This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Bizarre Browser (Opera, portable) Behaviour

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

My problem is with my Opera browser - its a portable version. However, the problem only seems to manifest itself on one particular machine, the one I'm submitting this post from. It's a a work machine at a company I do some consultancy for. Their systems are managed by a 3rd party, which is why I tend to run portable programs wherever possible - leave no trace! I have tried several 'installed' browsers on the same machine, namely IE, Firefox and Opera. All seem fine - it is just my portable version of Opera, albeit only on this machine, that seems to behave irregularly.

When browsing, if I select a link in, say Google, the first click typically (but not always) redirects to some strange site, normally shopping or consumer review site - but its never the same site twice. So, I click 'back', re-click my link and I'm connected to the correct site.

I've so far tried an anti-rootkit (from Sophos - this is also the Anti-V brand used by the company) and a program called Autorun Eater. The latter did initially report some type of infection with my portable USB device but that has since been cleared and no more infection reports since. (I do not run Autorun Eater all the time, just occasionally to check that all is as it should be).

As per instructions in how to post, please find below my copy & pasted HjT log. I can also supply the Startuplist.txt file if required. I have also downloaded and run ERUNT and have the registry backup saved to both HD and a portable device.

Thanks for any help in advance!

Nick
_____________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:24, on 24/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apple\Library\System\machd.exe
C:\Apple\Library\System\nmserver.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Gemplus\GemSafe Libraries\BIN\GCardSrvNT.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\Gemplus\GemSafe Libraries\BIN\GCardSrv.exe
C:\Apple\Library\WebObjects\Applications\wotaskd.woa\woservice.exe
C:\Apple\Library\Frameworks\Foundation.framework\Resources\pgroup.exe
C:\Apple\Library\WebObjects\Applications\wotaskd.woa\wotaskd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Gemplus\GemSafe Libraries\BIN\RegTool.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe
C:\Apple\Library\System\WindowServer.exe
E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
E:\PortableApps\Opera\op.com
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
E:\PortableApps\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: FreecycleMemberBHO - {C3E5E149-27B7-49D1-8420-B02AC52AF663} - C:\Program Files\Freecycle\FreecycleMember.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [RegTool] C:\Program Files\Gemplus\GemSafe Libraries\BIN\RegTool.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Pasteboard Server.lnk = C:\Apple\Library\Frameworks\AppKit.framework\Resources\pbs.exe
O4 - Global Startup: Window Server.lnk = C:\Apple\Library\System\WindowServer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files\PDFill\DownloadPDF.exe
O12 - Plugin for .csd: C:\Program Files\Gemplus\eSigner\plugin\Npcsig.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232017343437
O17 - HKLM\System\CCS\Services\Tcpip\..\{31E75CDF-A277-4E8E-A726-5256262FF18B}: Domain = mc2recovery.co.uk
O17 - HKLM\System\CCS\Services\Tcpip\..\{31E75CDF-A277-4E8E-A726-5256262FF18B}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CS1\Services\Tcpip\..\{31E75CDF-A277-4E8E-A726-5256262FF18B}: Domain = mc2recovery.co.uk
O17 - HKLM\System\CS1\Services\Tcpip\..\{31E75CDF-A277-4E8E-A726-5256262FF18B}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CS2\Services\Tcpip\..\{31E75CDF-A277-4E8E-A726-5256262FF18B}: Domain = mc2recovery.co.uk
O17 - HKLM\System\CS2\Services\Tcpip\..\{31E75CDF-A277-4E8E-A726-5256262FF18B}: NameServer = 85.255.115.30,85.255.112.150
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.30,85.255.112.150
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
O23 - Service: Apple Mach Daemon (Apple_Mach_Daemon) - Unknown owner - C:/Apple\Library\System\machd.exe
O23 - Service: Apple Netname Server (Apple_Netname_Server) - Unknown owner - C:/Apple\Library\System\nmserver.exe
O23 - Service: Intel® Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: GemSAFE Card Server - Gemplus - C:\Program Files\Gemplus\GemSafe Libraries\BIN\GCardSrvNT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Intel® Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe (file missing)
O23 - Service: Apple WebObjects Monitor 4.5.1 (WOMonitor451) - Unknown owner - C:\Apple\Library\WebObjects\Applications\wotaskd.woa\woservice.exe
O23 - Service: Apple WebObjects Task Daemon 4.5.1 (WOTASKD451) - Unknown owner - C:\Apple\Library\WebObjects\Applications\wotaskd.woa\woservice.exe

–
End of file - 8295 bytes
tickleusknee,

Unfortunately, according to the Terms of Use on this site (you can find them by clicking on Terms of Use in the upper left of your screen), we cannot work on business machines. We also do not work on machines without the permission of the owner of the machine (which it doesn't appear that you are).

You should have someone clean the machine in question because it does appear to have a DNSchanger virus. Often this can spread to other network shares (and infect removable media) including your router. Some variants cleanup very well with Malwarebytes' Antimalware. Others take considerable more effort.

I'm sorry that we aren't able to help you. :(

Good Luck. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI