Home / Software / Computer viruses and spyware / W32.Silly FDC.. what to do? plz
0 Members and 2 Guests are viewing this topic. « previous next »
Pages: 1 2 [All] - (Bottom) Print
Author Topic: W32.Silly FDC.. what to do? plz  (Read 12595 times)
Daffodial
Topic Starter
Rookie



Posts: 17


« on: June 11, 2008, 05:29:50 PM »

Hi great CH members.

I am in need for your geneoristy. After a full scan of my pc, i found this virus W32.Silly FDC (Two of it). Norton states that its risk level is high and it can't be removed so it suggests a reveiw of the virus. That's all. Plz help me how to get rid of it without losing any of my files.  ???

BTW, i ve Windows Vista which is protected by Norton and i run a regular update for the Windows and the Norton. I believed that this is all i need to do to protect my pc. I seem to be mistaken after all :'( :'(

I'd highly appreciate it. Thanks in advance  :-*
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #1 on: June 11, 2008, 05:53:38 PM »

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT  FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #2 on: June 14, 2008, 12:03:52 PM »

Are procedures followed for desktop pc the same as for laptop? coz this problem is in my laptop!!
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #3 on: June 14, 2008, 12:08:25 PM »

Same thing.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #4 on: June 19, 2008, 03:06:59 AM »

This's Superantispyware log.....

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/19/2008 at 11:58 AM

Application Version : 4.15.1000

Core Rules Database Version : 3485
Trace Rules Database Version: 1476

Scan type       : Complete Scan
Total Scan Time : 00:44:07

Memory items scanned      : 221
Memory threats detected   : 0
Registry items scanned    : 7064
Registry threats detected : 0
File items scanned        : 87478
File threats detected     : 18

Adware.Tracking Cookie
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@ad.yieldmanager[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@ads.araby[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@ads.cnn[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@advertising[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@apmebf[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@atdmt[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@casalemedia[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@doubleclick[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@eas.apm.emediate[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@fastclick[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@imrworldwide[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@m1.webstats.motigo[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@revenue[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@rotator.adjuggler[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@specificclick[2].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@statcounter[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@tacoda[1].txt
   C:\Users\MoOnYzoOmy\AppData\Roaming\Microsoft\Windows\Cookies\Low\moonyzoomy@tribalfusion[2].txt
   .doubleclick.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   rotator.adjuggler.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   rotator.adjuggler.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .statcounter.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .statcounter.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .statcounter.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .tribalfusion.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   ad.yieldmanager.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   www7.addfreestats.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .toplist.cz [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .adbrite.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .adbrite.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   *Blocked Russian URL* [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .advertising.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .fastclick.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .2o7.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .eb.adbureau.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.pointroll.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .atdmt.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .pro-market.net [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .webstats4u.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   eas.apm.emediate.eu [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   eas.apm.emediate.eu [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .track.webgains.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .apmebf.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   linkto.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   linkto.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   linkto.mediafire.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .clickaider.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .smileycentral.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .smileycentral.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .maxserving.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .ads.bridgetrack.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
   .mywebsearch.com [ C:\Users\MoOnYzoOmy\AppData\Roaming\Mozilla\Firefox\Profiles\e3cagx8g.default\cookies.txt ]
IP logged
Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #5 on: June 19, 2008, 03:47:13 AM »

Hi there,

While performing full scan by Malwarebytes' Anti-Malware, my computer has encountered an unexpected shutdown. After recovering from the shutdown, windows asked for checking solution online but I didn't coz i wanna ask you first if it's ok and what the problem is.

BTW while scanning, the internet was connected. Should I disconnect before scanning or what?

What shall I do now?

My Regards,
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #6 on: June 19, 2008, 10:11:20 AM »

Similar thing happened on one of my client's infected computer.
Try running scan one more time.
If it doesn't work, try Safe Mode.
If that doesn't work, post HJT log from Normal Mode.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #7 on: June 20, 2008, 02:30:23 AM »

It works on the safe mode,

Here's the log...

Malwarebytes' Anti-Malware 1.17
Database version: 869

11:18:33 20/06/08 a.m
mbam-log-6-20-2008 (11-18-33).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 127199
Time elapsed: 18 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 23
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
IP logged
Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #8 on: June 20, 2008, 02:49:49 AM »

Here's HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:46:53 a.m, on 20/06/08
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 11512 bytes
IP logged
Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #9 on: June 20, 2008, 02:59:22 AM »

Now what?  :)

I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.  :-\
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #10 on: June 20, 2008, 06:38:39 PM »

Quote
I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.
You'll have to elaborate little bit more on the above.

