Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Another W32.silly.fdc, Logs posted  (Read 5682 times)

0 Members and 1 Guest are viewing this topic.

psychotic

    Topic Starter


    Greenhorn

    Another W32.silly.fdc, Logs posted
    « on: April 06, 2009, 12:25:10 PM »
    The only other 3rd party program I have on this computer, particularity, is EndItAll. (Not counting the programs for these scans)

    Also, I am also experiencing these "transparent"(The same thing daffodil had.) files, here is a list of what they are.

    desktop.ini
    desktop.ini (Yes, there are 2 of them.)
    Folder.jpg
    AlbumArtSmall.jpg
    AlbumArt_(Random characters, numbers, and letters)Large
    AlbumArt_(Random characters, numbers, and letters)Small

    (On a side note, about those files, all except the desktop.ini files, have a picture, with the words Pat Banter, and a picture of her behind it... I'm under the assumption I got a ********* torrent, is this correct?)

    Haven't so much as clicked them, but by the names, they seem harmless, are they safe to trash? Or do they serve some kind of purpose?

    I started the other one (with daffodil)  Soooo... Here are my logs from the SUPERAntiSpyware:


    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/06/2009 at 03:52 PM

    Application Version : 4.26.1000

    Core Rules Database Version : 3830
    Trace Rules Database Version: 1786

    Scan type       : Complete Scan
    Total Scan Time : 00:58:03

    Memory items scanned      : 288
    Memory threats detected   : 0
    Registry items scanned    : 6851
    Registry threats detected : 2
    File items scanned        : 148212
    File threats detected     : 24

    Adware.Tracking Cookie
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@imrworldwide[2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@interclick[1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@coolsavings[2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@petfinder[1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@yeprevenue[1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][5].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@discount-pet-superstore[2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\doris@elitepvpers[2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
       C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Cookies\Low\doris@imrworldwide[2].txt

    Trojan.DNS-Changer (Hi-Jacked DNS)
       HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{225C21AF-2FD1-4017-97F3-FFB266B81B98}#NAMESERVER
       HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{225C21AF-2FD1-4017-97F3-FFB266B81B98}#NAMESERVER
     


    Malware Bytes results:

    Malwarebytes' Anti-Malware 1.35
    Database version: 1945
    Windows 6.0.6001 Service Pack 1

    4/6/2009 6:02:47 PM
    mbam-log-2009-04-06 (18-02-46).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 225856
    Time elapsed: 1 hour(s), 59 minute(s), 39 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 4
    Folders Infected: 2
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.101,85.255.112.113 -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.101,85.255.112.113 -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.101,85.255.112.113 -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayMe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMe (Trojan.DNSChanger) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Users\Doris\AppData\Local\codecsetup8678.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMe\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.


    HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:11:12 PM, on 4/6/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Ideazon\ZEngine\Zboard.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - MRI_DISABLED - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\Windows\System32\TwcToolbarBho.dll
    O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\Windows\System32\TwcToolbarIe7.dll
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: []  (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: []  (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
    O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O15 - Trusted Zone: *.moove.com
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)
    O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\system32\atashost.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9661 bytes





    Ok... So how exactly do I remove this crap?  :-X
    « Last Edit: April 06, 2009, 04:12:29 PM by psychotic »

    psychotic

      Topic Starter


      Greenhorn

      Re: Another W32.silly.fdc, Logs posted
      « Reply #1 on: April 06, 2009, 04:13:21 PM »
      Ok, thats all 3 logs... What am I suppose to do now? They keep saying the removed them, but they keep showing up.  :-\

      psychotic

        Topic Starter


        Greenhorn

        Re: Another W32.silly.fdc, Logs posted
        « Reply #2 on: April 07, 2009, 08:05:18 AM »
        Ok, I also notice that where the worm was, it now keeps showing as 3 empty registry keys to my scanners (Advanced SystemCare) When I click repair, it says problems fixed, but I scan again right after, and they are still there...

        So is the worm gone, or are there more steps I need to take?

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Another W32.silly.fdc, Logs posted
        « Reply #3 on: April 07, 2009, 11:10:37 AM »
        Stop using Advanced SystemCare before your computer becomes damaged. These tools are dangerous especially when there is already a problem.

        Right click HijackThis and choose 'Run as Administrator'

        Open HijackThis and select Do a system scan only.

