Check
> the registry and make sure AppInit_DLLs is still gone.
> Your computer should be free of this for good now.
>
>>-----Original Message-----
>>I'm experiencing problems with IE 6 under windows 98.
> the startup page keeps
>>resetting to about:blank which shows a search page with
> a bunch of
>>categories. i used CWShredder 1.57.0 with up to date
> patterns to clean up
>>CWS and it said it got rid of the searchx strain.
> however, the problem
>>didn't go away. i tried running CWShredder again and
> again it reported
>>searchx to be present and that it cleaned it up. any
> idea how to acutally
>>get rid of it? thanks for any help,
>>
>>>.
>>



Re: CWS searchx strain won't go away by Bill

Bill
Wed May 19 10:06:10 CDT 2004

I don't know what to look for in the defrag approach--I'd just suggest
running it and letting you know what happens.

Take a look at the message from rsteel posted to the thread--it looks
promising.

"Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
news:uGZZPcZPEHA.620@TK2MSFTNGP10.phx.gbl...
> I'm doing this for somebody whose computer i don't have access to. i'm
> forwarding suggestions to him. should i suggest the defrag method? i've
> told
> him to try cwshredder in safe mode but haven't heard back from him. if he
> uses the defrag method, would he do it in safe mode? what inidcation would
> he get to indicate that the "culprit" file was in use? you mention other
> methods but the only one i know is from the post that says to use
> find-all.bat. thanks for the help,
>
> gary
>
> "Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
> news:uXpGPZTPEHA.1160@TK2MSFTNGP09.phx.gbl...
>> Hmm - ought to be easier in 98.
>>
>> Do any of the methods of spotting the "culpret".dll file make any sense
>> to
>> you?
>>
>> It should still show as in use during a defrag or other operation on
> Win98.
>>
>> What I read Mike Burgess' as saying is that the .DLL file is randomly
> named,
>> making it hard to spot.
>>
>> HijackThis, and a post to a spyware forum, maybe with about:blank in the
>> subject header ought to get you some good attention, I'd think.
>>
>> Have you run both Ad-aware--current version and definitions, and
> CWShredder
>> (1.57??) in Safe mode?
>>
>>
>>
>> "Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
>> news:etyoBDTPEHA.3476@tk2msftngp13.phx.gbl...
>> > Bill,
>> >
>> > I saw that post but i think that's for XP. I'm running 98. when i tried
>> > "find-all.bat" i got a bunch of errors and the output.txt file didn't
> list
>> > any infection. i know that i've got CWS-searchx because CWShredder
>> > keeps
>> > reporting it.
>> >
>> > "Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
>> > news:%23g5FQnSPEHA.2704@TK2MSFTNGP10.phx.gbl...
>> >> I'm going to post two messages here, both from a thread in this same
>> > group,
>> >> and not very far away in time.
>> >>
>> >> The second is from PABear - giving Mike Burgess' (old) recipe for
> removal
>> > of
>> >> about:blank.
>> >>
>> >> However, read Mike Burgess' current advice first:
>>
>>> -------------------------------------------------------------------------
> -
>> > --------------
>> >> PA Bear,
>> >> FYI: the (CWS) infection for "About:Blank" seems to have morphed.
>> >>
>> >> About the only method that seems to work now is to discover the
>> >> culprit
>> >> dll, then install the "Recovery Console", boot to that, then
>> >> "attrib -r -h -s"
>> >> the culprit dll. Then "del <filename>.dll", then clean up the Registry
>> > with
>> >> CWShredder and Ad-Aware ... = PITA!
>> >>
>> >> In some cases you can discover the culprit by running Defrag, there
> will
>> >> be a (culprit dll) filename noted in the log.
>> >> ____________________________________________________________
>> >> Mike Burgess [MVP Windows Shell\User]
>> >> http://www.mvps.org/winhelp2002/
>> >> Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS
>> >> file
>> >> http://www.mvps.org/winhelp2002/hosts.htm [updated 05-15-04]
>> >> Please post replies to this Newsgroup, email address is invalid
