Computing.Net > Forums > Windows 95/98 > Task Manager Help and CoolWebSearch

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Task Manager Help and CoolWebSearch

Reply to Message Icon

Name: Greg Pluta
Date: June 16, 2004 at 12:38:50 Pacific
OS: Windows 98
CPU/Ram: Intel pentium II Processo
Comment:

Hey i need help. Whenever i start my computer and open my task manager box, i have all these programs such as scanregw. I wanna make this programs stop appearing. And before i used to have CoolWebSearch. I used the merjiks hijack this and deleted it but whenever i use ad-aware and scan my computer, it says the program is still there. i need to kno how to delete it manually AND how to make the unknown programs stop appearing in my task manager window. Any help will be appreciated. Email me back or post a reply here.
Thanks




Sponsored Link
Ads by Google

Response Number 1
Name: jboy
Date: June 16, 2004 at 13:45:52 Pacific
Reply:

Go to Merijn's download page and get CoolWebShredder.

Scanregw is pretty essential to your computer's continued good health - you should leave it enabled.

It creates a backup of the registry and allows you to restore things when there are problems.


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 2
Name: mesich
Date: June 16, 2004 at 14:27:45 Pacific
Reply:

Hi Greg, jboy, hello everyone

I agree with jboy on running CWShredder.

ScanregW.exe should not be listed within the Task Manager. ScanregW.exe runs when starting Windows however, it should not be continually running in the background.

For example, if I set a batch file to run before Windows loads, the .bat file runs and closes out.

It is the same concept with scanregw.exe. The executable is launched and ran. Upon completion the program closes out and is no longer running as a "Task".

I speculate you have a Trojan or Virus that's identifing itself as scanregw.exe such as the one described in this link.

I suggest you run an On-Line Virus Scan.

Post back with the results of the On-Line Scan.

Best Regards,
Mesich


0

Response Number 3
Name: jboy
Date: June 16, 2004 at 15:32:50 Pacific
Reply:

Ah, excellent point Mesich (and my error).

I was confusing disabling the entry in msconfig with what Greg had actually posted - sure, there should be no such process running in the background.


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 4
Name: Greg Pluta
Date: June 16, 2004 at 15:37:59 Pacific
Reply:

When I tried running the On-Line Virus Scan, a message popped up saying "Your current security settings prohibit running ActiveX controls on this page. As a result,the page may not display correctly. I will soon try the CW Shredder thx. By the way, Scanregw is not the only programs that appear. In my next post i will post them. Thank You for the help so far.


0

Response Number 5
Name: Greg Pluta
Date: June 16, 2004 at 15:43:02 Pacific
Reply:

Ok I ran CwShredder. then i ran ad-aware and i dont have it on my system anymore! Thank you so much but i am still concerned about the unknown programs. After I get a reply for this post, I will reboot my computer and then post the names of the other programs. You guys have been a great help. Thanks


0

Related Posts

See More



Response Number 6
Name: mesich
Date: June 16, 2004 at 15:49:53 Pacific
Reply:

Hi jboy, hello everyone

jboy,

Thank you.

It is so easy to miss things as such especially when the author of a trojan or virus uses an "impersonated Windows file" to launch their garbage.

I certainly apprecitate you sharing your vast knowledge and time with myself, and everyone here.

Best Regards,
Mesich



0

Response Number 7
Name: Greg Pluta
Date: June 16, 2004 at 15:52:22 Pacific
Reply:

Ok i rebooted my sytem and immediately after my icons showed up i opned my task manager. Here are some of the programs I saw: Pcciomon, Rundll32, Qttask, Taskmon, and <unknown> . I also saw Scanregw but from wat u guys told me it doesnt matter. Can you guys play look into this and see if theres anything i can do to manually delete these viruses or give me a link to a place that deletes viruses, parasites, and trojans. Ok thanks. Any help will be appreciated.


0

Response Number 8
Name: jboy
Date: June 16, 2004 at 15:55:42 Pacific
Reply:

Aw, Mesich - likewise (and then some)


Yes, CoolWebSearch is one of the nastier ones - thankfully we have Merijn's Shredder. Sorry about my earlier bad advice - a virus scan is still indicated, although you'll need someone more conversant with IE to advise you on your security settings.