        Place a check mark next to the following entries: (if there)

        • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        • R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        • R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        • O2 - BHO: (no name) - MRI_DISABLED - (no file)
        • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        • O4 - HKUS\S-1-5-19\..\RunOnce: [] (User \'LOCAL SERVICE\')
        • O4 - HKUS\S-1-5-20\..\RunOnce: []  (User 'NETWORK SERVICE')
        • O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
        • O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
        • O20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)
        .
        Important: Close all open windows except for HijackThis and then click Fix checked.

        Once completed, exit HijackThis.

        ----------

        Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

        Link #1
        Link #2

        **Note:  It is important that it is saved directly to your Desktop

        Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
         
        Double click combofix.exe & follow the prompts.
        When finished ComboFix will produce a log for you.
        Post the ComboFix log in your next reply.

        Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

        If you have problems with ComboFix usage, see How to use ComboFix

        psychotic

          Topic Starter


          Greenhorn

          Re: Another W32.silly.fdc, Logs posted
          « Reply #4 on: April 07, 2009, 01:37:50 PM »
          Ok, here is my combofix log....  So is it safe to delete all these transparent folders? Or even log on important sites, I.E. my online bank account?  Sorry, most of my knowledge is in building computers, not removing worms, trojans, whatever have you...  :-X


          ComboFix 09-04-04.01 - Doris 2009-04-07 15:23:26.1 - NTFSx86
          Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3061.2023 [GMT -4:00]
          Running from: c:\users\Doris\Desktop\ComboFix.exe
          AV: Norton Internet Security *On-access scanning disabled* (Updated)
          FW: Norton Internet Security *enabled*
           * Created a new restore point
          .

          (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\windows\system32\AutoRun.inf
          c:\windows\system32\KBL.LOG
          c:\windows\system32\x64

          .
          (((((((((((((((((((((((((   Files Created from 2009-03-07 to 2009-04-07  )))))))))))))))))))))))))))))))
          .

