# What is this computer infected with?

**URL:** https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406
**Category:** Factual Questions
**Created:** [March 10, 2004, 2:37am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406 "2004-03-10T02:37:45Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Eleusis](https://avatars.discourse-cdn.com/v4/letter/e/f4b2a3/32.png) [@Eleusis](https://boards.straightdope.com/u/Eleusis)
#### Post date: [March 10, 2004, 2:37am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/1 "2004-03-10T02:37:45Z")

</div>

I’m usually pretty good at diagnosing and getting rid of these things, but this one is eluding me.

The IE browser homepage was hijacked to [www.browser-page.com](http://www.browser-page.com) , and when I visit that page, a clone of [msn.com](http://msn.com) displays with a bunch of popups about spyware from [www.adwarehunter.com](http://www.adwarehunter.com) , and the CDROM drive opens.

When I go there from my laptop which is not infected, I get the myway news page, no popups, and no hot drive tray action.

I’ve run updated copies of both adaware and spybot S&D (neither found anything), and there is updated virus protection on the computer as well. Googling [browser-page.com](http://browser-page.com) and [adwarehunter.com](http://adwarehunter.com) is no help.

Any suggestions?

---

<div class="post-metadata">

### Author: ![Deadly\_Nightlight](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@Deadly\_Nightlight](https://boards.straightdope.com/u/Deadly_Nightlight)
#### Post date: [March 10, 2004, 2:58am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/2 "2004-03-10T02:58:47Z")

</div>

By Far I am no computer genius, however, I use “Hijack this” (its a program kinda like spybot) to see if I can find anything fishy. When all else fails, hijack this can usually help me out.

---

<div class="post-metadata">

### Author: ![Eleusis](https://avatars.discourse-cdn.com/v4/letter/e/f4b2a3/32.png) [@Eleusis](https://boards.straightdope.com/u/Eleusis)
#### Post date: [March 10, 2004, 3:22am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/3 "2004-03-10T03:22:01Z")

</div>

Thanks, I ran Hijack This, here is the log:

```auto

Logfile of HijackThis v1.97.3
Scan saved at 9:05:02 PM, on 3/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\LANSUITE\lansuits.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\lxamsp32.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\YAC\yac.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\logon.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Y:\Software\Utilitities\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38049.6845833333
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

```

It all looks normal as far as I can tell. AVG is the virus scanner. There’s a Lexmark X63 USB printer installed. Lansuits is a mail server. Yac is a Tivo hack that displays caller ID info on my TV screen. Logonui.exe and logon.scr running is normal because I’m using remote desktop to access the machine.

Some other things I’ve tried: I searched the registry for browser-page and adware, as well as the IP addresses I get when I ping [browser-page.com](http://browser-page.com), and [adwarehunter.com](http://adwarehunter.com), nothing. When I ping [browser-page.com](http://browser-page.com) it gets the correct IP, not the hijacked one. If I could figure out the IP of the actual hijacked [msn.com](http://msn.com) clone page, I’d try searching for that, too. I’ve checked my hosts file, nothing there.

---

<div class="post-metadata">

### Author: ![Deadly\_Nightlight](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@Deadly\_Nightlight](https://boards.straightdope.com/u/Deadly_Nightlight)
#### Post date: [March 10, 2004, 3:26am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/4 "2004-03-10T03:26:39Z")

</div>

Well I’ll be dipped. Your Log looks A-ok to me. I can’t think of anything else, But I am sure another much cooler doper will be along shortly to tell you some things to try. Some where around “the winter of our lost content” I had a 100 something post thread going about a computer problem I had, So I have full confidence in our fellow dopers 😃

---

<div class="post-metadata">

### Author: ![Cillasi](https://avatars.discourse-cdn.com/v4/letter/c/71e660/32.png) [@Cillasi](https://boards.straightdope.com/u/Cillasi)
#### Post date: [March 10, 2004, 4:07am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/5 "2004-03-10T04:07:25Z")

</div>

Spybot, adaware, etc., only target adware and spyware. They don’t identify viruses, trojans, etc.

What you have is a type of “infection” that is not considered adware, spyware, virus or trojan. Lots of companies won’t target these type of programs, which you download with a variety of freeware, like Kazaa and other peer-to-peer sharing programs because you supposedly give permission for them to be installed along with the freeware.

