HI,
I've been having trouble with Zlob.DNSchanger and possibly with several other malware as well. I followed the instructions in the ``BEFORE you POST'' topic :
1) eTrust Web Scanner did not find any infections (also it did not produce a log-file) and I used this scanner several times over the course of about a week.
2) Trend Micro did initially find infections, namely ADWARE_BHOT_E-VENTURES (13 infections), ADWARE_BHOT_IEHELPER (1 infection) and TSPY_BLASTER (1 infection). Incidentally, the tspy_blaster infection had been detected earlier also by the Kaspersky online scanner as
Net-Worm.Win32.Lovesan.a (located in C:\\WINNT\System32\TFTP1036).
In addition, Trend Micro detected 2 vulnerabilities (MS00-034 and MS01-028).
All infections have apparently been resolved by Trend Micro. However, when I ran Kaspersky another time, it found more infections (see the log below; the Backdoor.Win32.SdBot.pc had been detected by Kaspersky already earlier, but not the IM-Worm.Win32.Sohaned.t).
3) I ran Spybot in Safe Mode; it didn't detect anything. However, I forgot to run it in Safe Mode the first time and then it detected Zlob again; it keeps coming back apparently.
KASPERSKY ONLINE SCANNER REPORT
Thursday, August 09, 2007 5:17:07 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 9/08/2007
Kaspersky Anti-Virus database records: 377484
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 24902
Number of viruses found: 2
Number of infected objects: 4
Number of suspicious objects: 0
Duration of the scan process: 02:37:02
Infected Object Name / Virus Name / Last Action
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SYSTEM Object is locked skipped
C:\WINNT\system32\config\SOFTWARE Object is locked skipped
C:\WINNT\system32\config\DEFAULT Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\TFTP956 Infected: Backdoor.Win32.SdBot.pc skipped
C:\WINNT\Temp\ZLT0019c.TMP Object is locked skipped
C:\WINNT\Temp\ZLT001bd.TMP Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\Internet Logs\NO2.ldb Object is locked skipped
C:\WINNT\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINNT\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINNT\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
C:\Documents and Settings\Default User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_NO2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_NO2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Support.com\profiles\Administrator\triggers.log Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\COMPUTER RELATED\Hitman Pro\hitmanpro26.exe/file02 Infected: IM-Worm.Win32.Sohanad.t skipped
C:\Documents and Settings\Administrator\My Documents\COMPUTER RELATED\Hitman Pro\hitmanpro26.exe Inno: infected - 1 skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Hitman Pro\surfright.exe Infected: IM-Worm.Win32.Sohanad.t skipped
Scan process completed.
Finally, it has seemed to me that some icons relating to Yahoo Messenger look very slightly different for some weeks now - but perhaps this is merely due to some errors in my perceptions.
In any case, I would very much appreciate it if someone could help me with these problems.
Best regards, LSJ