×

Loading...

this may help you.

here is an example of remove CWS.Msconfd
1)Running CWShredder in Windows and rebooting after it detected and tried to repair the infectio.

2) Deleting the c:\winnt\system32\msconfd.dll file via Dos using a bootdisk (do not log into windows). You cannot delete this in Windows as it states that the file is in use.

3) Creating an empty text file in its place and making its attributes read only (make sure name is msconfd.dll and it is stored in C:\winnt\system32\).

4) Booting up normally into Windows and running CWShredder.

5) CWShredder finds the trojan and asks to reboot.

6) Once I rebooted I got a few error messages as the trojan tried to reinfect but could not because of the harmless read only msconfd.dll file I created in its location.

7) I then rebooted again and this time when I ran CWShredder it no longer appeared!!!

While doing this whole process I disabled my Internet connection but I do not know if this helped or not. Better to be safe...

Hope that helps you.
Sign in and Reply Report

Replies, comments and Discussions:

  • 枫下家园 / 电脑用户 / 我自己的google被黑了,中了cws病毒.找了3个小时解药也没治好.
    现象是,google搜索结果的连接被病毒篡改,改到 coolwebsearch,umaxsearch,等4~5个不同的垃圾网站上.
    每次要把搜索结果下面显示的连接地址手工复制到地址栏上才可以.
    按网上别人介绍的方法,禁止了 java,安装了adaware 6.0,最后把瑞星和nav 2004都升级也无效.凑合用了,痛苦啊.
    • this may help you.
      here is an example of remove CWS.Msconfd
      1)Running CWShredder in Windows and rebooting after it detected and tried to repair the infectio.

      2) Deleting the c:\winnt\system32\msconfd.dll file via Dos using a bootdisk (do not log into windows). You cannot delete this in Windows as it states that the file is in use.

      3) Creating an empty text file in its place and making its attributes read only (make sure name is msconfd.dll and it is stored in C:\winnt\system32\).

      4) Booting up normally into Windows and running CWShredder.

      5) CWShredder finds the trojan and asks to reboot.

      6) Once I rebooted I got a few error messages as the trojan tried to reinfect but could not because of the harmless read only msconfd.dll file I created in its location.

      7) I then rebooted again and this time when I ran CWShredder it no longer appeared!!!

      While doing this whole process I disabled my Internet connection but I do not know if this helped or not. Better to be safe...

      Hope that helps you.
    • hijackthis
    • CWShredder