Currently, McAfee will find and clean these programs, whereas Norton will not. My son had that CD drive door opening one, along with popups that won’t close and I was forced to buy McAfee in order to get rid of it because Norton doesn’t recognize it as a virus.

If you do a McAfee online scan, it will identify the “virus” but won’t clean it. You need the full program to clean it or attempt to do it yourself which is darned near impossible.

Good luck.

---

<div class="post-metadata">

### Author: ![danvanf](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@danvanf](https://boards.straightdope.com/u/danvanf)
#### Post date: [March 10, 2004, 5:13am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/6 "2004-03-10T05:13:39Z")

</div>

I’d take a look at your hosts file. Normally the only active line is something like 127.0.0.1 — localhost and a number of lines that start with # (comment)

---

<div class="post-metadata">

### Author: ![Toddly](https://avatars.discourse-cdn.com/v4/letter/t/22d042/32.png) [@Toddly](https://boards.straightdope.com/u/Toddly)
#### Post date: [March 10, 2004, 5:33am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/7 "2004-03-10T05:33:06Z")

</div>

I advise that you visit this [site](http://www.spywareinfo.com). It is dedicated to assistance in removing spyware, etc. They have Forums and with a search you might find a good fix. Make sure that you have the latest updates from Spybot. They are sometimes hard to get. I would also try CWShredder and see it that helps. There are links to it in the Spyware Forums. Your HiJack This log looks smaller that some that I have seen. You can post your log at the Forums and they will analyse it and help you out. My guess that it is in the registry somewhere. There is also a nice program called [Spyware Blaster](http://www.javacoolsoftware.com/spywareblaster.html) that you install and it prevents identified spyware from installation in the first place. It will not help now but prevents future problems.I have had good success with it on the computers at home. Make sure as always to install the latest updates. Post back if successful as I would be interested in the solution. Good Luck

---

<div class="post-metadata">

### Author: ![kniz](https://avatars.discourse-cdn.com/v4/letter/k/c37758/32.png) [@kniz](https://boards.straightdope.com/u/kniz)
#### Post date: [March 10, 2004, 5:59am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/8 "2004-03-10T05:59:21Z")

</div>

I had something very similar a couple of months ago. Fellow dopers advised me to switch browsers, since these type of attacks are almost always designed to zero in on Explorer (that is what most people use, so they get more victims). I changed to Firebird and my troubles immediately vanished. 🙂

---

<div class="post-metadata">

### Author: ![Urban\_Ranger](https://avatars.discourse-cdn.com/v4/letter/u/e9c0ed/32.png) [@Urban\_Ranger](https://boards.straightdope.com/u/Urban_Ranger)
#### Post date: [March 10, 2004, 8:29am UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/9 "2004-03-10T08:29:39Z")

</div>

Some time back, a program called Qhost does exactly that kind of thing. What you got is probably a variant of it.

---

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [March 10, 2004, 1:42pm UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/10 "2004-03-10T13:42:54Z")

</div>

You left out the most relevant portions of the hijackthis log: the R1 entries. They’ll tell about any browser hijackings. The log is also truncated, so if it is infected, it can’t be determined.

The most common cause for browser hijackings these days is CoolWebSearch. Download and run [CWShredder](http://www.siena.edu/antivirus/spyware/cws.htm) to see if that cleans it.

If CWShredder doesn’t run, you may need to run the CWS Killer removal tool on the page.

---

<div class="post-metadata">

### Author: ![Deadly\_Nightlight](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@Deadly\_Nightlight](https://boards.straightdope.com/u/Deadly_Nightlight)
#### Post date: [March 10, 2004, 2:14pm UTC](https://boards.straightdope.com/t/what-is-this-computer-infected-with/233406/11 "2004-03-10T14:14:12Z")

</div>

> [@kniz](#):
>
> I had something very similar a couple of months ago. Fellow dopers advised me to switch browsers, since these type of attacks are almost always designed to zero in on Explorer (that is what most people use, so they get more victims). I changed to Firebird and my troubles immediately vanished. 🙂

I would have to agree, I use mozilla. For all I know its a glorified IE, however, I don’t have the problems I had using IE. My niece always uses IE when she uses my computer and it drives me insane because I usually end up having to get rid of something.
