Hi
this started a week ago and what happend was i had a hijack called searchathand.com. I got rid of it this when i put in a result for google it didn't run the link it suppose to be. Instead it came up with weird links like 67.29.139.199 and Oldhetaira.com. Its weird cause some times when i do it, it works just fine and most of the time it doesn't.
Got results from Ewido
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:28:04 02/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
C:\Program Files\DivX\Google\Firefox\ffinstaller.exe -> Adware.MediaTicket : Ignored.
C:\###OLD FILES###\BACKUP\David\Local Settings\Temp\Okmt.exe -> Adware.Midadle : Ignored.
C:\###OLD FILES###\BACKUP\David\Local Settings\Temp\DQ6VFn5.exe -> Adware.WinFetcher : Ignored.
C:\###OLD FILES###\BACKUP\David\Local Settings\Temp\cpr_mm2.exe -> Downloader.Adroar : Cleaned with backup (quarantined).
[1416] VM_00870000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1468] VM_00920000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1484] VM_00380000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1580] VM_008F0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1684] VM_00890000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1820] VM_00880000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1956] VM_008A0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[204] VM_007B0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2188] VM_00E60000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2236] VM_009C0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2352] VM_00850000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2464] VM_00840000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2576] VM_008A0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2740] VM_00880000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2752] VM_00350000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2784] VM_00D90000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2868] VM_00D90000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[436] VM_003E0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[452] VM_00350000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[464] VM_00950000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[484] VM_008A0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[556] VM_008B0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[572] VM_00D60000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[596] VM_00C10000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[756] VM_00980000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\Program Files\US Nero 6 Ultra Edition 6.6.0.16 crack.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined).
C:\Program Files\ahead\Nero\crack.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Ignored.
C:\WINDOWS\Downloaded Program Files\gsda.dll -> Not-A-Virus.Downloader.Win32.SpyGame : Ignored.
C:\Program Files\Private Moon Studios\AGON\Data\Bin\ijl15.dll -> Not-A-Virus.Monitor.Win32.HiddenRecorder.a : Ignored.
::Report end
Silent runners
"Silent Runners.vbs", revision 48, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ares" = ""C:\Program Files\Ares\Ares.exe" -h" [file not found]
"Steam" = (empty string)
"LDM" = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" ["Logitech"]
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."]
"BitTorrent" = ""C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized" [file not found]
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" ["Google Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ATICCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime" [null data]
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"" ["Hewlett-Packard Company"]
"HPDJ Taskbar Utility" = "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe" ["HP"]
"InCD" = "C:\Program Files\ahead\InCD\InCD.exe" ["Copyright (C) ahead software gmbh and its licensors"]
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."]
"HP Software Update" = "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
"DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"LVCOMSX" = "C:\WINDOWS\System32\LVCOMSX.EXE" ["Logitech Inc."]
"LogitechVideoRepair" = "C:\Program Files\Logitech\Video\ISStart.exe " ["Logitech Inc."]
"LogitechVideoTray" = "C:\Program Files\Logitech\Video\LogiTray.exe" ["Logitech Inc."]
"Adobe Photo Downloader" = ""C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"" ["Adobe Systems Incorporated"]
"ISUSPM Startup" = "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup" ["InstallShield Software Corporation"]
"ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["InstallShield Software Corporation"]
"BHR" = "C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe" [file not found]
"!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["Anti-Malware Development a.s."]
"dmqhr.exe" = "C:\WINDOWS\System32\dmqhr.exe" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
this started a week ago and what happend was i had a hijack called searchathand.com. I got rid of it this when i put in a result for google it didn't run the link it suppose to be. Instead it came up with weird links like 67.29.139.199 and Oldhetaira.com. Its weird cause some times when i do it, it works just fine and most of the time it doesn't.
Got results from Ewido
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:28:04 02/10/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
C:\Program Files\DivX\Google\Firefox\ffinstaller.exe -> Adware.MediaTicket : Ignored.
C:\###OLD FILES###\BACKUP\David\Local Settings\Temp\Okmt.exe -> Adware.Midadle : Ignored.
C:\###OLD FILES###\BACKUP\David\Local Settings\Temp\DQ6VFn5.exe -> Adware.WinFetcher : Ignored.
C:\###OLD FILES###\BACKUP\David\Local Settings\Temp\cpr_mm2.exe -> Downloader.Adroar : Cleaned with backup (quarantined).
[1416] VM_00870000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1468] VM_00920000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1484] VM_00380000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1580] VM_008F0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1684] VM_00890000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1820] VM_00880000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1956] VM_008A0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[204] VM_007B0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2188] VM_00E60000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2236] VM_009C0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2352] VM_00850000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2464] VM_00840000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2576] VM_008A0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2740] VM_00880000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2752] VM_00350000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2784] VM_00D90000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[2868] VM_00D90000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[436] VM_003E0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[452] VM_00350000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[464] VM_00950000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[484] VM_008A0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[556] VM_008B0000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[572] VM_00D60000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[596] VM_00C10000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[756] VM_00980000 -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\Program Files\US Nero 6 Ultra Edition 6.6.0.16 crack.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined).
C:\Program Files\ahead\Nero\crack.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Ignored.
C:\WINDOWS\Downloaded Program Files\gsda.dll -> Not-A-Virus.Downloader.Win32.SpyGame : Ignored.
C:\Program Files\Private Moon Studios\AGON\Data\Bin\ijl15.dll -> Not-A-Virus.Monitor.Win32.HiddenRecorder.a : Ignored.
::Report end
Silent runners
"Silent Runners.vbs", revision 48, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ares" = ""C:\Program Files\Ares\Ares.exe" -h" [file not found]
"Steam" = (empty string)
"LDM" = "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" ["Logitech"]
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."]
"BitTorrent" = ""C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized" [file not found]
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" ["Google Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ATICCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime" [null data]
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"" ["Hewlett-Packard Company"]
"HPDJ Taskbar Utility" = "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe" ["HP"]
"InCD" = "C:\Program Files\ahead\InCD\InCD.exe" ["Copyright (C) ahead software gmbh and its licensors"]
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."]
"HP Software Update" = "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
"DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"LVCOMSX" = "C:\WINDOWS\System32\LVCOMSX.EXE" ["Logitech Inc."]
"LogitechVideoRepair" = "C:\Program Files\Logitech\Video\ISStart.exe " ["Logitech Inc."]
"LogitechVideoTray" = "C:\Program Files\Logitech\Video\LogiTray.exe" ["Logitech Inc."]
"Adobe Photo Downloader" = ""C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"" ["Adobe Systems Incorporated"]
"ISUSPM Startup" = "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup" ["InstallShield Software Corporation"]
"ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["InstallShield Software Corporation"]
"BHR" = "C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe" [file not found]
"!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["Anti-Malware Development a.s."]
"dmqhr.exe" = "C:\WINDOWS\System32\dmqhr.exe" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]