          2009-04-07 09:56 . 2009-04-07 09:56   118   --a------   c:\windows\System32\MRT.INI
          2009-04-06 23:44 . 2009-04-06 23:53   <DIR>   d--------   c:\users\Doris\AppData\Roaming\IObit
          2009-04-06 23:44 . 2009-04-07 10:00   <DIR>   d--------   c:\program files\IObit
          2009-04-06 23:43 . 2009-04-06 23:43   <DIR>   d--------   c:\program files\CCleaner
          2009-04-06 18:19 . 2009-04-06 18:18   410,984   --a------   c:\windows\System32\deploytk.dll
          2009-04-06 18:10 . 2009-04-06 18:10   <DIR>   d--------   c:\program files\Trend Micro
          2009-04-06 16:00 . 2009-04-06 16:00   <DIR>   d--------   c:\users\Doris\AppData\Roaming\Malwarebytes
          2009-04-06 16:00 . 2009-04-06 16:00   <DIR>   d--------   c:\users\All Users\Malwarebytes
          2009-04-06 16:00 . 2009-04-06 16:00   <DIR>   d--------   c:\programdata\Malwarebytes
          2009-04-06 16:00 . 2009-04-06 18:02   <DIR>   d--------   c:\program files\Malwarebytes' Anti-Malware
          2009-04-06 16:00 . 2009-03-26 16:49   38,496   --a------   c:\windows\System32\drivers\mbamswissarmy.sys
          2009-04-06 16:00 . 2009-03-26 16:49   15,504   --a------   c:\windows\System32\drivers\mbam.sys
          2009-04-06 14:44 . 2009-04-06 14:44   <DIR>   d--------   c:\users\Doris\AppData\Roaming\SUPERAntiSpyware.com
          2009-04-06 14:44 . 2009-04-06 14:44   <DIR>   d--------   c:\users\All Users\SUPERAntiSpyware.com
          2009-04-06 14:44 . 2009-04-06 14:44   <DIR>   d--------   c:\programdata\SUPERAntiSpyware.com
          2009-04-06 14:44 . 2009-04-06 14:44   <DIR>   d--------   c:\program files\SUPERAntiSpyware
          2009-04-05 09:52 . 2009-04-05 09:52   <DIR>   d--------   c:\users\Doris\AppData\Roaming\Darkfall
          2009-04-05 09:26 . 2008-07-12 08:18   3,851,784   --a------   c:\windows\System32\D3DX9_39.dll
          2009-04-05 09:26 . 2008-05-30 14:11   3,850,760   --a------   c:\windows\System32\D3DX9_38.dll
          2009-04-05 09:26 . 2008-03-05 15:56   3,786,760   --a------   c:\windows\System32\D3DX9_37.dll
          2009-04-05 09:26 . 2007-10-12 15:14   3,734,536   --a------   c:\windows\System32\d3dx9_36.dll
          2009-04-05 09:26 . 2007-07-19 18:14   3,727,720   --a------   c:\windows\System32\d3dx9_35.dll
          2009-04-05 09:26 . 2007-05-16 16:45   3,497,832   --a------   c:\windows\System32\d3dx9_34.dll
          2009-04-05 09:26 . 2007-03-12 16:42   3,495,784   --a------   c:\windows\System32\d3dx9_33.dll
          2009-04-05 09:26 . 2006-11-29 13:06   3,426,072   --a------   c:\windows\System32\d3dx9_32.dll
          2009-04-05 09:26 . 2006-09-28 16:05   2,414,360   --a------   c:\windows\System32\d3dx9_31.dll
          2009-04-05 09:25 . 2009-04-05 09:51   <DIR>   d--------   c:\program files\Darkfall
          2009-03-30 14:46 . 2008-10-31 13:25   53,248   --a------   c:\windows\nswatchdog.exe
          2009-03-26 21:01 . 2009-03-26 21:01   <DIR>   d--------   c:\program files\The Weather Channel Toolbar
          2009-03-26 21:01 . 2008-07-22 13:31   327,680   --a------   c:\windows\System32\TwcToolbarIe7.dll
          2009-03-26 21:01 . 2008-07-22 13:24   98,304   --a------   c:\windows\System32\TwcToolbarBho.dll
          2009-03-26 21:01 . 2007-12-03 12:36   25,600   --a------   c:\windows\System32\TwcToolInstDll.dll
          2009-03-26 21:00 . 2009-03-26 21:00   <DIR>   d--------   c:\program files\The Weather Channel FW
          2009-03-26 18:27 . 2009-03-26 18:27   <DIR>   d--------   c:\users\Doris\AppData\Roaming\AVS4YOU
          2009-03-26 18:27 . 2009-03-26 18:27   <DIR>   d--------   c:\users\All Users\AVS4YOU
          2009-03-26 18:27 . 2009-03-26 18:27   <DIR>   d--------   c:\programdata\AVS4YOU
          2009-03-26 18:25 . 2009-04-05 18:39   <DIR>   d--------   c:\program files\Common Files\AVSMedia
          2009-03-26 18:25 . 2009-04-05 18:39   <DIR>   d--------   c:\program files\AVS4YOU
          2009-03-26 18:25 . 2002-01-05 14:40   487,424   --a------   c:\windows\System32\msvcp70.dll
          2009-03-26 18:25 . 2003-05-21 12:50   24,576   --a------   c:\windows\System32\msxml3a.dll
          2009-03-23 14:45 . 2009-04-07 09:48   <DIR>   d--------   c:\users\Doris\Tracing
          2009-03-23 14:44 . 2009-03-23 14:44   <DIR>   d--------   c:\program files\Windows Live SkyDrive
          2009-03-23 14:44 . 2009-03-23 14:44   <DIR>   d--------   c:\program files\Microsoft
          2009-03-23 14:41 . 2009-03-23 14:41   <DIR>   d--------   c:\program files\Common Files\Windows Live
          2009-03-14 16:35 . 2009-03-14 16:36   <DIR>   d--------   c:\program files\EndItAll
          2009-03-14 04:19 . 2009-03-14 04:19   <DIR>   d--------   c:\program files\Movie Maker 2.6
          2009-03-14 03:35 . 2009-03-14 03:40   <DIR>   d--------   c:\users\Doris\AppData\Roaming\vlc
          2009-03-14 03:35 . 2009-03-14 03:35   <DIR>   d--------   c:\program files\VideoLAN
          2009-03-14 03:27 . 2009-03-14 16:25   <DIR>   d--------   c:\program files\Winamp
          2009-03-14 02:22 . 2009-03-14 02:22   <DIR>   d--------   c:\users\Doris\AppData\Roaming\Xilisoft Corporation
          2009-03-14 02:20 . 2009-03-14 02:20   <DIR>   d--------   c:\program files\Xilisoft
          2009-03-14 02:10 . 2009-03-14 16:25   <DIR>   d--------   c:\program files\WM Converter
          2009-03-14 01:58 . 2009-03-14 03:27   <DIR>   d--------   c:\program files\Common Files\PX Storage Engine
          2009-03-14 01:57 . 2009-03-27 09:27   <DIR>   d--------   c:\program files\DivX
          2009-03-14 01:37 . 2009-03-15 01:32   <DIR>   d-a------   c:\users\All Users\TEMP
          2009-03-14 01:37 . 2009-03-15 01:32   <DIR>   d-a------   c:\programdata\TEMP
          2009-03-14 01:37 . 2009-03-15 01:32   <DIR>   d--------   C:\Fraps
          2009-03-11 03:43 . 2002-01-05 13:48   974,848   ---------   c:\windows\System32\mfc70.dll
          2009-03-11 03:43 . 2002-01-05 12:37   344,064   ---------   c:\windows\System32\msvcr70.dll
          2009-03-11 03:43 . 2003-07-24 10:24   237,568   --a------   c:\windows\System32\demoover.exe
          2009-03-11 03:43 . 2004-05-29 17:52   91,072   ---------   c:\windows\System32\RoseCo2.dll
          2009-03-11 03:43 . 2004-05-29 17:53   82,896   ---------   c:\windows\System32\KickCom2.dll
          2009-03-11 03:42 . 2009-03-11 04:36   <DIR>   d--------   C:\moove
          2009-03-11 03:42 . 2001-10-12 15:44   3,310   ---------   c:\windows\System32\advanced.ico
          2009-03-11 03:42 . 1998-04-24 00:00   1,078   ---------   c:\windows\System32\rosewaste.ico
          2009-03-11 03:22 . 2009-03-14 16:28   <DIR>   d--------   c:\program files\Kaneva
          2009-03-10 13:17 . 2008-12-15 23:29   8,147,456   --a------   c:\windows\System32\wmploc.DLL
          2009-03-10 13:17 . 2008-12-16 01:31   7,680   --a------   c:\windows\System32\spwmp.dll
          2009-03-10 13:17 . 2008-12-16 01:31   4,096   --a------   c:\windows\System32\msdxm.ocx
          2009-03-10 13:17 . 2008-12-16 01:31   4,096   --a------   c:\windows\System32\dxmasf.dll
          2009-03-10 13:16 . 2009-02-08 23:10   2,033,152   --a------   c:\windows\System32\win32k.sys
          2009-03-10 13:16 . 2008-11-27 00:43   268,288   --a------   c:\windows\System32\schannel.dll