Meanwhile...

*** You need to update Java:
http://java.sun.com/javase/downloads/index.jsp
Java Runtime Environment (JRE) 6 Update 6
Uninstall all previous versions of Java through Add\Remove.

*** Disable Windows Defender, as it'll interfere with cleaning process:
   * Open Windows Defender
    * Click Tools
    * Click General Settings
    * Scroll down to Real Time Protection Options
    * Uncheck Turn on Real Time Protection
    * After you uncheck this, click on the Save button
    * Close Windows Defender

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- *O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
- *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
- *O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
- *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
- *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- *O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
- O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


4. Click on Fix checked button.

5. Restart computer.

6. Post new HijackThis log.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #11 on: June 21, 2008, 04:06:19 PM »

Hi Sir,


Concerning Java, which one to download (windows offline installion or windows online installion)? and which platform to choose (Windows , windows x64)???

Shall I uninstall all previous versions of java after updating java?

Thanks for being tolerant with me.  :-[
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #12 on: June 21, 2008, 06:01:42 PM »

Normally, I install off-line. Select Windows (not 64), and, yes, uninstall all previous versions.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #13 on: June 25, 2008, 04:04:04 PM »

Hi again,

After clicking on Fix checked button, a new window of HJT suddenly appears stating that an unexpected error has occured at procedure:
- O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

Error #5 Invalid procedure call or argument


Besides, after fixing finished, a window appears telling that HJT is not running correctly.

This is the new HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:18 ص, on 26/06/08
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 11254 bytes
IP logged
Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #14 on: June 25, 2008, 04:30:55 PM »

Quote
I've noticed that empty shortcuts are everywhere. Also i've found many created system files, files with dat and ini extensions which weren't there before.
You'll have to elaborate little bit more on the above.

Ok ..

When opening the C driver, I'd see empty and transparent folders like: $Recycle.Bin , shortcut of Documents and Settings, System Volume Information...
Inside Program Data Folder on C again, you'd find shortcuts of Application Data, Desktop, Document, Favouarite, Start menue, Templates. Again they are all empty.
And i'd see files like: autoexec.bat, config.sys , IO.sys .... and the like.

Once opening Username Folder, I'd find files like: ntuser.dat.log1 , ntuser.dat.log2, ntuser.dat (BLF file), ntuser.dat  (Regtrans-ns file), and ntuser.ini (config setting)

Once opening any folder containg a movie, I'd see $$Jet.THM$$.cache (cache file)

I'd find similar folders and files everywhere. Mostly they are shortcuts or empty folders. Once I tried deleting them, it's said that they contain a system file like desktop.ini and i cant remove them.

This is what makes me post here. My laptop was just brand clean but out of the blue these bugging folders are everywhere. ::)  :(


My Best Regards,
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #15 on: June 25, 2008, 07:43:45 PM »

Did you disable Windows Defender, while using HJT?
If so, uninstall HJT, download fresh copy, install it, and run steps form my post #10 again.

Don't worry about those strange looking files. As far, as I can see, they're all needed. Don't play with them, or things may get worse.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #16 on: June 26, 2008, 03:07:16 AM »

Hi Broni,

When attempting to disable Windows Defender, I've found that it's already turned off. So I've just followed the next steps.

Is that ok? or shall I turn it on and then disable it?
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #17 on: June 26, 2008, 06:06:14 PM »

That's fine. Leave it off for now.
Did you:
Quote
uninstall HJT, download fresh copy, install it, and run steps form my post #10 again.
IP logged

Daffodial
Topic Starter
Rookie



Posts: 17


« Reply #18 on: June 27, 2008, 04:44:58 AM »

Yep and this is the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:32:17 م, on 27/06/08
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 11535 bytes


IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #19 on: June 27, 2008, 07:25:33 PM »

*** Disable Windows Defender, as it'll interfere with cleaning process:
   * Open Windows Defender
    * Click Tools
    * Click General Settings
    * Scroll down to Real Time Protection Options
    * Uncheck Turn on Real Time Protection
    * After you uncheck this, click on the Save button
    * Close Windows Defender

