I will skip your comments and return to them after we discuss the logs and see what is left to do.
ewido anti-malware - Scan report Created on: 5:56:32 PM, 5/11/2006You can see all of the CoolWebSearch junk that CWShredder was supposed to remove. Something happened in the way that was run and I am hoping ewido got it all. We will run in again in safe mode to be sure, but it is so obvious you had a bad CWS infection also.
Right at this point it looks like ewido was able to remove what it found. I have links to show you how to control those cookies if you wish. I also have no objections to you editing your name out of the ewido report.
Logfile of HijackThis v1.99.1 Scan saved at 6:22:48 PM, on 5/11/2006 This log appears to be clean of malware:bigthumb: how is this computer running now?
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml
ewido is going to slow you a little, as will Prefetch until it repopulates. You can turn ewido off now or enjoy the benefits of the realtime protection for the trial period but it does use some resources. This is your call, and you can disable it in services when you wish, then keep and update the scanner if you wish, that is free. My canned:
ewido is a great program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.
Do this now to make sure none of that junk got in your System Restore files.
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?Open&src=sec_doc_nam
Now to your comments, for all programs that are running, good or bad, you are going to be prohitbited from changing or deleting by Windows if it is running. Normally just starting in safe mode when the program is not running will do it, sometimes you have to do it as an administrator, and yes we have tools like Killbox and Avenger that can do most anything. Seems to be a moot point as there appears to be no malware in the log.
Understand that HJT is a process manager, and when you remove an item from the HJT log the running process is stopped so you can delete an item. Some are harder than others, but in this case you have done the job.
This is what I would like you to do besides review the information I posted and purge the System Restore files.
1) Restart the computer in safe mode: http://www.bleepingcomputer.com/tutorials/tutorial61.html
Once you are in safe mode. open ewido and do a complete system scan removing anything located unless you know it is not bad. Save the scan report to post.
Empty your recycle bin and restart the computer to normal mode.
2) Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.
3) Post the ewido scan report (edit out personal names first) the Add Remove program list, and this time I need your comments. How is the computer running, what more do we need to do? Any error messages "word for word". Keep in mind this was one sick computer and we were none to gentle as we ripped some of the nasties out. Now is the time to look at your maintenance routines, scan disk, defragg, etc.
Thanks...Phil
ewido anti-malware - Scan report Created on: 5:56:32 PM, 5/11/2006You can see all of the CoolWebSearch junk that CWShredder was supposed to remove. Something happened in the way that was run and I am hoping ewido got it all. We will run in again in safe mode to be sure, but it is so obvious you had a bad CWS infection also.
Right at this point it looks like ewido was able to remove what it found. I have links to show you how to control those cookies if you wish. I also have no objections to you editing your name out of the ewido report.
Logfile of HijackThis v1.99.1 Scan saved at 6:22:48 PM, on 5/11/2006 This log appears to be clean of malware:bigthumb: how is this computer running now?
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml
ewido is going to slow you a little, as will Prefetch until it repopulates. You can turn ewido off now or enjoy the benefits of the realtime protection for the trial period but it does use some resources. This is your call, and you can disable it in services when you wish, then keep and update the scanner if you wish, that is free. My canned:
ewido is a great program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.
Do this now to make sure none of that junk got in your System Restore files.
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?Open&src=sec_doc_nam
Now to your comments, for all programs that are running, good or bad, you are going to be prohitbited from changing or deleting by Windows if it is running. Normally just starting in safe mode when the program is not running will do it, sometimes you have to do it as an administrator, and yes we have tools like Killbox and Avenger that can do most anything. Seems to be a moot point as there appears to be no malware in the log.
Understand that HJT is a process manager, and when you remove an item from the HJT log the running process is stopped so you can delete an item. Some are harder than others, but in this case you have done the job.
This is what I would like you to do besides review the information I posted and purge the System Restore files.
1) Restart the computer in safe mode: http://www.bleepingcomputer.com/tutorials/tutorial61.html
Once you are in safe mode. open ewido and do a complete system scan removing anything located unless you know it is not bad. Save the scan report to post.
Empty your recycle bin and restart the computer to normal mode.
2) Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.
3) Post the ewido scan report (edit out personal names first) the Add Remove program list, and this time I need your comments. How is the computer running, what more do we need to do? Any error messages "word for word". Keep in mind this was one sick computer and we were none to gentle as we ripped some of the nasties out. Now is the time to look at your maintenance routines, scan disk, defragg, etc.
Thanks...Phil