View Single Post
Old 07-09-2005, 06:04 PM   #2 (permalink)
MicroBell
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
I don't see any CWS hijacker files running in your log. The entrys that Ewido is finding are registry entrys and in a very odd location for a CWS hijack. CWS has never droped entrys in a Hardware location (that I know of). This location as to do with your bios and motherboard chipset features.


Please download CWShredder (link in my signature) and run the program. Select FIX and see it finds anything. Run another Ewido scan and see if it picks those entrys up again. If so....open regedit and export the following keys..save them as a txt file and post them here.

HKLM\HARDWARE\ACPI\FADT\

HKLM\HARDWARE\ACPI\RSDT\


Is this a Gateway PC? Are you using NetZero?

I also need the following logs...

Download Silent runners.Vbs http://www.silentrunners.org/
1. Make sure you have any script blocking software disabled
2. Run the program. It will take a few minutes to complete.
3. Once complete it will produce a log named “StartupPrograms” with Your user and date in the filename. Open that txt file and posts it contents in your next post.

Open hijackthis...click...config..misctools. Check the 2 box’s next to "Generate Startup List" and then click "Generate Startup List". Post that log in your next post.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder

Last edited by MicroBell; 07-09-2005 at 06:10 PM.
MicroBell is offline