          .
          ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2009-04-07 16:58   ---------   d-----w   c:\programdata\Symantec
          2009-04-07 02:55   ---------   d--h--w   c:\program files\InstallShield Installation Information
          2009-04-07 02:40   ---------   d-----w   c:\program files\Microsoft Games
          2009-04-07 02:34   ---------   d-----w   c:\users\Doris\AppData\Roaming\uTorrent
          2009-04-06 22:18   ---------   d-----w   c:\program files\Java
          2009-04-06 18:43   ---------   d-----w   c:\program files\Common Files\Wise Installation Wizard
          2009-04-05 22:12   ---------   d-----w   c:\program files\Common Files\Symantec Shared
          2009-03-27 22:45   ---------   d-----w   c:\users\Doris\AppData\Roaming\HP
          2009-03-23 18:43   ---------   d-----w   c:\program files\Windows Live
          2009-03-14 20:30   ---------   d-----w   c:\program files\Yahoo!
          2009-03-14 20:22   ---------   d-----w   c:\program files\Warcraft III
          2009-03-11 21:19   ---------   d-----w   c:\program files\Maxis
          2009-03-11 07:44   ---------   d-----w   c:\program files\Windows Mail
          2009-03-04 10:29   ---------   d-----w   c:\programdata\Yahoo!
          2009-03-04 10:26   ---------   d-----w   c:\users\Doris\AppData\Roaming\Yahoo!
          2009-02-28 04:03   ---------   d-----w   c:\users\Doris\AppData\Roaming\Ideazon
          2009-02-28 04:01   ---------   d-----w   c:\program files\Ideazon
          2009-02-20 01:48   ---------   d-----w   c:\program files\7-Zip
          2009-02-19 17:31   96,560   ----a-w   c:\windows\system32\drivers\symfw.sys
          2009-02-19 17:31   9,844   ----a-w   c:\windows\system32\drivers\SymRedir.cat
          2009-02-19 17:31   41,008   ----a-w   c:\windows\system32\drivers\symndisv.sys
          2009-02-19 17:31   38,576   ----a-w   c:\windows\system32\drivers\symids.sys
          2009-02-19 17:31   24,112   ----a-w   c:\windows\system32\drivers\SymIMV.sys
          2009-02-19 17:31   22,320   ----a-w   c:\windows\system32\drivers\symredrv.sys
          2009-02-19 17:31   184,496   ----a-w   c:\windows\system32\drivers\symtdi.sys
          2009-02-19 17:31   13,616   ----a-w   c:\windows\system32\drivers\symdns.sys
          2009-02-19 17:31   1,611   ----a-w   c:\windows\system32\drivers\SymRedir.inf
          2009-02-10 20:56   ---------   d-----w   c:\users\Doris\AppData\Roaming\GetRightToGo
          2009-02-06 22:52   49,504   ----a-w   c:\windows\System32\sirenacm.dll
          2009-01-15 06:11   827,392   ----a-w   c:\windows\System32\wininet.dll
          2008-01-21 02:43   174   --sha-w   c:\program files\desktop.ini
          .