Scanregw does matter - as Mesich pointed out, it should execute and exit - yours may be an imposter.

Some various sites to check your running programs list:

TaskList

Sysinfo

Startup List


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 9
Name: mesich
Date: June 16, 2004 at 16:05:42 Pacific
Reply:

Hi Greg, jboy, hello everyone

I highly suggest getting the On-Line Virus Scan completed.

Try the following and then running the scan:

In Internet Explorer select Tools and Internet Options

Click on the Security tab

Select the globe icon named Internet Zone

Click on Custom Level

Scroll down to the ActiveX controls and plug-ins section

Under Download signed ActiveX contols select Prompt

Under Run ActiveX controls and plug-ins select Enable

Under Script ActiveX controls marked safe for scripting select Enable

Click OK

Click OK

Before performing the above and running the virus scan post back with a hijackthis log.
It will allow us to see the registry entries if they exist that are referenced in msconfig-startup.

You can get here.

Best Regards,
Mesich


0

Response Number 10
Name: jboy
Date: June 16, 2004 at 16:10:48 Pacific
Reply:

PCCIOMon.exe: Real-time background antivirus scanning task from the PC-cillin antivirus software

Qttask: System Tray access to Apple's "Quick Time" viewer from version 5 onwards

<unknown> seems suspicious(?)

Taskmon: Related to the W32.MyDoom virus. Located in "C:\Windows\System\" on Windows 95/98/Me

That one could be bad - if it's in c:\windows then it's a normal (although possibly unwanted) process.


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 11
Name: Greg Pluta
Date: June 16, 2004 at 16:19:06 Pacific
Reply:

This is what I got for hijackthis:

Logfile of HijackThis v1.97.7
Scan saved at 6:15:56 PM, on 6/16/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCPFW.exe
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\TMPROXY.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\WINDOWS\TASKMON.exe
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\D\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\SYSTEM\STOPZILLABHO.DLL
O2 - BHO: (no name) - {C6EA5A8D-8B01-4498-8B9A-B40AA281035F} - C:\PROGRAM FILES\RETSINA SOFTWARE\IEJET\POPKILLER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCCIOMON.exe] "C:\Program Files\Trend Micro\Internet Security\PCCIOMON.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PCCIOMON.exe] "C:\Program Files\Trend Micro\Internet Security\PCCIOMON.exe"
O4 - HKLM\..\RunServices: [PccPfw] C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
O4 - HKLM\..\RunServices: [tmproxy] C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.exe"
O9 - Extra button: IEJet (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/drakken/us/win/QuickTimeInstaller.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cab?
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37956.1962152778
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/01a533f7b49a70b4b816/netzip/RdxIE601.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potd_x.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 204.127.198.4,63.240.76.4



0

Response Number 12
Name: jboy
Date: June 16, 2004 at 16:27:55 Pacific
Reply:

Mesich can best advise - although I believe any references to sp.html are suspect.


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 13
Name: Greg Pluta
Date: June 16, 2004 at 16:35:21 Pacific
Reply:

Ok heres a log on wat ive solved so far. I got rid of CWS. I found out that all i have to do is wait a couple of seconds when i reboot and then when i check my tasks, none of the ones i wrote before appear, which is good. I just want to know from mesich wat i have to delete from my hijack this log. Rite now im gonna go try to do that On-Line Virus Scanner thing.
Thanks guys for all your help both of you have been very helpful so far.


0

Response Number 14
Name: mesich
Date: June 16, 2004 at 16:36:59 Pacific
Reply:

Hi Greg, jboy, hello everyone

As usual jboy is on top of it. :-)
The sp.html files are bad.

Don't do anything with them yet as I would like a copy of it. :-)

Email it to me using the address after clicking on my name. I had a copy of it before but didn't save it after a format.

After emailing me the file try what I said in response #9 and running the on-line scan.

I'll look over your log while you are running the scan and between all of us we'll get the issue
resolve. :-)

Best Regards,
Mesich



0

Response Number 15
Name: Greg Pluta
Date: June 16, 2004 at 16:38:17 Pacific
Reply:

Ok we still have a problem. Mesich: when you told me to do all that security stuff, watever you told me to do was already like that in the settings. But i still get that message whenever I want to take the Scan. What should i do know. Also on some other pages ive been to i get the same message.
Try and help please.
Thanks.


