Computing.Net > Forums > Security and Virus > Strange CWShredder Occurance

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Strange CWShredder Occurance

Reply to Message Icon

Name: dw226
Date: January 21, 2004 at 22:57:40 Pacific
OS: XP Home
CPU/Ram: 1.8 Celeron/512MB
Comment:

Ok, I accidently click on an old version of CWShredder that I forgot to delete and when it starts, I get a message saying I have a variant of the Smartsearch CWS, I believe it was. Anyway, it said to counteract it, it would start with a random string and was not corrupted.

Well, I then notice it is the out of date version so I close it out, scan with the new one, and not a single thing is found. Any clue what's up with that?



Sponsored Link
Ads by Google

Response Number 1
Name: Ray Peate
Date: January 21, 2004 at 23:00:39 Pacific
Reply:

Yes - I got that, too!! However, my message appeared when I updated to the latest version but was exactly the same as yours - and so was the result when I ran a "Fix". Interesting to see what responses we get!!


0

Response Number 2
Name: blender
Date: January 21, 2004 at 23:24:54 Pacific
Reply:

Interesting...What version was the old one you used?
I just tried running the newest one (1.46.0.2)...no infection...closed, rebooted for the fun of it, ran an older version I had..version 1.36.0.1...said it restored 1 IE registry value...didn't specify what. After another reboot..ran another "fix" run with the new one and nothing found.
I didn't get the same message tho...quite different.


0

Response Number 3
Name: dw226
Date: January 21, 2004 at 23:38:41 Pacific
Reply:

Hi blender, I wish I could remember the number, but it was the one just prior to the newest version. I've never actually had this happen before as I usually delete the old version right away. Maybe it has done that for some time.

Very strange and, in a sense, a little worrying. I imagine it is just a program glitch.


0

Response Number 4
Name: dw226
Date: January 21, 2004 at 23:40:11 Pacific
Reply:

By the way, do either of you use Sygate? I read Imp's post about it being updated, but I'm being told I have the latest version when I check.


0

Response Number 5
Name: elric
Date: January 21, 2004 at 23:46:55 Pacific
Reply:

G'day,

That happened to me too- with the latest version (1.46.1).
It ran with that scrambled header and the warning, but didn't seem to erase anything.
I was concerned too, so maybe someone can shed some light on this (perhaps when it runs for the first, it needs to assume that the virus is there..?)
I think I'll run it again and see what happens.
regards,
Elric


0

Related Posts

See More



Response Number 6
Name: dw226
Date: January 21, 2004 at 23:59:01 Pacific
Reply:

Well now, is it doing that to you guys when you accidently click on an older version as I did, or is this happening with the newest version by itself? If it is the newest version doing this alone, then something is up with CWShredder.

But if you did the same thing I did, then it may not be of any importance. Though it doesn't seem like it should do this even in my case. In fact, I have ran older versions of the software before without getting the update, and it has never happened.


0

Response Number 7
Name: dw226
Date: January 22, 2004 at 00:01:31 Pacific
Reply:

I should mention that, at least in my case, deleting the old version and running the new did not produce this message again.


0

Response Number 8
Name: Ray Peate
Date: January 22, 2004 at 00:59:36 Pacific
Reply:

My message appeared at the point at which I moved from an "Old" version into the updated one. It's happened twice in succession - but no infection found when running "Fix". And no repeat in subsequent running of the program: interesting to see what happens when it is updated again!


0

Response Number 9
Name: Ray Peate
Date: January 22, 2004 at 01:01:27 Pacific
Reply:

ps: No, I don't run Sygate: I use Kerio.


0

Response Number 10
Name: blender
Date: January 22, 2004 at 02:20:08 Pacific
Reply:

I use Zone alarm pro
No I didn't accidently run the old cwshredder I had to look for an old copy I had on floppy...any time I update I just overwrite the current version. I had no errors when I did that. I have had no errors in the past either. (on my system or anyone elses I run it on)
Did you guys check again for update to cwshredder?...it is now at 1.46.02....both updates were quick in succession....
What I found weird was running the new version found nothing....running the older version found 1 reg value "fixed".... running the new version again finds nothing.
I doubt it is anything to worry about...mabye just remove any copies of CWShredder you have and download a fresh one. Mabye it got corrupted if a big pile of people were downloading the file at the same time.



