<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: [Trojan] Zlog.Downloader.oid, Smithfraud.C, Virus Protect &#x26; in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20399428</link>
<description></description>
<language>en</language>
<pubDate>Fri, 29 Aug 2008 23:20:13 EDT</pubDate>
<lastBuildDate>Fri, 29 Aug 2008 23:20:13 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] Zlog.Downloader.oid, Smithfraud.C, Virus Protect &#x26;</title>
<link>http://www.dslreports.com/forum/remark,20401164</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi hilldweller<br><br>Your HijackThis log shows that the infection had not been completely removed (before you chose to reformat).<br>The infection could have been removed.<br><br>Now that you have reformatted and reinstalled, here are some recommendations.<br><br>Please check your ActiveX security settings (Start -> Settings -> Control Panel -> Internet Options, Security Tab -> Internet -> Custom Level) and reset as recommended:<br><br>ActiveX controls and plug-ins<br>* Download signed ActiveX controls (Prompt)<br>* Download unsigned ActiveX controls (Disable)<br>* Initialize and script ActiveX controls not marked as safe (Disable)<br>* Script ActiveX controls marked safe for scripting (Prompt)<br>* Launching programs and files in an IFRAME (Prompt)<br>* Navigate sub-frames across different domains (Prompt)<br><br>I recommend installing a software firewall. I didn't see one in your HijackThis log (the XP SP2 firewall isn't sufficient protection, it only checks incoming data). Two free firewalls are Sunbelt Kerio Personal Firewall available from http://www.sunbelt-software.com/Kerio.cfm, and Zone Alarm from zonelabs.com http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp. There is a tutorial on understanding firewalls at http://www.bleepingcomputer.com/forums/tutorial60.html and and a tutorial from Markus Jansson on setting up ZoneAlarm at http://www.markusjansson.net/eza.html. If you install ZoneAlarm (an excellent firewall), I recommend <b>NOT</b> installing the new optional feature <i>Spy Blocker</i>, as it's run by the questionable search engine Ask.com. You can read more about Ask.com <A HREF="http://www.benedelman.org/spyware/installations/askjeeves-banner/"><b><u>here</u></b></a>.<br><br>There is a newer version of AVG available, version 8. If you use the free version, that has also been released:<br><A HREF="http://free.grisoft.com/ww.download?prd=afe">http://free.grisoft.com/ww.download?prd=afe</a><br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at http://www.mvps.org/winhelp2002/hosts.htm. <br><br>IE/SPYAD adds sites associated with ads and spyware to your Internet Restricted Zone and you can download that at http://www.spywarewarrior.com/uiuc/resource.htm.<br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at http://www.javacoolsoftware.com/products.html. <br><br>I recommend reading Tony Klein's article <i>So How did I get Infected in the First Place?</i> at http://forums.spywareinfo.com/index.php?showtopic=60955<br><br>Edit: URL fixed<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20401164</guid>
<pubDate>Mon, 28 Apr 2008 17:14:40 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] Zlog.Downloader.oid, Smithfraud.C, Virus Protect &#x26;</title>
<link>http://www.dslreports.com/forum/remark,20399428</link>
<description><![CDATA[<A HREF="/useremail/u/1123350"><b>hilldweller</b></A> : Problems came back, reformated and reinstalled.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20399428</guid>
<pubDate>Mon, 28 Apr 2008 12:14:51 EDT</pubDate>
</item>

<item>
<title>[Trojan] Zlog.Downloader.oid, Smithfraud.C, Virus Protect &#x26; etc</title>
<link>http://www.dslreports.com/forum/remark,20136432</link>
