Microsoft
Software
Hardware
Network
Question : Fake bing icon, browser hijacker virus thing
A colleague of mine tells me there is a pro hijackthis log decipherer on here. I've already tried malwarebytes, and the Microsoft offerings, and our office runs Vipre Enterprise. All came up with nada. All searches and links in IE are redirected to other full page ads. Sometimes for ADT, sometimes for doctors or some such thing. I will be running: Kaspersky, Eset, Bitdefender, F-secure, Panda, AdAware, S&D, etc throughout the day. But if someone here can decipher the hijackthis log better than I can, that would be awesome! Thanks! -Angela
Windows 7 Pro 32bit.
Logfile of HijackThis v1.99.1
Scan saved at 5:47:17 PM, on 6/22/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Running processes:
C:\Windows\system32\taskho
st.exe
C:\Windows\system32\rdpcli
p.exe
C:\Windows\system32\Dwm.ex
e
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Sunbelt Software\SBEAgent\SBAMTray
.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
C:\Program Files\DellTPad\ApMsgFwd.ex
e
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhos
t.exe
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe
C:\Windows\system32\wuaucl
t.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\system32\mmc.ex
e
C:\Windows\system32\Search
FilterHost
.exe
X:\Malware apps\HijackThis\HijackThis
.exe
X:\Malware apps\malwarebytes-mbam-set
up-1.46.ex
e
C:\Users\angela\AppData\Lo
cal\Temp\i
s-DRNQB.tm
p\malwareb
ytes-mbam-
setup-1.46
.tmp
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://g.msn.com/USREL/1
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fw
link/?Link
Id=54896
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://g.msn.com/USREL/1
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fw
link/?Link
Id=69157
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fw
link/?Link
Id=54896
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fw
link/?Link
Id=54896
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fw
link/?Link
Id=69157
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = 192.168.0.253:8080
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = 192.168.1.0;192.168.0.0;pr
emium.doma
inname.com
;claims.do
mainname.c
om;web-rep
orts.com;1
92.168.0.4
;192.168.0
.254;web-m
onitor.com
;domainnam
e.com;doma
inname-rep
orts.com;d
omainname-
reports.co
m;localhos
t;domainna
meadmin.co
m;<local>
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-F
CE54AD9C20
8} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-9
0988571CEC
B} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B
9E3AAC4465
B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.d
ll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
164760863C
6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
445EE16191
0} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-D
C94EC1ACF1
0} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8
A89D322906
8} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D
2AAB95CABE
3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.
exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files\Sunbelt Software\SBEAgent\SBAMTray
.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Snagit 9.lnk = C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECapture.
html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppend.h
tml
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECaptureS
elLinks.ht
ml
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppendSe
lLinks.htm
l
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECapture.
html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppend.h
tml
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECapture.
html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppend.h
tml
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.h
tm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D
9FCDDC9D60
0} - C:\Program Files\Windows Live\Writer\WriterBrowserE
xtension.d
ll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D
9FCDDC9D60
0} - C:\Program Files\Windows Live\Writer\WriterBrowserE
xtension.d
ll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MIF5BA~1\Offic
e12\REFIEB
AR.DLL
O9 - Extra button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5
C8D4460577
F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5
C8D4460577
F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi
.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napins
p.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [INTERNATIONAL] International
O13 - Gopher Prefix:
O15 - Trusted Zone: *.ameritrade.com
O15 - Trusted Zone: *.cyberhotline.com
O15 - Trusted Zone: *.ameritrade.com (HKLM)
O15 - Trusted Zone: *.cyberhotline.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsth
elper.dll
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D
6057B9A918
F} (JuniperSetupClientControl
Class) -
https://ssl.domainname.com
/dana-cach
ed/sc/
Juni
perSetupCl
ient.cab
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = domainname
O17 - HKLM\Software\..\Telephony
: DomainName = domainname
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = domainname
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = domainname
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\WIC4A1~1\MESSE
N~1\MSGRAP
~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
0C04F8EC29
4} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\WIC4A1~1\MESSE
N~1\MSGRAP
~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-1
0D7BE1653C
0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-0
0B0D022E94
5} - C:\PROGRA~1\COMMON~1\MICRO
S~1\OFFICE
12\MSOXMLM
F.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxde
v.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.
exe
O23 - Service: CLMonitor - Unknown owner - c:\Program Files\Dell\Latitude ON Reader\CLMonitorService.ex
e
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostCont
rolService
.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStor
ageService
.exe
O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: SQL Server (CRM) (MSSQL$CRM) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\
sqlservr.e
xe" -sCRM (file missing)
O23 - Service: @%SystemRoot%\system32\qwa
ve.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: VIPRE Enterprise Agent (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\SBEAgent\SBAMSvc.
exe
O23 - Service: SB Recovery Service (SBPIMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\SBEAgent\SBPIMSvc
.exe
O23 - Service: @%SystemRoot%\system32\sec
logon.dll,
-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: Smith Micro Connection Manager Service (SMManager) - Smith Micro Software, Inc. - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\Driver
Store\File
Repository
\stwrt.inf
_x86_neutr
al_450b431
403c091e3\
STacSV.exe
O23 - Service: NTRU TSS v1.2.1.29 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe (file missing)
Answer : Fake bing icon, browser hijacker virus thing
Hi
Run Tdsskiller(right click and runas admin) and post its logfile from c:\tdsskiller.log
http://support.kaspersky.c
om/viruses
/solutions
?qid=20828
0684
Random Solutions
V-lookup
Word 2010 - Changing external linked images into embedded images
Cisco VLAN
differences between windows server 2003 and windows server 2003 r2
How do I write a batch that will open an Explorer window to a particular folder?
mssql: I would like to have this where clause modified to search for all records or if beginDate & endDate specfified then search between dates
Move a VM
Best method for automated use of Defrag, chkdsk, Disk cleanup, etc.
Dropdown with links
SQL 2005 Query Help - Incorrect syntax near ';'.