Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi,
I always have a recurrence of CWS_NS3 on my pc. I ran HijackThis, Spybot, Ad-Aware, etc., but it always reappeared. The interesting thing is that it was always picked up by Spy Sweeper and not by the other spyware programs. After further research I finally tracked the reappearance of CWS_NS3 to qttask.exe. To test and verify that this was the culprit, I would run the Spy Sweeper program to get rid of any traces of CWS_NS3. After I did that I would run Spy Sweeper a second time to make certain that the traces were gone. After doing this I would double-click on qttask.exe and then run the Spy Sweeper program a third time. Sure enough each time I repeat those steps, CWS-NS3 reappears. Could someone explain this?
I realize that qttask.exe is a file that QuickTime utilizes. I am wondering if the Spy Sweeper program is giving me a false reading on qttask.exe. However, if this is not a false reading and this file is re-generating CWS_NS3 on my pc, what are the best steps to take to resolve this problem?
Thanks,
Lincoln.Lincoln Lee

Home Search Assistant / CWS_NS3 Removal Guide.
Read the related tutorials within the link too.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Whilst your here, you'd better run the very latest, hot off the press, CWShredder version 2.0.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Just back off that CWShredder™ 2.0 for the time being.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Carry on :)
CWShredder™ 2.0 is good.
http://forums.spywareinfo.com/index.php?showtopic=31685#
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Hi again,
Ran the updated version of CWShredder but it did not pick up anything even though I did run Spy Sweeper to confirm that the trace was there (No, I did not quarantine it).
How about that connection between CWS_NS3 and qttask.exe????
Thanks,
LincolnLincoln Lee

All well and good.
But did you read / follow / do / run, all the advice from the original link in response #1 ?
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Hi,
I did look at the suggested web page, but did not run the advice since the problem described on that web page did not match the problem that I have on my PC. The only similarity is the mention of CWS_NS3. Other than this, I do not have any of the other symptoms described on the page.
I have run HijackThis multiple times and have removed suspected processes. The log looks clean now. However, the CWS_NS3 problem returns only when qtttask.exe is executed. Having read the tutorial it appears that the spyware can attach itself to a file. So I am assuming thta it has somehow done so with qttask.exe. But the tutorial went on to state that this can be solved by using ADSSpy. However, what I read indicted that this was not for Windows ME.
Any other suggestions?
Thanks,
Lincoln.Lincoln Lee

Run HijackThis again and post the log here. I'll look at it. Make sure you have the latest HijackThis 1.98.2 and make sure it's unzipped to your program files.
Woe betide you, if I find things that match up in that original article though and find you haven't run AboutBuster etc. You'd better run for cover :)
Make sure ALL your spyware apps are up to date too.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Hi,
Below is the log (you've got me shaking in my booties!):
Logfile of HijackThis v1.98.2
Scan saved at 10:11:12 PM, on 10/20/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.exe
C:\WINDOWS\EXPLORER.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.exe
C:\WINDOWS\SYSTEM\MDM.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.exe
C:\PROGRAM FILES\HISTORYKILL\HISTKILL.exe
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\HIJACKTHIS\HIJACKTHIS.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.exe
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.exe" /0
O4 - HKCU\..\RunServices: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\RunServices: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.exe" /0
O4 - Startup: POWERR~1.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O15 - Trusted Zone: *.ameritrade.com
O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) - http://classlive.ecollege.com/~sdk/SDK/paste/lsiw9x.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {F8F88D0D-E455-11D6-B547-00400555C7FB} (DiskHealth2 Class) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_03) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CABAnd of course my thanks,
LincolnLincoln Lee

Okie DOK - Mr Lincoln Lee. Not a lot wrong with that at first glance.
Boot into safe mode and open HJT. Checkmark the following ...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - Startup: POWERR~1.exe
And unless you put that there in trusted zones, then get rid of it too ...O15 - Trusted Zone: *.ameritrade.com
and remove.
Try that first and report back.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Also after you've done that, download the VX2 Cleaner for Ad-Aware - install it and run it.
Lavasoft support forums -- Add Ons -- VX2 Cleaner
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

I have exactly the same problem on 2 machines. One with Xp and another with 98. Spysweeper detects CWS_NS3 and 174 traces on both computers. After rebooting they come back. I also cannot install Norton Firewall because of the bug.
I deleted the quicktime files and that made no difference. I've done pretty much everything I can think of. The folks at Webroot cannot offer any more help either.Has anyone figured this out yet?

Well as you can see, we will never know because, dips--- poster, never posted back.
But if you wanna put down a log file and see if there are any obvious similarities anywhere with the log above, then do so.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

I also have the same problem with CWS_NS3. I would appreciate if anyone can help me out. I use spysweeper to get rid of it only to see it come back. I can paste my log f anyone wants to look at it.

May as well have a look out of curiousity. Stick it down.
See the iDiOt walk
See the idiot TaLkWaLk IdIoT WaLk

Logfile of HijackThis v1.98.2
Scan saved at 11:46:43 PM, on 10/27/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.exe
E:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
E:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
E:\WINDOWS\System32\CTHELPER.exe
E:\WINDOWS\SOUNDMAN.exe
E:\Program Files\Yahoo!\browser\ybrwicon.exe
E:\Program Files\BroadJump\Client Foundation\CFD.exe
E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
E:\Program Files\Browser Mouse\mouse32a.exe
E:\Program Files\Messenger\msmsgs.exe
E:\WINDOWS\System32\RUNDLL32.exe
E:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
E:\Program Files\Creative\MediaSource\RemoteControl\RCMan.exe
E:\Program Files\Multimedia keyboard utility\1.3\KbdAp32A.exe
E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
E:\WINDOWS\System32\CTsvcCDA.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\MsPMSPSv.exe
E:\Program Files\Internet Explorer\IEXPLORE.exe
E:\Documents and Settings\AMD\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTSysVol] E:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] E:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [SBDrvDet] E:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [CTRegRun] E:\WINDOWS\CTRegRun.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [YBrowser] E:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [BJCFD] E:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] E:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMK08KB] E:\Program Files\Multimedia keyboard utility\1.3\MMKEYBD.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.exe E:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Creative MediaSource Go] E:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] E:\Program Files\Creative\MediaSource\RemoteControl\RCMan.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [SpySweeper] E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Global Startup: SBC Self Support Tool.lnk = E:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///E:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - E:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - E:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098929199248
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |