Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with MY START SEARCH and innoapp malware


  • This topic is locked This topic is locked
1 reply to this topic

#1 jkmarx1982

jkmarx1982

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:38 PM

Posted 08 December 2014 - 12:47 PM

Dear all!!!

I have been facing this issue for close to two weeks. Tried some of the steps that was available online. Part of it was rectified. But my browser is bogged down by the pop ups possibly due to this annoying MY START SEARCH malware.

I am an amateur musician who used to try new VSTi uploaded in some websites. Yes I must admit, I cannot spend much. So I look out for cracked music softwares. When I tried to download a VSTi from a file sharing website, I accidentally downloaded something and my browser was automatically changed to MY START SEARCH homepage.

I tried several things. Scanned with Malwarebytes and Spybot..Nothing helped. Finally I read somewhere that ADWcleaner is effective. I tried it and my browser was back to normal. My homepages were no more hijacked or redirected.

But off late, whenever i try to visit some websites, i get the annoying popups (3 popups) in the bottom of the browser window and they keep on coming. These pop ups are so similar of the one that i experienced when my system was affected with MY START SEARCH malware.

Now i observed that my system is also infected with innoapp malware. I am helpless. Please help me.. Thanks for any help...

 

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.17126
Run by KARL MARX at 23:06:47 on 2014-12-08
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.3061.1357 [GMT 5.5:30]
.
AV: Panda Free Antivirus *Enabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
AV: Spybot - Search and Destroy *Disabled/Outdated* {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D}
SP: Panda Free Antivirus *Enabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Panda Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\Panda Security\Panda Security Protection\PSANHost.exe
C:\Program Files\Panda Security\Panda Devices Agent\AgentSvc.exe
C:\Program Files\Panda Security\Panda Security Protection\PSUAService.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Panda Security\Panda Security Protection\PSUAMain.exe
C:\Users\KARL MARX\AppData\Roaming\DRPSu\DrvUpdater.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\File Association Helper\FAHWindow.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\WandouLabs\wandoujia_helper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\wbem\WmiPrvSE.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
mSearch Page = hxxp://www.google.com
mDefault_Page_URL = www.google.com
mDefault_Search_URL = www.google.com
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - c:\program files\free download manager\iefdm2.dll
uRun: [DrvUpdater] c:\users\karl marx\appdata\roaming\drpsu\DrvUpdater.exe /hide
uRun: [Free Download Manager] c:\program files\free download manager\fdm.exe -autorun
uRun: [Adobe Reader Synchronizer] "c:\program files\adobe\reader 10.0\reader\AdobeCollabSync.exe"
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDVCPL] "c:\program files\realtek\audio\hda\RtHDVCpl.exe" -s
mRun: [PSUAMain] "c:\program files\panda security\panda security protection\PSUAMain.exe" /LaunchSysTray
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRun: [FAHConsole] c:\program files\file association helper\FAHConsole.exe
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: c:\users\karlma~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\users\karlma~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\karlma~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\wandou~1.lnk - c:\program files\wandoulabs\wandoujia_helper.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: MaxGPOScriptWait = dword:600
IE: Download all with Free Download Manager - c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
   If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
TCP: NameServer = 202.53.8.18 123.176.37.35
TCP: Interfaces\{6125319C-C6DC-49B9-9134-9ABECD302485} : DHCPNameServer = 202.53.8.18 123.176.37.35
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\karl marx\appdata\roaming\mozilla\firefox\profiles\1dpcoqlx.default\
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_15_0_0_239.dll
.
============= SERVICES / DRIVERS ===============
.
R1 NNSALPC;NNSALPC;c:\windows\system32\drivers\NNSAlpc.sys [2014-6-4 88992]
R1 NNSHTTP;NNSHTTP;c:\windows\system32\drivers\NNSHttp.sys [2014-6-18 166816]
R1 NNSHTTPS;NNSHTTPS;c:\windows\system32\drivers\NNSHttps.sys [2014-6-4 110624]
R1 NNSIDS;NNSIDS;c:\windows\system32\drivers\NNSIds.sys [2014-6-4 125216]
R1 NNSNAHSL;Network Activity Hook Server LightWeight Filter Driver;c:\windows\system32\drivers\NNSNAHSL.sys [2014-1-16 40192]
R1 NNSPICC;NNSPICC;c:\windows\system32\drivers\NNSpicc.sys [2014-6-4 96160]
R1 NNSPIHSW;NNSPIHSW;c:\windows\system32\drivers\NNSPihsw.sys [2014-6-4 61984]
R1 NNSPOP3;NNSPOP3;c:\windows\system32\drivers\NNSPop3.sys [2014-6-4 121888]
R1 NNSPROT;NNSPROT;c:\windows\system32\drivers\NNSProt.sys [2014-6-4 288032]
R1 NNSPRV;NNSPRV;c:\windows\system32\drivers\NNSPrv.sys [2014-6-4 208800]
R1 NNSSMTP;NNSSMTP;c:\windows\system32\drivers\NNSSmtp.sys [2014-6-4 109856]
R1 NNSSTRM;NNSSTRM;c:\windows\system32\drivers\NNSStrm.sys [2014-6-4 244000]
R1 NNSTLSC;NNSTLSC;c:\windows\system32\drivers\NNStlsc.sys [2014-6-4 96928]
R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [2014-10-2 168208]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-7-9 1871160]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-7-9 969016]
R2 NanoServiceMain;Panda Protection Service;c:\program files\panda security\panda security protection\PSANHost.exe [2014-10-14 142072]
R2 PandaAgent;Panda Devices Agent;c:\program files\panda security\panda devices agent\AgentSvc.exe [2014-10-9 66808]
R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [2014-10-14 139536]
R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [2014-10-14 105232]
R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [2014-10-2 113936]
R2 PSINProt;PSINProt;c:\windows\system32\drivers\PSINProt.sys [2014-10-2 124688]
R2 PSINReg;PSINReg;c:\windows\system32\drivers\PSINReg.sys [2014-10-14 100112]
R2 PSUAService;Panda Product Service;c:\program files\panda security\panda security protection\PSUAService.exe [2014-10-16 38136]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2014-11-23 171928]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2014-5-22 33792]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-7-9 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2014-7-9 114904]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2014-7-9 51928]
R3 PSKMAD;PSKMAD;c:\windows\system32\drivers\PSKMAD.sys [2014-12-6 48736]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-11 139776]
R3 TotRec8;Total Recorder WDM audio filter driver;c:\windows\system32\drivers\TotRec8.sys [2014-6-23 91728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2014-11-23 1738168]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2014-11-23 2088408]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2014-5-20 674048]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2014-5-20 79360]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2014-8-1 66112]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2014-6-23 49856]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2014-3-31 1512640]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-6-28 108032]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2014-6-24 15872]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2014-8-1 180672]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;c:\windows\system32\drivers\gtkdrv.sys [2014-12-5 16128]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-6-26 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2014-6-25 1343400]
S3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM);c:\windows\system32\drivers\ymidusbw.sys [2013-4-4 36520]
.
=============== Created Last 30 ================
.
2014-12-07 07:25:16    --------    d-----w-    c:\users\karl marx\appdata\local\WinZip
2014-12-07 07:23:36    --------    d-----w-    c:\program files\File Association Helper
2014-12-06 07:19:41    --------    d-----w-    c:\programdata\GridinSoft
2014-12-06 02:10:32    48736    ----a-w-    c:\windows\system32\drivers\PSKMAD.sys
2014-12-05 15:25:04    16128    ----a-w-    c:\windows\system32\drivers\gtkdrv.sys
2014-12-01 14:45:50    --------    d-----w-    c:\programdata\F-Secure
2014-12-01 14:43:53    --------    d-----w-    c:\users\karl marx\appdata\roaming\QuickScan
2014-11-28 17:35:24    290304    ----a-w-    c:\windows\system32\subinacl.exe
2014-11-28 17:35:22    --------    d-----w-    c:\program files\common files\Microsoft
2014-11-28 17:35:22    --------    d-----w-    c:\program files\Adware-Removal-Tool
2014-11-23 17:34:56    --------    d-----w-    C:\AdwCleaner
2014-11-23 14:23:53    18968    ----a-w-    c:\windows\system32\sdnclean.exe
2014-11-23 14:23:47    --------    d-----w-    c:\programdata\Spybot - Search & Destroy
2014-11-23 14:23:40    --------    d-----w-    c:\program files\Spybot - Search & Destroy 2
2014-11-23 12:54:13    --------    d-----w-    c:\users\karl marx\appdata\roaming\{37E99E86-D615-4B08-937F-F8F935C455F3}_ANZHUANG
2014-11-23 12:52:41    --------    d-----w-    c:\program files\c34bb4fc-c23a-4eef-becd-4082e56ca948
.
==================== Find3M  ====================
.
2014-12-08 16:33:49    114904    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2014-12-02 01:14:12    71344    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2014-12-02 01:14:12    701104    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2014-11-21 00:44:20    51928    ----a-w-    c:\windows\system32\drivers\mwac.sys
2014-11-21 00:44:10    75480    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2014-11-21 00:44:06    23256    ----a-w-    c:\windows\system32\drivers\mbam.sys
2014-10-13 20:04:20    100112    ----a-w-    c:\windows\system32\drivers\PSINReg.sys
2014-10-13 20:04:19    105232    ----a-w-    c:\windows\system32\drivers\PSINFile.sys
2014-10-13 20:04:18    139536    ----a-w-    c:\windows\system32\drivers\PSINAflt.sys
2014-10-02 14:16:38    124688    ----a-w-    c:\windows\system32\drivers\PSINProt.sys
2014-10-02 14:16:38    113936    ----a-w-    c:\windows\system32\drivers\PSINProc.sys
2014-10-02 14:16:37    168208    ----a-w-    c:\windows\system32\drivers\PSINKNC.sys
.
============= FINISH: 23:07:30.56 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 tetonbob

tetonbob

  • Malware Response Team
  • 796 posts
  • OFFLINE
  •  
  • Local time:07:08 AM

Posted 12 December 2014 - 12:26 AM

As this issue is being addressed elsewhere, this topic will be closed. Thank you.


Practice Safe Surfing

Proud Member of UNITE since 2006

Microsoft MVP Consumer Security 2009 - 2015




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users