I have a user that I am positive has the CWS trojan.
Anti-virus shows clean bill of health.
We loaded and ran spysweeper on the user's machine. Spyweeper keeps popping up the same files even after he quarantees and removes these files:
C:\WINNT\ntpb32.exe
C:\WINNT\system32\htqa.exe
C:\WINNT\system32\apppk.exe
C:\WINNT\mfcyb.exe
C:\WINNT\system32\apimg.exe
C:\WINNT\system32\d3wg32.exe
C:\WINNT\system32\d3ts32.exe
Doing some investigation I concluded that he has the CWS trojan (variant unknown). I downloaded removeCWS_killer.exe and it stated that it was not found. So then I ran CWShredder.exe and tried to update it from 1.59.0 to 1.59.1 and it wouldn't let us update. So we just tried to run [Fix] without updating and it the window/ application would disappear. So the user tried to restart the app and it came up stating that the CWS trojan variant was present and that the program/application was started under a random string???
So I had her reboot her system to try and run it again, but she received some image errors on boot up and when we finally ran the CWShredder.exe again we got the same disappearing application problem.
So I had her reboot into safe mode and try again and got the same results.
So now I am stuck trying to fix the problem. Need help desperately!!
I looked at this thread, but not sure if this would be a good start for me. Very strange behaviour in XP thread779-764333
Any help would be grateful.
TIA
Carrie
Anti-virus shows clean bill of health.
We loaded and ran spysweeper on the user's machine. Spyweeper keeps popping up the same files even after he quarantees and removes these files:
C:\WINNT\ntpb32.exe
C:\WINNT\system32\htqa.exe
C:\WINNT\system32\apppk.exe
C:\WINNT\mfcyb.exe
C:\WINNT\system32\apimg.exe
C:\WINNT\system32\d3wg32.exe
C:\WINNT\system32\d3ts32.exe
Doing some investigation I concluded that he has the CWS trojan (variant unknown). I downloaded removeCWS_killer.exe and it stated that it was not found. So then I ran CWShredder.exe and tried to update it from 1.59.0 to 1.59.1 and it wouldn't let us update. So we just tried to run [Fix] without updating and it the window/ application would disappear. So the user tried to restart the app and it came up stating that the CWS trojan variant was present and that the program/application was started under a random string???
So I had her reboot her system to try and run it again, but she received some image errors on boot up and when we finally ran the CWShredder.exe again we got the same disappearing application problem.
So I had her reboot into safe mode and try again and got the same results.
So now I am stuck trying to fix the problem. Need help desperately!!
I looked at this thread, but not sure if this would be a good start for me. Very strange behaviour in XP thread779-764333
Any help would be grateful.
TIA
Carrie