0

Response Number 11
Name: elric
Date: January 22, 2004 at 03:20:47 Pacific
Reply:

G'day,

I ran version 1.46.1 again and it didn't find anything and the header was the normal CWShredder ...etc. So I then ran the only previous version I could find - 1.44.2- and it didn't find anything and the header was normal. I ran 1.46.1 again and nothing had changed. I then downloaded ver 1.46.2 and it did exactly what 1.46.1 did on its first run (the random header and the warning about coolwebsearch)and didn't seem to clean anything from my machine (unless the initial warning was implying that it would remove it) and then reverted back to normal when running it a second time.
I've just thought of an idea: I will remove the latest version using cyberscrub and then re-download it; if the coolwebsearch virus was removed by running it just now, it should come up with the normal header and not the encrypted one. I'll let you know how I get on.
regards,
Elric


0

Response Number 12
Name: elric
Date: January 22, 2004 at 03:45:32 Pacific
Reply:

G'day,

Just tried that; completely wiped v1.46.2 with cyberscrub and then updated my v1.44.2 with the latest (v1.46.2), ran it and voila!
No warning, no encrypted header (as I would expect)and no virus found.
This must mean that the CoolWebSearch virus go back into my machine between updates (1.44.2-1.46.1-1.46.2). So, if I'm right, we must run CWShredder after EVERY net session.
Anyone know how to automate this ??
regards,
Elric


0

Response Number 13
Name: dw226
Date: January 22, 2004 at 11:26:51 Pacific
Reply:

I'm not sure if there is an auto function to run it on a schedule. I don't see any place within CWShredder that you can.


0

Response Number 14
Name: XpUser
Date: January 22, 2004 at 13:00:56 Pacific
Reply:

Elric and dw226,

Just a thought - what if you use XP native Scheduled Task in the System Tools to run CWShredder?


0

Response Number 15
Name: dw226
Date: January 22, 2004 at 14:46:46 Pacific
Reply:

Hmm, now there's an idea. But doesn't the program have to support an automated function such as an antivirus program has in order for it to do this?


0

Response Number 16
Name: XpUser
Date: January 22, 2004 at 16:19:56 Pacific
Reply:

dw226,

I can't say cuz I haven't yet used Scheduled tasks; however I think the link below will shed more lights on what ya can do with it

Running Programs on a Schedule Using Scheduled Tasks - http://delltech.150m.com/XP/running/7.htm

Let me know if this helps - if not I mite dig more deep in my brain :)

Regards


0

Response Number 17
Name: iceblue
Date: January 22, 2004 at 16:28:59 Pacific
Reply:

Merijin is lightning fast with updates; there can be a same day update. Sometimes you can download a new version and click Update only to find yet another.

A new version is available:
CWShredder 1.46.0003



0

Response Number 18
Name: Abnormal
Date: January 22, 2004 at 20:23:31 Pacific
Reply:

Sometimes I think the Man is playing
with coolwebsearh.
Hope it's confusing them also.

http://www.dslreports.com/forum/remark,9156752~mode=flat


0

Response Number 19
Name: blender
Date: January 22, 2004 at 20:27:59 Pacific
Reply:

Another new one...Thanks Ice!

Elric, dw226

With the need to update it almost daily...and the speed of scan/fix...is this just a challange to automate it? I run cwshredder almost every day...and it almost always finds 1 or 2 infected ie registry values....THERE WE GO!!! hahaha just got the same warning! right after update, unzipping to cwshredder folder, replacing the old, delete the zip, run cwshredder...no infection found...exit, rerun, no warning or random strings, no infection.

Speaking of updates...anyone who uses mcafee av...I do and have had I think at least 8 updates this week alone! (usually 1x/week) Haven't had time to read the new viruses database but must be a pile...


0

Sponsored Link
Ads by Google
Reply to Message Icon

Trojan.Download virus O1 Entry in HijackThis/Qu...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Strange CWShredder Occurance

Computer is actin strange lately www.computing.net/answers/security/computer-is-actin-strange-lately/13956.html

Question about CWShredder www.computing.net/answers/security/question-about-cwshredder-/9817.html

Popup Prompts to Download? www.computing.net/answers/security/popup-prompts-to-download/9379.html