PDA

View Full Version : Icepack To Tashi Regarding Malware & Trojans



icepack
2009-12-17, 00:24
Hi Tashi,
I hope I am doing this correctly.Spybot gave me an option to copy scan results onto clipboard which I am including in this new post.


I've been struggling with 3 Malware entries under Win32.Agent.pz that are said to be fixed by my Spybot program but they keep showing up the next time I scan.

I also have a Win32.zBot showing up with 5 Trojan entries and have the same problem.4 of the 5 trojans are said to be fixed but again show up when I scan.One trojan in the program directory cannot be fixed.

My problems are light so far involving a few game icons that will not open and only lead to larger problems if they are clicked on.I have had warnings from microsoft that my computer is infected with I think about 24 different items which is the count on this clipboard I am pasting on this thread.


I've just today downloaded the recent Spybot program replacing the older one and was hoping it would solve my problems the older one could not.

Thanks Again,
Andrew

Win32.Agent.pz: [SBI $7EC6899E] Settings (Registry value, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Network\UID

Win32.Agent.pz: [SBI $8980C6CD] Settings (Registry value, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Network\UID

Win32.Agent.pz: [SBI $0F1C75F7] Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID

Win32.ZBot: [SBI $6CF375A8] Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=...C:\WINDOWS\system32\sdra64.exe,...

Win32.ZBot: [SBI $C6F7C082] File (File, nothing done)
C:\WINDOWS\system32\sdra64.exe
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E

Win32.ZBot: [SBI $8D46873E] Program directory (Directory, nothing done)
C:\WINDOWS\system32\lowsec\

Win32.ZBot: [SBI $7F8D8AB8] File (File, nothing done)
C:\WINDOWS\system32\lowsec\local.ds
Properties.size=206850
Properties.md5=D41D8CD98F00B204E9800998ECF8427E
Properties.filedate=1261001345
Properties.filedatetext=2009-12-16 17:09:04

Win32.ZBot: [SBI $163CD113] File (File, nothing done)
C:\WINDOWS\system32\lowsec\user.ds
Properties.size=0
Properties.md5=D41D8CD98F00B204E9800998ECF8427E
Properties.filedate=1261003409
Properties.filedatetext=2009-12-16 17:43:28


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-12-16 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-09-07 advcheck.dll (1.6.4.18)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-10-08 Includes\Adware.sbi (*)
2009-12-15 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2009-12-15 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-12-15 Includes\HijackersC.sbi (*)
2009-12-15 Includes\Keyloggers.sbi (*)
2009-12-15 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-12-15 Includes\Malware.sbi (*)
2009-12-15 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-12-15 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-12-15 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-11-03 Includes\Spyware.sbi (*)
2009-12-15 Includes\SpywareC.sbi (*)

tashi
2009-12-17, 02:14
Hello icepack,


Please see this forum's FAQ which details how to produce a HJT log and copy paste it into a new topic.
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

If HJT won't run please start a new topic anyway, make note of the situation and an authorized volunteer analyst will advise you when available.

Best regards.
http://forums.spybot.info/newreply.php?do=newreply&p=351795

Edit
http://forums.spybot.info/showthread.php?t=54178 :)