>> >> --
>>
>>> -------------------------------------------------------------------------
> -
>> > -------------------------
>> >>
>> >> PA Bear writes:
>> >>
>> >> [Posted numerous times in this newsgroup: http://snipurl.com/6hka]
>> >>
>> >> Here is MVP Mike Burgess' fix for CWS.Searchx (a CWS.Aboutblank
> variant):
>> >>
>> >> <paste>
>> >> Ok, here goes ... this is my "How To:" (Hint: print out the below)
>> >>
>> >> [Tools and files needed]
>> >>
>> >> Download: "RepairAppInit.reg" (XP\2K only!)
>> >> http://www.mvps.org/winhelp2002/RepairAppInit.reg
>> >> Do not do anything with this file yet, it will be needed later.
>> >>
>> >> Download: CWShredder
>> >> http://www.spywareinfo.com/~merijn/files/hijackthis.zip
>> >> Unzip, but do not run it yet, it will be needed later.
>> >>
>> >> Download: Ad-Aware
>> >> http://www.lavasoft.de/software/adaware/
>> >> Install, but do not run it yet, it will be needed later.
>> >>
>> >> Download: Find-All.zip
>> >> http://www10.brinkster.com/expl0iter/freeatlast/pvtool.htm
>> >> Unzip, but do not run it yet, it will be needed later.
>> >>
>> >> Download: WINFILE.zip
>> >> http://www10.brinkster.com/expl0iter/freeatlast/WINFILE.zip
>> >> Unzip, but do not run it yet, it will be needed later.
>> >>
>> >> Download: Registrar Lite [freeware]
>> >> http://www.resplendence.com/download
>> >> Install, but do not run it yet, it will be needed later.
>> >>
>> >> [Step1]
>> >>
>> >> Double-click the included "Find-All.bat" file from Find-All.zip.
>> >> Generates: "output.txt"
>> >> Note: if infected you will see:
>> >>
>> >> Locked file(s) found...
>> >> C:\WINDOWS\System32\<filename> +++ File read error
>> >> Where "<filename>" is the hidden invisable installer.
>> >> Note: "+++ File read error" is not an error, this just identifies the
>> >> culprit.
>> >>
>> >> [Step2]
>> >>
>> >> Run "Registrar Lite" and navigate to:
>> >> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\Windows]
>> >> Double click on "AppInit_DLLs" entry (right pane)
>> >> The size will likely be something other than "1" (if infected)
>> >> IMPORTANT: Make a note of the filename and location (folder)
>> >>
>> >> [Step3]
>> >>
>> >> Rename the highlighted "Windows" key (left pane)
>> >> To rename: Right-click and select: Rename
>> >> (type) NoWindows
>> >>
>> >>
>> >> Double-click "AppInit_DLLs" again (right pane)
>> >> Clear (delete) the "Value" containing the .dll and click Ok.
>> >>
>> >>
>> >> IMPORTANT: Rename the "NoWindows" key (left pane)
>> >> To rename: Right-click and select: Rename
>> >> (type) "Windows" (no quotes) and close RegLite.
>> >>
>> >> [Step 4]
>> >>
>> >> Using Windows Explorer go to your root drive: (typically) "C:\"
>> >> Click File (up top) select: New > Folder
>> >> (type) "Junk" (no quotes)
>> >>
>> >> Open Winfile
>> >>
>> >> Navigate to System32 folder.
>> >> Click File (up top) select: Move
>> >>
>> >> Copy and paste this into the 'From' box:
>> > C:\WINDOWS\System32\<filename>.dll
>> >> Copy and paste this into the 'To' box: C:\Junk\<filename>.dll
>> >>
>> >> Note: where "<filename>" = culprit dll from "output.txt"
>> >>
>> >> Click OK. Close Winfile
>> >> Open Windows Explorer and check in C:\Junk for the "<filename>.dll"
> file.
>> >>
>> >> At this point see if you can rename the "<filename>.dll"
>> >> Do this several time, changing the name and extension each time.
>> >> Then see if you can "Move" to "A:\" (floppy)
>> >>
>> >> [Step 5]
>> >>
>> >> Locate: "RepairAppInit.reg" right-click and select: Merge
>> >> Ok the prompt
>> >>
>> >> [Step 6]
>> >>
>> >> Open Regedit (Start | Run (type) "regedit" (no quotes)
>> >> Use the Search function for the <filename>.dll
>> >> Click: Edit (up top) select: Find
>> >> (type) <filename>.dll, click: Find Next
>> >>
>> >> Note: where "<filename>" = culprit dll from "output.txt"
>> >>
>> >> Remove all instances found.Press "F3" to continue searching
>> >> until you see the "Completed" message.
>> >>
>> >> Next repeat the above steps, subsitute the "secondary dll"
