I got called up by my parents about an infection their machine. The main evidence was WinFixer, however it transpired that there was a load of other stuff too.
I've followed the self help tutorial and things seem to be a little better. Can someone take a look at my Ewido and Hijackthis logs and tell me if there's any more I need to do? It'd be greatly appreciated.
I Ewido in safe mode as instructed and got the log below, then on reboot, Adaware automatically re-ran as expected and cleaned another fault.
My logs are;
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 15:42:53 19/08/2006
+ Scan result:
C:\Documents and Settings\Jane\Application Data\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\db -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\report -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\report\ag_ShopperReports.xml -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\report\ag_ShopperReports.xml.db -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\report\send_ShopperReports.xml -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\report\send_ShopperReports.xml.db -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\res1 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\cs\res1\WhiteList.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jane\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Brian\Cookies\brian@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@112.2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@112.2o7[4].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@marksandspencer.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@marksandspencer.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@microsofteup.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@msnuk.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@msnuk.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@ostg.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@propertyfinderltd.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@sonycorporate.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@2o7[5].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@blessedherbs.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@marksandspencer.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@redcatsuk.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Bpath : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Bpath : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@burstnet[4].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\simon\Cookies\simon@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][3].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][4].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][3].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][3].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@hypertracker[2].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Itrack : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@www.res99[1].txt -> TrackingCookie.Res99 : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@serving-sys[3].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@serving-sys[4].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed]-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed]-stat[3].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Brian\Cookies\brian@web-stat[3].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed]-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Jane\Cookies\jane@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Brian\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Jane\Cookies\[removed][3].txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
and
Logfile of HijackThis v1.99.1
Scan saved at 16:10:02, on 19/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\simon\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.lineone.net/search-main_ie4.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lineone.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lineone.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by LineOne
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lineone.net
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientIn…2/OCI/setup.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1140425442718
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
Many thanks in advance!
Simon