Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.fbdownloader.com/?channel=sfuk205
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://search.fbdownloader.com/search.php?channel=sfuk205&q={searchTerms}
FF - prefs.js..browser.search.defaulturl: "http://search.fbdownloader.com/search.php?channel=sfuk205&q="
FF - prefs.js..browser.startup.homepage: "http://search.fbdownloader.com/?channel=sfuk205"
FF - prefs.js..keyword.URL: "http://search.fbdownloader.com/search.php?channel=sfuk205&q=
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
:Files
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[RESETHOSTS]
start
HKU\Dan\...\Run: [SCheck] "C:\Users\Dan\AppData\Roaming\SCheck\SCheck.exe" check [41984 2012-12-19] ()
HKU\Dan\...\Run: [SSync] "C:\Users\Dan\AppData\Roaming\SSync\SSync.exe" [41984 2012-12-19] ()
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] C:\$Recycle.Bin\S-1-5-18\$efd8300e57d98426a0bc288ca2382ba0\n. ATTENTION! ====> ZeroAccess
C:\$Recycle.Bin\S-1-5-18\$efd8300e57d98426a0bc288ca2382ba0\n
2013-02-16 10:59 - 2013-02-16 10:59 - 00000000 ____D C:\Users\Dan\Application Data\SCheck
2013-02-16 10:59 - 2013-02-16 10:59 - 00000000 ____D C:\Users\Dan\Application Data\Common
2013-02-16 10:59 - 2013-02-16 10:59 - 00000000 ____D C:\Users\Dan\AppData\Roaming\SCheck
2013-02-16 10:59 - 2013-02-16 10:59 - 00000000 ____D C:\Users\Dan\AppData\Roaming\Common
2013-02-16 11:00 - 2013-02-16 11:00 - 00000000 ____D C:\Users\Dan\Application Data\SSync
2013-02-16 11:00 - 2013-02-16 11:00 - 00000000 ____D C:\Users\Dan\AppData\Roaming\SSync
Folder: C:\Users\Dan\Desktop\76561198005397767
end
Fiery said:That is ok, did OTL provide a log once you rebooted? If so, attach that log as well.
Now, please do a new FRST scan so I can make sure the infection is gone.
All processes killed
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Prefs.js: "http://search.fbdownloader.com/search.php?channel=sfuk205&q=" removed from browser.search.defaulturl
Prefs.js: "http://search.fbdownloader.com/?channel=sfuk205" removed from browser.startup.homepage
Prefs.js: "http://search.fbdownloader.com/search.php?channel=sfuk205&q= removed from keyword.URL
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Dan\Downloads\cmd.bat deleted successfully.
C:\Users\Dan\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
User: All Users
User: Dan
->Temp folder emptied: 75591326 bytes
->Temporary Internet Files folder emptied: 76171138 bytes
->Java cache emptied: 479638 bytes
->FireFox cache emptied: 2578201 bytes
->Google Chrome cache emptied: 41490927 bytes
->Flash cache emptied: 938 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
User: Guest
User: HomeGroupUser$
User: matt
->Temp folder emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 78028 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46433401 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 232.00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.69.0 log created on 02192013_175335
Files\Folders moved on Reboot...
C:\Users\Dan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Dan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QVCBI0QR\index[1].htm moved successfully.
File\Folder C:\Windows\temp\hsperfdata_DAN-PC$\2060 not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Fiery said:Just the FRST scan will be fine![]()
Fiery said:Has that been happening before the last FRST fix or after?
Abuelo said:Yes that is a folder known to me, I can see why it would look suspicious!
sh=553B685F5F02CA37A3C61FA96E8E7AE77AE24F69 ft=1 fh=a1e7991b07f47d08 vn="a variant of Win32/SoftonicDownloader.E application" ac=I fn="C:\Users\Dan\Downloads\SoftonicDownloader_for_surgeon-simulator-2013.exe"
Members who viewed this thread in the last 5 minutes