Home > Hjt Log > HJT Log - Trying To Get Rid Of CWS.Feads

HJT Log - Trying To Get Rid Of CWS.Feads

thanks for you help on this..it's greatly appreciated. Please post one here in your thread.Thank you for your patience. Run a search of all files with the same size as the wmpscfgs.exe file.

vivien classicsoftware05-16-2008, 12:30 AMIf the performance is where you want it, let me know and we can go from there. C:\WINDOWS\WMSysPrx.prx:hdftjRemoved Stream! C:\WINDOWS\tiscali04.ico:njjnwRemoved Stream! CWS/FAKESCAN691.

the task scheduler thing eluded me and im glad i came here :) Second of all the trojan didnt originate with the wmpscfgs.exe file, i think mine originated from a file I can not access regedit and I have gone through 6 different steps I found on the net. My computer feels like it's dying. If you don't have HijackThis, you can download it here: http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html Thank you for posting this fix, and thanks to Kan for providing it.

Any help would be greatly appreciated.Thanks, Logfile of HijackThis v1.99.0Scan saved at 6:00:04 PM, on 3/12/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\MSN Then click the Show report button and copy and paste what's present under results in your next reply. I asked for help and I used my communication skills and the data I had on had as best I could. Thanks for the advice and info.

help please!! please help !!!!!!!!!!!!!!! C:\WINDOWS\iebr.exe:khzgaRemoved Stream! C:\WINDOWS\mfccm.exe:rrxcvRemoved Stream!

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Norton AntiVirus even when i browser around, close ie and reopen, my home page is still valid. I went to the folder of each of the items on both these lists (most of them are the same items). - In the folders where these exe files are, the here be me log files.Logfile of HijackThis v1.99.1Scan saved at 23:02:59, on 12/08/2006Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exeC:\Program Files\ewido anti-spyware 4.0\guard.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\sstray.exeC:\Program Files\Java\jre1.5.0_03\bin\jusched.exeC:\Program Files\CyberLink\PowerDVD\PDVDServ.exeC:\WINDOWS\System32\RUNDLL32.EXEC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program

Some Adware may hijack the ads of other companies, replacing them with its own.Use Add/Remove program applet to remove. CWSEXCEL726. You are all awesome! oh, i-feel-a-song-comin-on!!

Good job with that Zerospyware scam. PC not running up to speed Diff computer HJT log file... It is these tasks that run the "wmpscfgs.exe" program. 3/ Run Regedit and search for all occurrences of ".delme" and delete any keys with this string 4/ Run a disk search i even rebooted, opened ie and it's still the valid home page.

Nov 13, 2005 #3 swker98 TechSpot Paladin Posts: 1,077 hmm your post sounds like a scam, if your computer isnt runnibg slow then i wouldnt worry about it, some comapnys use CWSCONTROL725. Then i deleted all the scheduled tasks related to the virus.

Windows has detected Spyware infection Oct 27, 2008 "Your computer is infected!

looks like it's not really fixed tho' because my homepage in ie6 gets changed to about:blank (then Spybot finds coolwwwsearch again). help please! "HiJackThis" Log Help-CWS.Feads spyware HijackThis Log for VroomSearch problem W32.SILLYP2p problems crashing big time but not in safe mode my hijack log. When I knocked some of it out through the other OS, it disabled my every last option to put my system back to the way it was before. I especially like the buzztail and his philosophy for handling viruses and other baddies.

If you try to allow one, UAC will be disabled. i've tried the above mentioned method, but i'm still gettin the same msg…. :-( Please help….. What can i do to save my clients computer? thank you, thank you!