<description><![CDATA[<A HREF="/useremail/u/1123350"><b>hilldweller</b></A> : I have ran Spybot Search and Destroy, AVG Antivirus and CA online scans, Adaware does not run, errors out on updating.<br>Please review for furthe problems.<br><br>Thanks for your service :)<br><br>I am posting the Spybot and Hijackthis logs:<br><br>--- Report generated: 2008-03-09 11:48 ---<br><br>SpyLocked.FakeAlert: [SBI $636BCE49] Uninstall settings (Registry key, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert<br><br>VirusProtect: [SBI $21D7A104] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{0979850F-6C3E-4294-B225-B3D3C4A6F2A1}<br><br>VirusProtect: [SBI $08A67F25] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{1BB2DA5F-B78F-44EA-BDA1-771CBE1DEC68}<br><br>VirusProtect: [SBI $DCDE6275] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{2A4E73C5-BA3C-4391-B7E5-FFE8D3BD6245}<br><br>VirusProtect: [SBI $7DEC7ECA] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{44A923CA-F430-4F85-9F84-5153ECDB882E}<br><br>VirusProtect: [SBI $40334284] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{4E6E21EC-9D72-4164-8A53-74786A467872}<br><br>VirusProtect: [SBI $AE26764B] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{631E9E48-B066-43DA-92AC-6DADF61B173B}<br><br>VirusProtect: [SBI $943F4215] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{65C1361C-E696-4AF0-9E21-81910193F352}<br><br>VirusProtect: [SBI $723426D5] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{77DCE805-C8CE-48AA-A47F-BFA6CC7704B3}<br><br>VirusProtect: [SBI $BFAF0A61] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{8D42769F-07D8-494D-AAB4-AA1652C541FA}<br><br>VirusProtect: [SBI $1F67FF17] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{A1922071-390C-418D-916D-91209E95D286}<br><br>VirusProtect: [SBI $EDB577AC] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{A1F8CD95-CFB3-43D1-A956-63441CC058C1}<br><br>VirusProtect: [SBI $122EA804] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{A63B46AD-96A7-4A2C-BD8F-8CD097E1593A}<br><br>VirusProtect: [SBI $6B445D72] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{A65F98DD-2360-468C-B76E-B1B84C0D547C}<br><br>VirusProtect: [SBI $F574529F] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{AE2AEED0-BE1B-4BA2-826E-20D1991081B8}<br><br>VirusProtect: [SBI $36BBE026] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{D7F73787-6206-4BBA-BDC0-7CFA9940DBCB}<br><br>VirusProtect: [SBI $21FAEE5D] Interface (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\Interface\{E770F739-2968-4ED9-A63C-DC1938DC82A2}<br><br>VirusProtect: [SBI $925637FC] Type library (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\TypeLib\{CFAFA83C-855B-4E3D-92B9-A587995B675A}<br><br>Win32.Renos: [SBI $7B2A75E0]  Executable (File, fixed)<br>  C:\Documents and Settings\Jim\Local Settings\Temp\laf4.exe<br><br>Smitfraud-C.: [SBI $10577975] Autorun settings (Registry value, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\some<br><br>Smitfraud-C.: [SBI $8F732AAF] Autorun settings (Registry value, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\start<br><br>Win32.Renos: [SBI $3A39BF54] Class ID (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\CLSID\{917f93bf-6714-4e11-8982-59db2e0f88fc}<br><br>Win32.Renos: [SBI $71F2A583] Autorun settings (Registry value, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{917f93bf-6714-4e11-8982-59db2e0f88fc}<br><br>Zlob.Downloader.vdt: [SBI $F73BCA8D] Uninstall settings (Registry key, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software<br><br>Zlob.Downloader.oid: [SBI $D9A7F62E] Browser helper object (Registry key, fixed)<br>  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}<br><br>Zlob.Downloader.oid: [SBI $4D3C8FCD] Class ID (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\CLSID\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}<br><br>Zlob.Downloader.vdt: [SBI $9098130D] User settings (Registry