          (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* empty entries & legit default entries are not shown
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
          "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
          "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
          "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
          "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
          "DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 801904]
          "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
          "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-10-25 212992]
          "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-19 468264]
          "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-12-06 202032]
          "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
          "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
          "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
          "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
          "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
          "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
          "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
          "Zboard"="c:\program files\Ideazon\ZEngine\Zboard.exe" [2008-11-12 57344]
          "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-06 148888]
          "MRT"="c:\windows\system32\MRT.exe" [2009-02-25 24768960]

          c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
          HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableUIADesktopToggle"= 0 (0x0)

          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
          "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
          2008-12-22 12:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "msacm.l3codecp"= l3codecp.acm

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
          --a------ 2007-05-11 07:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
          --a------ 2007-10-03 19:15 480560 c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
          --a------ 2007-10-03 18:44 178712 c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
          "UacDisableNotify"=dword:00000001
          "InternetSettingsDisableNotify"=dword:00000001
          "AutoUpdateDisableNotify"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-256968735-640673003-351684455-1004]
          "EnableNotificationsRef"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
          "{0C53955B-DA7B-4D19-BA7F-C3CB861DD127}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
          "{FD04AC5D-80BB-4236-B929-5FE0F9062AA1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
          "{7B754820-430B-45BC-94F4-41B6E1FE1C31}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
          "{5DAE2496-F342-4EDC-AD0D-57C4F2FBD791}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
          "{5506AB42-C949-428E-9933-843D58434240}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
          "{70BBC0E6-A428-4B94-AED1-03C6FC39BEF7}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
          "{B1DD21E3-600D-4A50-BFC1-46449F6C36B9}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
          "{03510A4F-F70C-41A5-BCBC-ACE4311F5B29}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
          "{E8474A6C-2929-473E-BC70-2CAF59DF1323}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
          "{9D3EAB25-7FE2-4059-99AD-705B409E0582}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
          "{7AC37F4F-38B2-467D-9B36-5928C8AE0322}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
          "{0E2AE14D-5586-4934-BDB9-A8F70E2B55B8}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
          "{45FABCFD-6E9B-4EB4-93F1-895F353A67BC}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
          "{B440AFF3-8EE0-4D1A-9DFB-61E0B55D8BD5}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
          "{ED3E1680-003B-426D-9408-CDF644F7D019}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
          "{836450E8-5137-45BF-9A16-2CF8F78ACF9E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
          "{DD3C3DCF-01F9-44F9-BFD5-F880336DFBBC}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
          "{94B91045-FA70-47D5-BA2E-73CAAE9B3DBA}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
          "{879FFDE0-AD61-4957-9273-00A29424AC84}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
          "{8FC23F4B-A223-47CE-AAF6-80D1ECCA86E3}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
          "{388F61DD-611C-41AD-A683-ADA389F202DA}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
          "{B7058F4F-EF2A-4A66-AD3C-F12AF8F61AD7}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
          "{C6D9C9BC-4D8E-4BC4-A497-318C91E8718C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
          "{43037F55-683A-4730-953C-52E5C9AE903A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
          "{DFCD453A-013C-4E44-B814-DF8A13DBECF8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe
          "{11D47BC6-927C-446B-B95B-2F12BB5DCD83}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
          "{949E98F9-9D71-4F4D-B614-A612C3ED49CA}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
          "{FBE336B9-2DA9-4BAA-AF38-7B5367D4F205}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
          "{3E387DF5-D4AE-4BCC-8E41-79DC113F3C48}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
          "{29AB88E1-4A3C-4469-82EA-3BA6912D4DD7}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
          "{4AFE900C-BF8C-47C0-96F1-FDC0B170FAB6}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
          "{2B3A7DE9-42B4-486A-A869-D629014218F7}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
          "{7959871D-B519-44FD-A2A9-38B50744F7B8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe:hpqnrs08.exe
          "{C838A574-C47C-4072-BB8D-F0182151F6D2}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
          "{A90D1241-56BC-46CE-A8FE-855A3AB04C28}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
          "{B61A6346-323D-455F-9CE9-8488A575F881}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
          "{1E017D30-5307-4F81-B074-70CAFA94D7DC}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
          "{9F636F78-1F18-4E1E-B7B5-12219041BFE1}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
          "{65B23307-6F92-41CD-A629-AE686E1D5AEB}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
          "EnableFirewall"= 0 (0x0)
          "DoNotAllowExceptions"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
          "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