>> >> From: "text/html" as seen in the "output.txt"
>> >>
>> >>
>> >> [Step 7]
>> >>
>> >> Run CWShredder and reboot.
>> >>
>> >> [Step 8]
>> >> Run Ad-Aware
>> >>
>> >> Reconfigure Ad-Aware for Full Scan:
>> >> Please update the reference file following the instructions here:
>> >> http://www.lavahelp.com/howto/updref/index.html
>> >>
>> >> Launch the program, and click on the Gear at the top of the start
> screen.
>> >>
>> >> Click the "Scanning" button.
>> >> Under Drives & Folders, select "Scan within Archives".
>> >> Click "Click here to select Drives + folders" and select your
>> >> installed
>> > hard
>> >> drives.
>> >>
>> >> Under Memory & Registry, select all options.
>> >> Click the "Advanced" button.
>> >> Under "Log-file detail", select all options.
>> >> Click the "Tweaks" button.
>> >>
>> >> Under "Scanning Engine", select the following:
>> >> "Include additional Ad-aware settings in logfile" and
>> >> "Unload recognized processes during scanning."
>> >> Under "Cleaning Engine", select the following:
>> >> "Let Windows remove files in use after reboot."
>> >> Click on 'Proceed' to save these Preferences.
>> >> Please make sure that you activate IN-DEPTH scanning before you
> proceed.
>> >>
>> >> After the above post a fresh log ...
>> >> --
>> >>
>> >> Disclaimer: Renaming the "Windows" key modified some security
>> >> settings.
>> >>
>> >> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\Windows]
>> >>
>> >> Right-click the "Windows" key, select: Permissions
>> >>
>> >> [Example]
>> >> Before renaming the "Windows" key:
>> >>
>> >> "Path"
>> >> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\Windows"
>> >> "Read":
>> >> *"Administrators
>> >> *Power Users
>> >> *Users"
>> >> "Write"
>> >> *"Administrators"
>> >>
>> >> --
>> >> [Example]
>> >>
>> >> After Renaming the key:
>> >>
>> >> "Path"
>> >> "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\Windows"
>> >> "Read":
>> >> ***"Everyone"***
>> >> "Write"
>> >> *"Administrators
>> >> --
>> >>
>> >> You need to check that and if 'Everyone' was added (as seen above)
>> >> You need to reset your original settings as follows:
>> >> Note: do this after removing the infection.
>> >>
>> >> Right-click "Windows", select: Permissions
>> >> [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
> NT\CurrentVersion\Windows]
>> >>
>> >> Click Advanced [button]
>> >> If the "inherit permissions" box is checked = Uncheck it.
>> >> Then select "COPY" on the prompt.
>> >>
>> >> Select "Everyone Group" (if listed) and remove. (only the group)
>> >> You can individually view/edit each group settings.
>> >> Be sure "Administrators" and "System" have full control on all.
>> >> Note: Creator owner full control on Sub keys only.
>> >> "Power users" and "users" = "read control".
>> >> </paste>
>> >> --
>> >> HTH - Please Reply to This Thread
>> >>
>> >> ~Robear Dyer (PA Bear)
>> >> MS MVP-Windows (IE/OE), AH-VSOP
>> >>
>> >> AumHa Forums
>> >> http://forum.aumha.org
>> >>
>> >> What You Should Know About Spyware
>> >> http://www.microsoft.com/mscorp/twc/privacy/spyware.mspx
>> >>
>>
>>> -------------------------------------------------------------------------
> -
>> > --------
>> >> "Gary Roach" <jgroach@NOSPAMcogeco.ca> wrote in message
>> >> news:uupv08QPEHA.1048@tk2msftngp13.phx.gbl...
>> >> > I'm experiencing problems with IE 6 under windows 98. the startup
> page
>> >> > keeps
>> >> > resetting to about:blank which shows a search page with a bunch of
>> >> > categories. i used CWShredder 1.57.0 with up to date patterns to
> clean
>> > up
>> >> > CWS and it said it got rid of the searchx strain. however, the
> problem
>> >> > didn't go away. i tried running CWShredder again and again it
> reported
>> >> > searchx to be present and that it cleaned it up. any idea how to
>> > acutally
>> >> > get rid of it? thanks for any help,
>> >> >
>> >> > gary
>> >> >
>> >> > --
>> >> > Gary Roach
>> >> > ADB Services
>> >> >
>> >> >
>> >>
>> >>
>> >
>> >
>>
>>
>
>



