Great summation by Merijn of known CWS variants so far :
CoolWebSearch ChroniclesThe last couple of days CWS has been real busy, new variants have been identified, some of them still under investigation :
1. sys.reg/winshow
as seen
HERE <- sys.reg
as seen
HERE <- winshow.dll
2. searchv/msupdater
as seen
HERE3. dreplace.dll (BHO)
as seen
HERE and
HERENOTE : If you have the Dreplace.dll, with svcinit in running processes, there is a special registry fix, written by Mosaic (thanks Mo!) :
Check the item below in HijackThis, close all windows except HijackThis and click Fix checked:
O2 - BHO: HTML Source Editor - {086AE192-23A6-48D6-96EC-715F53797E85} - C:\WINDOWS\System32\DReplace.dll
Then go to this site http://www.mjc1.com/files/mo/ and click the svcinit link and download userinit.zip
Unzip and doubleclick that file. (Thanks Pieter)
4. searchdot.net/C:\WINDOWS\Fonts\msoffice.hta (CWS?)
as seen
HERE5. searchv/mupdate
F0 - system.ini: Shell=Explorer.exe mupdate.exe
F1 - win.ini: run=mupdate.exe
F2 - REG:system.ini: Shell=Explorer.exe mupdate.exe
as seen
HERE6. Luckysearch.net variant, hijack keeps returning
as seen
HEREMerijn seems to be real busy irl; hope he hurries back soon, he will have a lot of work

Hope Tony and Pieter still have a lot of free time in their hands, for doing great investigational work

(Thanks to mjc and boOch for the help of this summation!)

Cheers,