key, fixed)<br>  HKEY_USERS\S-1-5-21-1659004503-1454471165-725345543-1004\Software\NetProject<br><br>Zlob.Downloader.vdt: [SBI $00788CF1] Program directory (Directory, fixed)<br>  C:\Program Files\NetProject\<br><br>Zlob.Downloader.vdt: [SBI $3E9924D8]  Executable (File, fixed)<br>  C:\Program Files\NetProject\uninst.exe<br><br>Zlob.Downloader.vdt: [SBI $673E8E06] Settings (Registry key, fixed)<br>  HKEY_CLASSES_ROOT\videoPl.chl\<br><br>--- Spybot - Search & Destroy version: 1.5.2  (build: 20080128) ---<br><br>2008-01-28 blindman.exe (1.0.0.7)<br>2008-01-28 SDDelFile.exe (1.0.2.4)<br>2008-01-28 SDMain.exe (1.0.0.5)<br>2007-10-07 SDShred.exe (1.0.1.2)<br>2008-01-28 SDUpdate.exe (1.0.8.8)<br>2008-01-28 SDWinSec.exe (1.0.0.11)<br>2008-01-28 SpybotSD.exe (1.5.2.20)<br>2008-01-28 TeaTimer.exe (1.5.2.16)<br>2008-03-09 unins000.exe (51.49.0.0)<br>2008-01-28 Update.exe (1.4.0.6)<br>2008-01-28 advcheck.dll (1.5.4.5)<br>2007-04-02 aports.dll (2.1.0.0)<br>2007-11-17 DelZip179.dll (1.79.7.4)<br>2008-01-28 SDFiles.dll (1.5.1.19)<br>2008-01-28 SDHelper.dll (1.5.0.11)<br>2008-01-28 Tools.dll (2.1.3.3)<br>2008-03-05 Includes\Cookies.sbi (*)<br>2007-12-26 Includes\Dialer.sbi (*)<br>2008-03-05 Includes\DialerC.sbi (*)<br>2008-03-05 Includes\HeavyDuty.sbi (*)<br>2008-03-05 Includes\Hijackers.sbi (*)<br>2008-03-05 Includes\HijackersC.sbi (*)<br>2008-02-27 Includes\Keyloggers.sbi (*)<br>2008-03-05 Includes\KeyloggersC.sbi (*)<br>2004-11-29 Includes\LSP.sbi (*)<br>2008-02-27 Includes\Malware.sbi (*)<br>2008-03-05 Includes\MalwareC.sbi (*)<br>2008-02-20 Includes\PUPS.sbi (*)<br>2008-03-05 Includes\PUPSC.sbi (*)<br>2008-03-05 Includes\Revision.sbi (*)<br>2008-01-09 Includes\Security.sbi (*)<br>2008-03-05 Includes\SecurityC.sbi (*)<br>2008-02-20 Includes\Spybots.sbi (*)<br>2008-03-05 Includes\SpybotsC.sbi (*)<br>2007-11-06 Includes\Tracks.uti<br>2008-02-27 Includes\Trojans.sbi (*)<br>2008-03-05 Includes\TrojansC.sbi (*)<br>2007-12-24 Plugins\TCPIPAddress.dll<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 1:33:22 PM, on 3/9/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16608)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>C:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>C:\WINDOWS\system32\CTsvcCDA.exe<br>C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\system32\MsPMSPSv.exe<br>C:\WINDOWS\system32\RUNDLL32.EXE<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\PROGRA~1\Grisoft\AVG7\avgcc.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.battle.net/" >www.battle.net/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')<br>O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe<br>O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe<br>O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - &raquo;<A HREF="http://www.explorertool.net/redirect.php" >www.explorertool.net/redirect.php</A> (file missing)<br>O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - &raquo;<A HREF="http://www.explorertool.net/redirect.php" >www.explorertool.net/redirect.php</A> (file missing)<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - &raquo;<A HREF="http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab" >www.ca.com/us/securityadvisor/vi&middot;&middot;&middot;scan.cab</A><br>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &raquo;<A HREF="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" >fpdownload2.macromedia.com/get/s&middot;&middot;&middot;lash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{D82AF55E-1798-4B19-B9AE-307287EF818B}: NameServer = 206.13.29.12,206.13.30.12<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe<br>O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br><br>--<br>End of file - 5887 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20136432</guid>
<pubDate>Sun, 09 Mar 2008 16:44:34 EDT</pubDate>
</item>

</channel>
</rss>