          R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090331.003\IDSvix86.sys [2009-04-02 272432]
          R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-03-23 9968]
          R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-03-23 72944]
          R2 atashost;WebEx Service Host for Support Center;c:\windows\System32\atashost.exe [2008-09-09 20376]
          R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2007-08-25 149352]
          R3 Alpham1;Ideazon ZBoard USB Human Interface Device;c:\windows\System32\drivers\Alpham1.sys [2007-07-23 42624]
          R3 Alpham2;Ideazon ZBoard MM USB Human Interface Device;c:\windows\System32\drivers\Alpham2.sys [2007-03-20 18432]
          R3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2007-05-29 23888]
          R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-01 101936]
          R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
          R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2009-02-19 41008]

          --- Other Services/Drivers In Memory ---

          *NewlyCreated* - COMHOST

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
          hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc

          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
          "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
          .
          Contents of the 'Scheduled Tasks' folder

          2009-04-07 c:\windows\Tasks\AWC Startup.job
          - c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-02-22 14:45]

          2009-04-07 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Doris.job
          - c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 20:19]

          2009-04-07 c:\windows\Tasks\SmartDefrag.job
          - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-02-13 18:15]

          2009-04-07 c:\windows\Tasks\SmartDefrag.job
          - c:\program files\IObit\IObit SmartDefrag\ [2009-04-06 23:44]
          .
          .
          ------- Supplementary Scan -------
          .
          uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
          mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
          IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
          Trusted Zone: moove.com
          FF - ProfilePath - c:\users\Doris\AppData\Roaming\Mozilla\Firefox\Profiles\ea13htpd.default\
          FF - prefs.js: browser.startup.homepage - hxxp://www.perfectworld.com
          FF - plugin: c:\program files\Mozilla Firefox\plugins\npkanevapatch.dll
          FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
          .

          **************************************************************************

          catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-04-07 15:27:33
          Windows 6.0.6001 Service Pack 1 NTFS

          scanning hidden processes ... 

          scanning hidden autostart entries ...

          scanning hidden files ... 

          scan completed successfully
          hidden files: 0

          **************************************************************************
          .
          Completion time: 2009-04-07 15:31:00
          ComboFix-quarantined-files.txt  2009-04-07 19:30:54

          Pre-Run: 106,823,573,504 bytes free
          Post-Run: 106,879,004,672 bytes free

          285   --- E O F ---   2009-04-07 13:56:33

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Another W32.silly.fdc, Logs posted
          « Reply #5 on: April 07, 2009, 01:50:14 PM »
            So is it safe to delete all these transparent folders? Or even log on important sites, I.E. my online bank account?  Sorry, most of my knowledge is in building computers, not removing worms, trojans, whatever have you

            Let me know how everything is after this next step.

            • Click START then RUN
            • Now type Combofix /u in the runbox
            • Make sure there's a space between Combofix and /u
            • Then hit Enter.
            • The above procedure will:
            • Delete the following:
            • ComboFix and its associated files and folders.
            • Reset the clock settings.
            • Hide file extensions, if required.
            • Hide System/Hidden files, if required.
            • Set a new, clean Restore Point.
            .
            ----------

            Are the icons still there and if so which ones?



            psychotic

              Topic Starter


              Greenhorn

              Re: Another W32.silly.fdc, Logs posted
              « Reply #6 on: April 07, 2009, 02:12:01 PM »
              They are all still there  :-\    (The notpad file you see, is just the instructions I was to print.)