0

Response Number 16
Name: mesich
Date: June 16, 2004 at 16:54:38 Pacific
Reply:

Hi Greg, jboy, hello everyone

Let's not worry about the ActiveX for the moment and concentrate on getting rid of the items listed within your log file.
I am going over it right now.

Meantime, can you send me a copy of the sp.html file?


Best Regards,
Mesich


0

Response Number 17
Name: mesich
Date: June 16, 2004 at 17:10:07 Pacific
Reply:

Hi Greg, jboy, hello everyone

Remove the following items using hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html

Restart the computer and go to C:\Windows\Temp, and delete all of the files from that folder.

Going to sit down for some dinner and will check back in just a bit.

Best Regards,
Mesich


0

Response Number 18
Name: Greg Pluta
Date: June 16, 2004 at 17:47:17 Pacific
Reply:

I went to C:\Windows\Temp and deleted every file except for Cookies, History, and Temporary Internet Files. it did not let me delete a file called MiniBugInstaller. Please let me know if i need the files Cookies, History, and Temporary Internet Files. Im not sure if i need them but they kinda sound important.


0

Response Number 19
Name: Greg Pluta
Date: June 16, 2004 at 17:48:28 Pacific
Reply:

By the way where can i find the sp.html file??


0

Response Number 20
Name: jboy
Date: June 16, 2004 at 17:59:52 Pacific
Reply:

If it exists, it would be in C:\WINDOWS\TEMP (as indicated by the HJT! log) although it sounds like you may have already deleted it (recycle bin?)

If you checked the appropriate boxes when you ran HiJackThis! and chose 'fix selected' then references to the offending file would have been removed from your registry as well.

Minibuginstaller would seem to have to do with your 'weatherbug' installation - although I'm unsure why it would remain in the temp directory. Generally files are 'undeletable' if they are in use by Windows - which can usually be gotten around by deleting while in Safe Mode (or DOS)

Cookies, while not strictly necessary can be helpful in storing your preferences and logins for various websites (like this one) but also can be used for tracking purposes. I wouldn't worry overly much - run Ad-aware to rid yourself of the less desirable ones.

We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 21
Name: DAVEINCAPS
Date: June 16, 2004 at 18:20:08 Pacific
Reply:

That sp.html hijacker may be getting more common. This thread from a few days ago concerned it also:

http://computing.net/windows95/wwwboard/forum/159270.html


0

Response Number 22
Name: jboy
Date: June 16, 2004 at 18:30:47 Pacific
Reply:

Yes, I thought I'd only recently read about this one, that must've been it - although anything launching from the temp directory has to be viewed with a certain suspicion.


0

Response Number 23
Name: Greg Pluta
Date: June 16, 2004 at 18:53:38 Pacific
Reply:

I need a question answered should I delete sp.html or not?


0

Response Number 24
Name: jboy
Date: June 16, 2004 at 18:56:56 Pacific
Reply:

Email it to Mesich first, for his 'bug collection'


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 25
Name: Greg Pluta
Date: June 16, 2004 at 19:03:58 Pacific
Reply:

Yes, but exactly how do I do that.


0

Response Number 26
Name: jboy
Date: June 16, 2004 at 19:07:22 Pacific
Reply:

Click on his name to get the address, and email as an attachment?


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 27
Name: Greg Pluta
Date: June 16, 2004 at 19:16:05 Pacific
Reply:

Ok i sent it to mesich. Im waiting for his reply.


0

Response Number 28
Name: jboy
Date: June 16, 2004 at 19:21:38 Pacific
Reply:

Good stuff - I'm sure he'll appreciate it.


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 29
Name: mesich
Date: June 16, 2004 at 19:31:49 Pacific
Reply:

Hi Greg, jboy, DAVEINCAPS, hello everyone

Greg,

I got your email however there was no file attatched.

Here is the entire content of your email:

C:\WINDOWS\TEMP\sp.html

Type this in as a website link. Im lookind forward to your help.

Thanks

Unfortunately there was not a link provided.