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
- *O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
- *O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
- O4 - Global Startup: Bluetooth Manager.lnk = ?
- O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
- O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)


4. Click on Fix checked button.

5. Restart computer.

6. Post new HijackThis log.
IP logged

junnosuke_sama
Newbie



Posts: 1


« Reply #20 on: June 16, 2010, 08:32:49 PM »

Hi Broni,

I'm also having the same issue with W32.SillyDC. This morning I logged onto my computer to check my email. For one of my inbox I found an email to myself from my aol account. Several people were attached and this was the only successful email to send from my aol account. Currently, aol has demonstrated a number of 18 activities. 17 of those emails were returned because of incorrect email addresses or bots. Norton classified the problem as: desktop.ini contained threat W32.SillyDC. I was wondering if the aol incident is related to the worm. It's been 9 hours since the last attempted email--which failed. *roughly this is when i deleted a few more desktop.ini--after the first--and restarted my computer*

I believe I know what the problem is. I downloaded some files yesterday. One was an album that went into my music folder and the older was some chapters that went into a sub-manga folder. When I realized that emails were being sent without me doing so, I quickly deleted the album I downloaded. Hours later once the problem was diagnosed I checked out my manga folder. (Note: One of the manga files I couldn't transfer from the zip folder and into my folder because an error box kept appearing. I finally managed to get the file by downloading from another available link. This was yesterday). When I discarded the music album as the cause of incident I deleted the manga files, as soon as I did desktop.ini appeared in that folder. I googled desktop.ini and read in a forum that ". . ".ini is perfectly fine. One way or another IExplorer uses this file and they're meant to be hidden. Apparently, the reason why they show is because I somehow disabled the hidden button--which I didn't. Microsoft seems to agree with this statement because it tells me how to disable visibility. I also stumbled across another source of information stating that desktop.ini appears when the folder has been customized. While looking at the folders from my C drive, this statement also proved to be 90% true. Some files I don't remember using within this week for a desktop.ini to be present.

Since the first diagnostic I've run two extra scans. Only cookies are being resolved. I looked at the source and the problem is explorer. all other cookies from seamonkey and firefox aren't being considered a threat. On my old computer, which still works perfectly fine, I had to delete explorer because of viruses that were being tracked back to it.

To make long story short, my major concern is this W32.SillyCD. Norton says the problem has been resolved--though, it didn't appear as such until I deleted some desktop.ini. Could this worm be affecting my aol account? I'm thinking this is something else because my computer runs perfectly fine. I've restarted it and nothing pops up. Not that anything ever did. My other email accounts work fine. I do notice some transparent files though. They have shortcuts and folders like: Documents and Settings, Cookies, Local Settings, ect, can not be opened. I keep getting an access denied. Looking back at the folders I checked this morning, more shortcut transparent files appear. I also deleted some files (Ntuser.dat) and they reappear in the folders. They are dated from today, 3:42PM.  I can not delete the Ntusers from my document folder, I keep getting access denied. Now, a ntuser.ini appears in that folder which wasn't there before. Should I leave things as they are or should I still be concerned despite what Norton says? I've only had this computer for 10 months. I'm sure one or two more virus exist somewhere but none have manifested any trouble.

I tried following the steps you gave earlier but I can't find Run on my start menu. Of all things!!

I'm sorry to be another technotard.

Thank you and enjoy your day!
IP logged
Broni
Mastermind


Thanked: 610
Posts: 28,751

Computer: Specs
Experience: Experienced
OS: Windows Vista


Kraków my love :)

Computer Help Forum
« Reply #21 on: June 16, 2010, 09:14:27 PM »

Read here: http://www.computerhope.com/forum/index.php/topic,46313.0.html
Start new topic here: http://www.computerhope.com/forum/index.php/board,7.0.html
Do NOT post any logs in THIS thread.
IP logged

Peterwolfe
Hopeful



Posts: 287




« Reply #22 on: June 17, 2010, 03:57:12 PM »

oh naughty PC user, junnosuke_sama, on what sites have you been????? And never use Norton......use the free warez from the Net!!! They are all better than this slavedriver...
IP logged
Pages: 1 2 [All] - (Top) Print 
Home / Software / Computer viruses and spyware / W32.Silly FDC.. what to do? plz « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 5.464 seconds with 19 queries.