Computing.Net > Forums > Windows Me > CWS_NS3 and qttask.exe

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

CWS_NS3 and qttask.exe

Reply to Message Icon

Name: drlwlee
Date: October 18, 2004 at 22:13:56 Pacific
OS: Windows ME
CPU/Ram: PIII 933Mhz/512MB
Comment:

Hi,

I always have a recurrence of CWS_NS3 on my pc. I ran HijackThis, Spybot, Ad-Aware, etc., but it always reappeared. The interesting thing is that it was always picked up by Spy Sweeper and not by the other spyware programs. After further research I finally tracked the reappearance of CWS_NS3 to qttask.exe. To test and verify that this was the culprit, I would run the Spy Sweeper program to get rid of any traces of CWS_NS3. After I did that I would run Spy Sweeper a second time to make certain that the traces were gone. After doing this I would double-click on qttask.exe and then run the Spy Sweeper program a third time. Sure enough each time I repeat those steps, CWS-NS3 reappears. Could someone explain this?

I realize that qttask.exe is a file that QuickTime utilizes. I am wondering if the Spy Sweeper program is giving me a false reading on qttask.exe. However, if this is not a false reading and this file is re-generating CWS_NS3 on my pc, what are the best steps to take to resolve this problem?

Thanks,
Lincoln.

Lincoln Lee



Sponsored Link
Ads by Google

Response Number 1
Name: Viking
Date: October 19, 2004 at 01:39:44 Pacific
Reply:

Home Search Assistant / CWS_NS3 Removal Guide.

Read the related tutorials within the link too.


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 2
Name: Viking
Date: October 19, 2004 at 02:33:14 Pacific
Reply:

Whilst your here, you'd better run the very latest, hot off the press, CWShredder version 2.0.

CWShredder™ 2.0 @ Majorgeeks

CWShredder™ 2.0 @ Intermute


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 3
Name: Viking
Date: October 19, 2004 at 08:22:19 Pacific
Reply:

Just back off that CWShredder™ 2.0 for the time being.


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 4
Name: Viking
Date: October 19, 2004 at 10:13:51 Pacific
Reply:

Carry on :)

CWShredder™ 2.0 is good.

http://forums.spywareinfo.com/index.php?showtopic=31685#

See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 5
Name: drlwlee
Date: October 19, 2004 at 16:33:08 Pacific
Reply:

Hi again,

Ran the updated version of CWShredder but it did not pick up anything even though I did run Spy Sweeper to confirm that the trace was there (No, I did not quarantine it).

How about that connection between CWS_NS3 and qttask.exe????

Thanks,
Lincoln

Lincoln Lee


0

Related Posts

See More



Response Number 6
Name: Viking
Date: October 20, 2004 at 02:50:32 Pacific
Reply:

All well and good.

But did you read / follow / do / run, all the advice from the original link in response #1 ?


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 7
Name: drlwlee
Date: October 20, 2004 at 08:11:40 Pacific
Reply:

Hi,

I did look at the suggested web page, but did not run the advice since the problem described on that web page did not match the problem that I have on my PC. The only similarity is the mention of CWS_NS3. Other than this, I do not have any of the other symptoms described on the page.

I have run HijackThis multiple times and have removed suspected processes. The log looks clean now. However, the CWS_NS3 problem returns only when qtttask.exe is executed. Having read the tutorial it appears that the spyware can attach itself to a file. So I am assuming thta it has somehow done so with qttask.exe. But the tutorial went on to state that this can be solved by using ADSSpy. However, what I read indicted that this was not for Windows ME.

Any other suggestions?

Thanks,
Lincoln.

Lincoln Lee


0

Response Number 8
Name: Viking
Date: October 20, 2004 at 08:24:08 Pacific
Reply:

Run HijackThis again and post the log here. I'll look at it. Make sure you have the latest HijackThis 1.98.2 and make sure it's unzipped to your program files.

Woe betide you, if I find things that match up in that original article though and find you haven't run AboutBuster etc. You'd better run for cover :)

Make sure ALL your spyware apps are up to date too.


