I ran Spybot yesterday and it reported Widgi as a problem. When I clicked fix it removed some other problems but reported that it couldn't remove one entry but would do so on restart.
I resatrted and it started Spybot (no other tasks were running or started) and Spybot repoerted a couple of other errors (why? It didn't report them before) but Widgi was still there. I restarted again and Spybot reported Widgi is still a problem.
How can I get rid of it.
I'm running XP SP3 with the Chrome browser.
Last edited by tashi; 2012-06-17 at 03:05.
Reason: Moved from the malware forum
Could you post the fixes logfile here,please?
Go into Spybot > Mode > Advanced mode > Tools > View Reports > View Previous reports.Look for the Fixes.yymmdd-hhmm file with the date from when you ran your scan,and doubleclick it.It will open up in the Spybot window,rightclick somewhere in that window and select Select All,then rightclick again and select Copy,then paste it here.
Widgi.Toolbar: [SBI $D4C0BB69] System Service (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Application Updater
Common Dialogs: History (2 files) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
MS Office 9.0: Recently used files (32 files) (Directory, nothing done)
C:\Documents and Settings\Douglas Howell\Application Data\Microsoft\Office\Recent\
MS Management Console: [SBI $ECD50EAD] Recent command list (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Microsoft Management Console\Recent File List
MS Direct3D: [SBI $C2A44980] Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Direct3D\MostRecentApplication\Name
MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name
MS Office 9.0: [SBI $BCA8814E] Internet history (Registry value, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Office\9.0\Common\Internet\UseRWHlinkNavigation
MS Office 9.0 (Word): [SBI $EC31BB71] Recently used file list (Registry value, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Office\9.0\Word\Data\Settings
MS Office 9.0 (PowerPoint): [SBI $43C6507A] Recent file list (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Office\9.0\PowerPoint\Recent File List
MS Search Assistant: [SBI $AE0C4647] Typed search terms history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Search Assistant\ACMru
Windows.OpenWith: [SBI $F3568C7E] Open with list - .123 extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.123\OpenWithList
Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList
Windows.OpenWith: [SBI $9E8D5C8A] Open with list - .CDA extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\OpenWithList
Windows.OpenWith: [SBI $ECC28BDF] Open with list - .CSV extension (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CSV\OpenWithList
Windows Explorer: [SBI $AA0766B5] Stream history (27 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: [SBI $2026AFB6] User Assistant history IE (5 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Explorer: [SBI $6107D172] User Assistant history files (91 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: [SBI $B7EBA926] Last visited history (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry change, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows Media\WMSDK\General\ComputerName
Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows Media\WMSDK\General\UniqueID
Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry value, nothing done)
HKEY_USERS\S-1-5-21-2946278530-654351994-41216124-1006\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Try going to Start on your computer,then Run.Type in services.msc,Services should open.Scroll through,and if there is a service named Application Updater(it also might have the description 'Automatically downloads and installs application updates'),then click on it and press Stop.If that's successful,try running Spybot and see if it is able to remove it now.
The rest of the items in your logfile all look to be usage tracks,and should have shown as the colour green when the scan was done: http://www.safer-networking.org/en/d...agetracks.html
They're of no harm,so you can just ignore them if you wish.
Application updater is showing 'Start the service'
However I tried to click 'start' so that I could 'stop' it but it gave an error saying 'Cannot find the path specified'
There is also a another service 'Automatic Updates' which is for Windows updates. But I assume that is not the one.
Did you have MyBrowserBar or Dealio toolbar installed before,or currently installed?If it's currently installed,you might be able to uninstall it from add/remove programs or from your browser.
From what I can find,it may have been bundled with another product,if you don't remember installing it.
It may also be named something else,I think...Youtube downloader toolbar,perhaps,or a couple of others.
Perhaps the service was left from a past install then.To check for sure,you could ask for help in malware removal.Should be able to remove it in there.