Computing.Net > Forums > Security and Virus > Removal of unwanted program

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Removal of unwanted program

Reply to Message Icon

Name: louis hill
Date: May 12, 2009 at 11:40:44 Pacific
OS: Windows XP
CPU/Ram: 264
Product: Dell / Inspirion 600m
Subcategory: Viruses
Comment:

How do I get rid of HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeCtfmon.exe?
"CoolWebSearch Ctfmon32 parasite variant"

I located this with a Hijackthis scan.Thank you very much.

Curious George



Sponsored Link
Ads by Google

Response Number 1
Name: mavis007
Date: May 12, 2009 at 15:28:11 Pacific
Reply:

...Variant 10: CWS.Ctfmon32

Approx date first sighted: September 22, 2003
Symptoms: Start page and Search pages changed to www.slawsearch.com, 'Customize Search Assistant' closing after opening it, hijack coming back after a reboot.
Cleverness: 3/10
Manual removal difficulty: Involves some Registry editing
This variant surfaced after a quiet time. CWShredder could fix it, but it would return after rebooting the computer. Apart from the new filename 'CTFMON32.EXE' (note that 'CTFMON.EXE' is the real Windows system file) it worked pretty much the same way as CWS.Bootconf: the file loads at startup, resetting homepages and search pages, and then closes. Deleting the file and changing everything back to normal fixes it

Grrrr
"...pentathol makes you sing like a canary"
... got brain freeze


0
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Removal of unwanted program

removal of yod.htm www.computing.net/answers/security/removal-of-yodhtm/19611.html

Any body heard of a program called www.computing.net/answers/security/any-body-heard-of-a-program-called-/6854.html

manual removal of troj_imiserv.c www.computing.net/answers/security/manual-removal-of-trojimiservc/13794.html