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 9
Name: drlwlee
Date: October 20, 2004 at 22:15:27 Pacific
Reply:

Hi,

Below is the log (you've got me shaking in my booties!):

Logfile of HijackThis v1.98.2
Scan saved at 10:11:12 PM, on 10/20/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.exe
C:\WINDOWS\EXPLORER.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.exe
C:\WINDOWS\SYSTEM\MDM.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\WINDOWS\SYSTEM\RPCSS.exe
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.exe
C:\PROGRAM FILES\HISTORYKILL\HISTKILL.exe
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.exe
C:\HIJACKTHIS\HIJACKTHIS.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.exe
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.exe" /0
O4 - HKCU\..\RunServices: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\RunServices: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.exe" /0
O4 - Startup: POWERR~1.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O15 - Trusted Zone: *.ameritrade.com
O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) - http://classlive.ecollege.com/~sdk/SDK/paste/lsiw9x.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {F8F88D0D-E455-11D6-B547-00400555C7FB} (DiskHealth2 Class) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_03) -
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

And of course my thanks,
Lincoln

Lincoln Lee


0

Response Number 10
Name: Viking
Date: October 21, 2004 at 05:37:52 Pacific
Reply:

Okie DOK - Mr Lincoln Lee. Not a lot wrong with that at first glance.

Boot into safe mode and open HJT. Checkmark the following ...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =


O4 - Startup: POWERR~1.exe


And unless you put that there in trusted zones, then get rid of it too ...

O15 - Trusted Zone: *.ameritrade.com

and remove.


Try that first and report back.


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 11
Name: Viking
Date: October 21, 2004 at 08:06:47 Pacific
Reply:

Also after you've done that, download the VX2 Cleaner for Ad-Aware - install it and run it.

Lavasoft support forums -- Add Ons -- VX2 Cleaner


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 12
Name: vader69
Date: October 26, 2004 at 07:31:35 Pacific
Reply:

I have exactly the same problem on 2 machines. One with Xp and another with 98. Spysweeper detects CWS_NS3 and 174 traces on both computers. After rebooting they come back. I also cannot install Norton Firewall because of the bug.
I deleted the quicktime files and that made no difference. I've done pretty much everything I can think of. The folks at Webroot cannot offer any more help either.

Has anyone figured this out yet?



0

Response Number 13
Name: Viking
Date: October 26, 2004 at 16:21:14 Pacific
Reply:

Well as you can see, we will never know because, dips--- poster, never posted back.

But if you wanna put down a log file and see if there are any obvious similarities anywhere with the log above, then do so.


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 14
Name: Arek
Date: October 28, 2004 at 00:01:28 Pacific
Reply:

I also have the same problem with CWS_NS3. I would appreciate if anyone can help me out. I use spysweeper to get rid of it only to see it come back. I can paste my log f anyone wants to look at it.


0

Response Number 15
Name: Viking
Date: October 28, 2004 at 09:41:40 Pacific
Reply:

May as well have a look out of curiousity. Stick it down.


See the iDiOt walk
See the idiot TaLk

WaLk IdIoT WaLk


0

Response Number 16
Name: Arek
Date: October 28, 2004 at 17:57:38 Pacific
Reply:

Logfile of HijackThis v1.98.2
Scan saved at 11:46:43 PM, on 10/27/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.exe
E:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
E:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
E:\WINDOWS\System32\CTHELPER.exe
E:\WINDOWS\SOUNDMAN.exe
E:\Program Files\Yahoo!\browser\ybrwicon.exe
E:\Program Files\BroadJump\Client Foundation\CFD.exe
E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
E:\Program Files\Browser Mouse\mouse32a.exe
E:\Program Files\Messenger\msmsgs.exe
E:\WINDOWS\System32\RUNDLL32.exe
E:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
E:\Program Files\Creative\MediaSource\RemoteControl\RCMan.exe
E:\Program Files\Multimedia keyboard utility\1.3\KbdAp32A.exe
E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
E:\WINDOWS\System32\CTsvcCDA.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\MsPMSPSv.exe
E:\Program Files\Internet Explorer\IEXPLORE.exe
E:\Documents and Settings\AMD\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTSysVol] E:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] E:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [SBDrvDet] E:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [CTRegRun] E:\WINDOWS\CTRegRun.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [YBrowser] E:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [BJCFD] E:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "E:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] E:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMK08KB] E:\Program Files\Multimedia keyboard utility\1.3\MMKEYBD.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.exe E:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Creative MediaSource Go] E:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] E:\Program Files\Creative\MediaSource\RemoteControl\RCMan.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [SpySweeper] E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Global Startup: SBC Self Support Tool.lnk = E:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///E:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - E:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - E:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1098929199248
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Me Forum Home


Sponsored links

Ads by Google


Results for: CWS_NS3 and qttask.exe

qttask.exe www.computing.net/answers/windows-me/qttaskexe/13459.html

services.exe and rundll32.exe www.computing.net/answers/windows-me/servicesexe-and-rundll32exe/44721.html

windowsMe and twunk_16.exe and twunk_32. www.computing.net/answers/windows-me/windowsme-and-twunk16exe-and-twunk32/12417.html