I have to get up very early in the morning so don't worry about sending the file. I'll see if I can't hunt it up on one of the backup CD I created or from some backup email when it was sent from someone else.

Remove the files as suggested by jboy and you should be good to go. Nothing else in the hijackthis log that is of concern.


Best Regards,
Mesich


0

Response Number 30
Name: Greg Pluta
Date: June 16, 2004 at 19:47:48 Pacific
Reply:

OK so jboy, what files did u tell me to delete again. My head is all mixed up.


0

Response Number 31
Name: Greg Pluta
Date: June 16, 2004 at 19:51:23 Pacific
Reply:

Thanks everybody for all yer help. jboy and mesich, you guys were really helpful. I would be no where without you guys. Just one last question. I still need help fixing my ActionX problem. So mesich, when u have the time, can u help me fix that problem? Thanks again everyone.


0

Response Number 32
Name: jboy
Date: June 16, 2004 at 20:08:46 Pacific
Reply:

Glad we could be of assistance.

Your ActiveX Control settings aren't necessarily a problem, they just prevent you from accessing certain online services such as that AV site. You'll likely get it sorted eventually, meanwhile, keep your PC-Cillin up to date to guard against virus, and look into Ad-aware and Spybot S&D for other threats.


We have nothing against ideas. We're against people spreading them. - General Augusto Pinochet of Chile


0

Response Number 33
Name: DAVEINCAPS
Date: June 16, 2004 at 20:21:08 Pacific
Reply:

From the IE toolbar go to TOOLS--INTERNET OPTIONS--SECURITY. If you lower the security level you shouldn't get that message.

After the virus scan it would be a good idea to raise the level again to what it was before the scan.


0

Response Number 34
Name: Greg Pluta
Date: June 16, 2004 at 20:26:08 Pacific
Reply:

Doesnt work when i change the level to low, I press OK. Then when i checked the level again it was back as medium.


0

Response Number 35
Name: DAVEINCAPS
Date: June 16, 2004 at 20:26:37 Pacific
Reply:

Sorry Mesich, I see you covered that in #9 above. One of these days I'll actually start reading the posts instead of relying on my vast psychic abilities.


0

Response Number 36
Name: DAVEINCAPS
Date: June 16, 2004 at 20:30:55 Pacific
Reply:

On mine, I lowered to to LOW and hit apply and OK and it held that setting.

You may need to check the custom levels as Mesich mentions in #9.


0

Response Number 37
Name: Greg Pluta
Date: June 16, 2004 at 21:48:14 Pacific
Reply:

Sorry i misunderstood. I got it now. But even on low the scan still does not work. Thank you for you help DAVEINCAPS.


0

Response Number 38
Name: DAVEINCAPS
Date: June 16, 2004 at 22:02:39 Pacific
Reply:

I thought that would have done it. Maybe you need to open a new IE window or even reboot after making the change.


0

Response Number 39
Name: Greg Pluta
Date: June 16, 2004 at 22:23:18 Pacific
Reply:

I misunderstood before. thank you very much. But the scan still does not work but thats ok becuz i think im all good. Thanks again. And Mesich and jboy, I am forever in your debt. If i need more help I will post back here knowing that I will find great infromation.


0

Response Number 40
Name: Greg Pluta
Date: June 17, 2004 at 08:31:13 Pacific
Reply:

Ok i rebooted my system and went on the internet and guess what? CWS was back. I ran CWShredder and got rid of it. Now i wanna know how to keep it from getting back on my system. I know it gives me two links but i need instruction on wat to do.
Thanks.


0

Response Number 41
Name: Greg Pluta
Date: June 17, 2004 at 08:44:39 Pacific
Reply:

I have yet another problem. My security settings are all screwed up. Can someone plz post what each level is supposed to be.


0

Sponsored Link
Ads by Google
Reply to Message Icon

BellSouth IE virtual CD



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Task Manager Help and CoolWebSearch

Wacky Task Manager! www.computing.net/answers/windows-95/wacky-task-manager/133574.html

something wierd in my task manager www.computing.net/answers/windows-95/something-wierd-in-my-task-manager/160229.html

multiple iexplore in task manager www.computing.net/answers/windows-95/multiple-iexplore-in-task-manager/164261.html