              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Another W32.silly.fdc, Logs posted
              « Reply #7 on: April 07, 2009, 02:20:47 PM »
              • Close all programs so that you are at your desktop.
              • Open the Control Panel menu and click Folder Options.
              • After the new window appears select the View tab.
              • Make sure there is NO checkmark in the checkbox labeled Display the contents of system folders.
              • Under the Hidden files and folders section select the radio button labeled Do not show hidden files and folders.
              • Place a checkmark in the checkbox labeled Hide file extensions for known file types.
              • Place a checkmark from the checkbox labeled Hide protected operating system files.
              • Press the Apply button and then the OK button and exit My Computer.
              • Now your computer is configured to hide all hidden files and folders which is the default and should always be this way unless needed for maintenance or removing malware.
              .
              ----------

              Now delete any hidden (transparent) files/folders left on the desktop.

              Download CCleaner Slim and save it to your Desktop.
              When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
              Follow the prompts to install the program.
              Complete the installation then:

              • Double-click the CCleaner shortcut on the desktop to start the program.
              • Click on the Options block on the left, then choose Cookies.
                • Under Cookies to Delete, highlight any cookies you would like to retain permanently
                • Click the right arrow > to move them to the Cookies to Keep window.
                .
              • Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours
              • Click Cleaner on the left then Run Cleaner on the right to run the program.
              • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner
              • Caution: It is not recommended that you use the 'Registry' feature unless you are very familiar with the registry.
              • Exit CCleaner after it has completed its process.
              .
              Note CCleaner is a 100% free tool. I suggest keeping it and running it regularly to keep your computer running smooth.

              ----------

              We have not done a full virus scan yet so we should do so now.

              Use the Kaspersky Lab Online Scanner

              In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

              • Click on SCAN NOW
              • Click Accept.
              • The program will then begin downloading the latest definition files.
              • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
              • The scan will take a while, so be patient and let it finish.
              When the scan is done, in the Scan is complete window, any infection is displayed.
              There is no option to clean/disinfect, however, we need to analyze the information on the report.

              To obtain the report:
              Click on: Save Report As
              • Next, in the Save as prompt, Save in area, select: Desktop.
              • In the File name area use KScan, or something similar.
              • In Save as type: click the drop arrow and select: Text file [*.txt]
              • Then, click: Save


              Copy and paste the Kaspersky Online Scanner Report in your next reply.

              Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

              If needed, this animation will guide you through the process.

              psychotic

                Topic Starter


                Greenhorn

                Re: Another W32.silly.fdc, Logs posted
                « Reply #8 on: April 07, 2009, 03:45:09 PM »
                The Hidden files, are fully hidden now, didn't have to delete any of them, started the scan an hour ago, its at 18%, will post it as soon as its done.

                Thanks for your help thus far, by the way.

                psychotic

                  Topic Starter


                  Greenhorn

                  Re: Another W32.silly.fdc, Logs posted
                  « Reply #9 on: April 07, 2009, 07:12:05 PM »
                  Uhhh.... heres the log..., lol, 0 problems... So am I clean?   ;D

                  No malware has been detected. The scan area is clean.
                  « Last Edit: April 07, 2009, 07:43:18 PM by evilfantasy »

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Another W32.silly.fdc, Logs posted
                  « Reply #10 on: April 07, 2009, 07:44:17 PM »
                  Looks good.

                  Final steps.

                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .
                  ----------

                  Go to Microsoft Windows Update and get all critical updates.

                  ----------

                  I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                  * Using SpywareBlaster to protect your computer from Spyware and Malware
                  * If you don't know what ActiveX controls are, see here

                  Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

                  psychotic

                    Topic Starter


                    Greenhorn

                    Re: Another W32.silly.fdc, Logs posted
                    « Reply #11 on: April 07, 2009, 09:56:59 PM »
                    Ok, thanks again, glad I found a place that won't charge me an arm and a leg for this :P


                    Take care

                    evilfantasy

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Calm like a bomb
                    • Thanked: 493
                    • Experience: Experienced
                    • OS: Windows 11
                    Re: Another W32.silly.fdc, Logs posted
                    « Reply #12 on: April 07, 2009, 10:38:56 PM »
                    Your welcome.

                    Safe surfing... (|