PDA

View Full Version : Zlob.Downloader issue



morpheus_77
2006-07-28, 22:28
Hello... I did a scan with ewido and it showed that i have an Zlob.Downloader, i believe the file was a wininet.dll
I followed all the instructions to remove the problem as posted on this board, as i've done this before, and ewido once again found the zlob.downloader. I applied all actions (thus quarantining the zlob). Spybot doesn't detect the zlob.downloader, neither does ewido either. I'm going to post my logs to make sure.
SmitFraudFix v2.69

Scan done at 14:37:14.81, 28/07/2006
Run from C:\Documents and Settings\Bailey\Desktop\DESKTOP FOLDERS\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

morpheus_77
2006-07-28, 22:29
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0028730.tlb -> Downloader.Zlob.yi : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.134:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.787:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.73:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.91:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.43:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.187:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.44:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.214:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.215:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.216:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.473:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.474:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.20:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.394:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.395:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.396:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.397:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.37:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.38:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.39:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.40:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.41:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.42:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.257:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.258:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.259:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.965:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.114:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.975:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.299:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.300:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.169:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Popuptraffic : Cleaned.

morpheus_77
2006-07-28, 22:29
:mozilla.175:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Popuptraffic : Cleaned.
:mozilla.281:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.292:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.293:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.857:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.858:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.859:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.860:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.96:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.97:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.14:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.15:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.16:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.17:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.920:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.921:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.922:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.955:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.172:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.173:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.112:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.49:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.50:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.51:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.52:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.798:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.799:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.800:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.71:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.109:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.110:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.113:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.72:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.86:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.87:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.88:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.89:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.90:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

morpheus_77
2006-07-28, 22:30
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138383301296
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

pskelley
2006-08-01, 02:39
Hello and welcome to the forum. You cut off the first four lines of the HJT log, but I managed to scan it and it is clean, as are the other logs. If your computer is back to normal, I would say you are good to go. Take this information with you:

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

ewido is a great program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?Open&src=sec_doc_nam

Safe surfing...tashi:) will close your topic in a day or so.

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

tashi
2006-08-05, 18:59
Thanks Phil.

Archived.