PDA

View Full Version : Clean up of Neglect



wyrmrider
2008-09-28, 23:12
I was given a Xp SP2 machine to clean up
6 kids Norton had expired, no third party firewall
It had SB 1.4 and ad-aware SE
which I removed and ran removal samll fix tool
It had windows live one care so I ran a scan
it found 6 malware but said it could not remove
so I tried windows defender and windows malicious software removal tool
no results

rinstalled spybot and there was a scan of around 1,000 items which found two (what?) but said could not remove
I cannot find a log of this install time scan- Is this a new feature?

so I ran a full scan and found 6 tracking cookies but no malware.

Incidentally after the scan I ran update before immunize and it found an update. (The most recent from last wednasday)
This update should have been found before the scan should it not?


I then ran MBAM and Rogue remover which also found nothing

I instlled Avast boot time scan found two items
one is our old friend JS:IstBar which I think Spybot should have caught
do you want the sample?
the other two were a generic trojan and generic adware
Spywarestormer[1].exe
I thought Spybot targeted Spywarestormer? Do you want a sample?
I'll upload these to Jotti and see if I can get a positive ID

So best case I still have 3 potential problems found by WLC assuming Avast got 3 of them
I think I'll run myself a HJT
not asking for malware removal help

wyrmrider
2008-09-29, 19:11
VT
analisis/
1dcc140bd4e48273ff3c65a209e9c88d
kaspersky
not-a-virus:PSWTool.Win32.PWDump.2,
not-a-virus:PSWTool.Win32.RAS.a
bit defender
Virtool.PWDump.A



be839cfaec80507df9ab434ce8366b95 prompt[1].htm Trojan-Downloader.JS.IstBar.j

23f4d962bf2564e8640ff9ef713a7cef Port_RockXP_v4.exe

ce8dea4188da9d3c35100216b8c91440 file may have been damaged
Spywarestormer


HJT resonably clear

spybotsandra
2008-10-01, 10:25
Hello,

Please send samples to:
samples(at)spybot.info
Thanks. :)

Best regards
Sandra
Team Spybot