Re: CWS searchx strain won't go away by FakeMailThatWorks

FakeMailThatWorks
Wed May 19 11:00:38 CDT 2004


"Gary Roach" <jgroach@NOSPAMcogeco.ca> schreef in bericht
news:uupv08QPEHA.1048@tk2msftngp13.phx.gbl...
> I'm experiencing problems with IE 6 under windows 98. the startup page
keeps
> resetting to about:blank which shows a search page with a bunch of
> categories. i used CWShredder 1.57.0 with up to date patterns to clean up
> CWS and it said it got rid of the searchx strain. however, the problem
> didn't go away. i tried running CWShredder again and again it reported
> searchx to be present and that it cleaned it up. any idea how to acutally
> get rid of it? thanks for any help,

To comfort you Merijn Bellekom is the CWS programmer.
http://www.spywareinfo.com/~merijn/cwschronicles.html#searchx



Re: CWS searchx strain won't go away by FakeMailThatWorks

FakeMailThatWorks
Wed May 19 11:05:13 CDT 2004


"FakeMailThatWorks" <ftw@chello.nl> schreef in bericht
news:%232$4ppbPEHA.3748@TK2MSFTNGP09.phx.gbl...

SNIP

>
> To comfort you Merijn Bellekom is the CWS programmer.
> http://www.spywareinfo.com/~merijn/cwschronicles.html#searchx

Read CWS shredder programmer :-) Sorry.



Re: CWS searchx strain won't go away by Gary

Gary
Wed May 19 13:04:53 CDT 2004

Thanks for the info - i'm using 98 and i've searched the registry for
appinit_dlls but found nothing. bill suggests trying cwshredder in safe mode
which i failed to do while i had the computer myself. i've suggested to the
owner of the machine that he try that. i'll see how it goes.

"rsteel@hotmail.com" <anonymous@discussions.microsoft.com> wrote in message
news:f16b01c43d80$9db74b40$a001280a@phx.gbl...
> Hi, I had the same problem & picked up the following from
> another forum which solves the problem.
> I copy & pasted it.
>
> If you are not overly confident to do this, get someone
> who knows their way around the PC to do it for you. It
> should only btake a few minutes.
>
> Good luck, this trojan is a pain in the butt!!
>
> ==========================================================
>
> This helped me remove searchx (coolwebsearch variant)
> One way to notice that you have searchx or perhaps
> another coolwebsearch variant is to download hijackthis
> and see if homeoldsp=about.blank is present.
>
> Follow these directions to remove searchx:
>
> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
> NT\CurrentVersion\Windows\AppInit_DLLs
>
> You have to remove this key. The value of this key may
> look blank for you, but it is not. They hide the value so
> you can't see it. This registry key tells Windows to load
> the trojan DLL every time ANY application is run giving
> it complete control to do whatever it wants. So you need
> to remove it so that the trojan DLL cannot load and keep
> re-infecting your pc.
>
> The way to remove the registry key is not obvious. If you
> just delete it from regedit, since the trojan DLL is
> loaded, it will re-add it right back. (Try it. Delete the
> AppInit_DLLs registry key and hit F5. Notice that it's
> added right back by the trojan). So what you have to do
> is the following which worked for me.
>
> 1. Rename the HLM\Software\Microsoft\Windows
> NT\CurrentVersion\Windows folder to Windows2.
> 2. Now delete the AppInit_DLLs key under the Windows2
> folder.
> 3. Hit F5 and notice that AppInit_DLLs doesn't come back.
> 4. Rename the Windows2 folder back to Windows.
>
> Now that AppInit_DLLs is gone, run the latest Adaware 6
> to remove the trojan for good. Reboot your machine. Check
> the registry and make sure AppInit_DLLs is still gone.
> Your computer should be free of this for good now.
>
> >-----Original Message-----
> >I'm experiencing problems with IE 6 under windows 98.
> the startup page keeps
> >resetting to about:blank which shows a search page with
> a bunch of
> >categories. i used CWShredder 1.57.0 with up to date
> patterns to clean up
> >CWS and it said it got rid of the searchx strain.
> however, the problem
> >didn't go away. i tried running CWShredder again and
> again it reported
> >searchx to be present and that it cleaned it up. any
> idea how to acutally
> >get rid of it? thanks for any help,
> >
> >>.
> >



Re: CWS searchx strain won't go away by Bill

Bill
Wed May 19 14:45:20 CDT 2004

Thanks for the correction--that had me worried (about you!) for moment.

"FakeMailThatWorks" <ftw@chello.nl> wrote in message
news:%23PTBOsbPEHA.1048@tk2msftngp13.phx.gbl...
>
> "FakeMailThatWorks" <ftw@chello.nl> schreef in bericht
> news:%232$4ppbPEHA.3748@TK2MSFTNGP09.phx.gbl...
>
> SNIP
>
>>
>> To comfort you Merijn Bellekom is the CWS programmer.
>> http://www.spywareinfo.com/~merijn/cwschronicles.html#searchx
>
> Read CWS shredder programmer :-) Sorry.
>
>



Re: CWS searchx strain won't go away by cibbarelli

cibbarelli
Tue May 25 15:43:39 CDT 2004

HELP!! I have followed the instructions below and still can't shake
this thing. I'm wondering if I have a new strain/variant.

1. I do have the "homeoldsp=about.blank" present when I run HiJack
this. I keep electing to fix and it keeps coming back.

2. I found the "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows
NT\CurrentVersion\Windows\AppInit_DLLs" and deleted it. When I hit F5
it never came back but I still had the same problem (hijacked start
page instead of about:blank). So I did a search while in regedit and
found the AppInit_Dlls hidden elsewhere. This time I followed the
instructions on renaming the folder, deleting, changing the name back,
etc. I then ran AdAware 6, CWShredder, Spybot, and rebooted. My
about:blank start page is still some bastard Search Spyware but I
can't find AppInit_DLLs anywhere withi