Laptop update - all the stuff you don’t see
May 1, 2008 – 2:31 pmI always use more than one virus scanner. I know it takes more time, but if you look at the results below it will be come clear. Originally I tried just to clean the laptop with spybot to get an idea of just how infected it was. When I came across the licensing issue, and the problems with Symantec Live update, I knew it was time to wipe and start over. I booted with a copy of Trinity Rescue Kit, and used NTFS-3G along with rsync to backup everything on the laptop to a server I have just for backups. I then reformatted the laptop and used clamav on the archive. Below is the output from the clamscan. This is all the junk spybot *didn’t* find.
/data/user/WINDOWS/MEMORY.DMP: Adware.NewDotNet.B FOUND
/data/user/WINDOWS/Giggles-Shapes_SS.scr: Trojan.Downloader.Banload-4568 FOUND
/data/user/WINDOWS/NDNuninstall6_22.exe: Adware.NewDotNet.B-3 FOUND
/data/user/Documents and Settings/Owner/Local Settings/Temp/SAVE-Cm-Sm-Tb.exe: Adware.WhenU-3 FOUND
/data/user/Documents and Settings/Owner/Local Settings/Application Data/IM/Identities/{461B3DBF-2BF9-4A69-B5AE-ABFCAAEA10BD}/Message Store/Inbox.imm: Phishing.Heuristics.Email.SpoofedDomain FOUND
/data/user/Program Files/SuperStar/Beginning Math/start.exe: PUA.Elirt FOUND
/data/user/Program Files/Giggles Computer Funtime For Baby/Giggles-Shapes/Giggles Baby - Shapes.exe: Trojan.Downloader.Banload-4568 FOUND
/data/user/Program Files/Giggles Computer Funtime For Baby/Giggles-Shapes/Check Out Giggles Gear.exe: Trojan.Downloader.Banload-4568 FOUND
/data/user/Program Files/MSN Messenger/riched20.dll: Adware.Searchbar-19 FOUND
/data/user/Program Files/MP3 Player Utilities 3.68/DelDrv.exe: Trojan.Delall FOUND
/data/user/Program Files/Common Files/Symantec Shared/SymcData/idsdefs/20070426.001/sigs.dat: Exploit.JS.CVE-2005-1790.A FOUND
———– SCAN SUMMARY ———–
Known viruses: 274284
Engine version: 0.92.1
Scanned directories: 5364
Scanned files: 66988
Infected files: 12
Data scanned: 25033.76 MB
Time: 5946.744 sec (99 m 6 s)
(END)