
Help! Spyware Keeps Returning (hijackthis Log)
Started by
Kevin G
, Jul 10 2007 08:20 PM
42 replies to this topic
#31
Posted 20 July 2007 - 08:28 PM
Register to Remove
#32
Posted 21 July 2007 - 09:57 AM
nope the Zango removal didn't change anything in access issues. But I do find it interesting that you saw Zone alarm stuff, as it did used to be on here. and as far as adobe changes recently there were none that i know of.
#33
Posted 21 July 2007 - 03:05 PM
This then might be an issue of a partially uninstalled ZA package there - a pretty standard solution is to reinstall and then uninstall again, but let's see what that services is about as far as status first.
Go here http://www.billsway.com/vbspage/ and download, unzip and run the Registry Search Tool (scroll down the page to locate it). Type (or copy/paste) vsdatant in the dialog box. Let it run and after a few minutes, a prompt will appear. Click OK to write the results to Notepad and post them back here please.
Best to do a check for ATMhelpr as well, since I am not accustomed to seeing that in GMER logs until now.
Go here http://www.billsway.com/vbspage/ and download, unzip and run the Registry Search Tool (scroll down the page to locate it). Type (or copy/paste) vsdatant in the dialog box. Let it run and after a few minutes, a prompt will appear. Click OK to write the results to Notepad and post them back here please.
Best to do a check for ATMhelpr as well, since I am not accustomed to seeing that in GMER logs until now.
#34
Posted 22 July 2007 - 06:19 AM
REGEDIT4
; RegSrch.vbs � Bill James
; Registry search results for string "vsdatant" 7/22/2007 8:11:54 AM
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSDATANT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSDATANT 00]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSDATANT 00]
"Service"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSDATANT 00]
"DeviceDesc"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSDATANT 00\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\vsdatant]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\vsdatant]
"EventMessageFile"="C:\\WINDOWS\\system32\\vsdatant.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsdatant]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsdatant]
"DisplayName"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vsdatant\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT 00]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT 00]
"Service"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT 00]
"DeviceDesc"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT 00\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT 00\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSDATANT 00\Control]
"ActiveService"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\vsdatant]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\vsdatant]
"EventMessageFile"="C:\\WINDOWS\\system32\\vsdatant.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vsdatant]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vsdatant]
"DisplayName"="vsdatant"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vsdatant\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vsdatant\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vsdatant\Enum]
"0"="Root\\LEGACY_VSDATANT\