CWS.LoadAdv.400

  • Thread starter Thread starter kwdiamond
  • Start date Start date
K

kwdiamond

This hijacker appears to elude the Anti Spyware Beta 1.
This is from another anti spyware (freedom) log which
detected it and removed it... later to reappear for some
reason.



CWS.LoadAdv.400 Application 9/13/2005 10:09:42 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:42 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:44 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:45 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:46 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:47 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:48 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:49 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:50 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:51 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:53 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:53 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:54 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:55 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:56 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:57 AM
CWS.LoadAdv.400 Application 9/13/2005 10:09:58 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:42 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:43 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:44 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:45 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:46 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:47 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:48 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:49 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:50 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:51 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:52 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:53 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:54 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:55 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:56 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:57 AM
CWS.LoadAdv.400 Application 9/15/2005 10:27:59 AM
 
This is Backdoor Haxdoor so it is nasty infection, Can
you tell me abit more about the antispy you said removed
this (Freedom) ?

Haxdoor opens a backdoor and can give access on the
infected pc to the attacker also it can act as a
keylogger, steal passwords and install rootkits that can
prevent it being stopped or deleted and can disable other
Security software (Antivirus, Firewall & Antispy)

Your best using AntiVius scanners for this and if the
problems continue then use we can use Hijack This and
other tools to clean up.

Run these scanners :

Trend Micro

http://housecall.antivirus.com/

Panda

http://www.pandasoftware.com/activescan/

----------------------------------------------------------

If the problem is still there use Hijack This and
Microworlds Escan and post the log's they produce either
on here or to my email and we can manually remove all the
junk.

Download Hijack This, Save it to desktop or C:drive,
Extract and run then choose "system scan and save
logfile" and post that back

http://www.spywareinfo.com/~merijn/files/hijackthis.zip



Also download Microworlds eScan

http://www.mwti.net/download/tools/mwav.exe


Save it to a folder.

Double click the Mwav.exe file.

Select all local drives, scan all files, and press SCAN.
When it is completed, anything found will be displayed in
the lower pane.

In the Virus Log Information Pane......
Left click and highlight all the information in the Lower
pane --- Use &CTRL C on your keyboard to copy everything
found in the lower pane and save it to a notepad file

*Note* If prompted that a virus was found and you need to
purchase the product to remove the malware, just close
out the prompt and let it continue scanning. We are not
going to use this to remove anything...but to Identify
the bad files.

Once you copy that to a Notepad file...highlight the text
and copy it here with a Hijack This log

Regards Andy
 
Back
Top