{"id":7192,"date":"2021-11-23T10:36:55","date_gmt":"2021-11-23T10:36:55","guid":{"rendered":"https:\/\/lgildv5i97.onrocket.site\/answers\/?post_type=question&#038;p=7192"},"modified":"2021-11-23T10:38:09","modified_gmt":"2021-11-23T10:38:09","slug":"redirect-virus-searchprotocolhost-exe","status":"publish","type":"question","link":"https:\/\/computing.net\/answers\/security\/redirect-virus-searchprotocolhostexe\/37331.html","title":{"rendered":"Redirect Virus: SearchProtocolHost.Exe"},"content":{"rendered":"<p>i realized there was a redirect virus on my computer&#8230;<\/p>\n<p>i figured out the issue my self using task manager ( stopped all other processes except Internet explorer and assumed the one that would pop up would be the issue&#8230;)<\/p>\n<p>i have used trend micro- hijack this -heard of it from other users saying it would help to fix the problem<\/p>\n<p>i have no idea what to think of it because there was a pop up that said:<\/p>\n<p>For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, Hijack This may NOT be able to fix this.<\/p>\n<p>If that happens, you need to edit the file yourself. To do this, &#8230; Run and type:<\/p>\n<p>notepad C:\\Windows\\System32\\drivers\\etc\\hosts<br \/>\nand pres enter. find the line(s) Hijack this reports and delete them. Save the file as &#8216;hosts.&#8217; and reboot.<\/p>\n<p>&#8230;then there was another option for vista- i have this and right click -&gt;run as administrator.<\/p>\n<p>do i need to edit the file?&#8230; how would i know?<\/p>\n<p>this is the log and its really long because i wasn&#8217;t sure if i needed to not include anything<\/p>\n<p>Log file of Trend Micro Hijack This v2.0.4<br \/>\nScan saved at 18:41:12, on 2011-11-08<br \/>\nPlatform: Windows Vista SP2 (WinNT 6.00.1906)<br \/>\nMSIE: Internet Explorer v9.00 (9.00.8112.16421)<br \/>\nBoot mode: Normal<\/p>\n<p>Running processes:<br \/>\nC:\\Windows\\system32\\taskeng.exe<br \/>\nC:\\Windows\\Explorer.EXE<br \/>\nC:\\Program Files\\Windows Defender\\MSASCui.exe<br \/>\nC:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe<br \/>\nC:\\Windows\\sttray.exe<br \/>\nC:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe<br \/>\nC:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.EXE<br \/>\nC:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe<br \/>\nC:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe<br \/>\nC:\\Program Files\\Internet Explorer\\iexplore.exe<br \/>\nC:\\Program Files\\Internet Explorer\\iexplore.exe<br \/>\nC:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe<br \/>\nC:\\Program Files\\Internet Explorer\\iexplore.exe<br \/>\nC:\\Program Files\\Trend Micro\\Hijack This\\Hijack This.exe<br \/>\nC:\\Windows\\System32\\SnippingTool.exe<br \/>\nC:\\Program Files\\Internet Explorer\\iexplore.exe<br \/>\nC:\\Program Files\\Windows Media Player\\wmpnscfg.exe<\/p>\n<p>R1 &#8211; HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page =\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/go.microsoft.com\/fwlink\/?LinkId=54896\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>\nR1 &#8211; HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL =\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/go.microsoft.com\/fwlink\/?LinkId=54896\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>\nR1 &#8211; HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page =\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/go.microsoft.com\/fwlink\/?LinkId=54896\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>\nR0 &#8211; HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/go.microsoft.com\/fwlink\/?LinkId=69157\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>\nR0 &#8211; HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =<br \/>\nR0 &#8211; HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =<br \/>\nR1 &#8211; HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Window Title = Internet Explorer provided by Dell<br \/>\nR1 &#8211; HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyServer = http=127.0.0.1:6522<br \/>\nR0 &#8211; HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =<br \/>\nR3 &#8211; URLSearchHook: (no name) &#8211; {88c7f2aa-f93f-432c-8f0e-b7d85967a527} &#8211; (no file)<br \/>\nO1 &#8211; Hosts: ::1 local host<br \/>\nO2 &#8211; BHO: StumbleUpon Launcher &#8211; {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} &#8211; C:\\Program Files\\StumbleUpon\\StumbleUponIEBar.dll<br \/>\nO2 &#8211; BHO: AcroIEHelperStub &#8211; {18DF081C-E8AD-4283-A596-FA578C2EBDC3} &#8211; C:\\Program Files\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll<br \/>\nO2 &#8211; BHO: (no name) &#8211; {9D425283-D487-4337-BAB6-AB8354A81457} &#8211; (no file)<br \/>\nO2 &#8211; BHO: AIM Toolbar Loader &#8211; {b0cda128-b425-4eef-a174-61a11ac5dbf8} &#8211; C:\\Program Files\\AIM Toolbar\\aimtb.dll (file missing)<br \/>\nO2 &#8211; BHO: CBrowserHelperObject Object &#8211; {CA6319C0-31B7-401E-A518-A07C3DB8F777} &#8211; C:\\Program Files\\Dell\\BAE\\BAE.dll<br \/>\nO2 &#8211; BHO: Java(tm) Plug-In 2 SSV Helper &#8211; {DBC80044-A445-435b-BC74-9C25C1C588A9} &#8211; C:\\Program Files\\Java\\jre6\\bin\\jp2ssv.dll<br \/>\nO2 &#8211; BHO: Yontoo Layers &#8211; {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} &#8211; C:\\Program Files\\Yontoo Layers\\YontooIEClient.dll (file missing)<br \/>\nO3 &#8211; Toolbar: AIM Toolbar &#8211; {61539ecd-cc67-4437-a03c-9aaccbd14326} &#8211; C:\\Program Files\\AIM Toolbar\\aimtb.dll (file missing)<br \/>\nO3 &#8211; Toolbar: StumbleUpon Toolbar &#8211; {5093EB4C-3E93-40AB-9266-B607BA87BDC8} &#8211; C:\\Program Files\\StumbleUpon\\StumbleUponIEBar.dll<br \/>\nO3 &#8211; Toolbar: (no name) &#8211; {9D425283-D487-4337-BAB6-AB8354A81457} &#8211; (no file)<br \/>\nO4 &#8211; HKLM\\..\\Run: [Windows Defender] %ProgramFiles%\\Windows Defender\\MSASCui.exe -hide<br \/>\nO4 &#8211; HKLM\\..\\Run: [SynTPEnh] C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe<br \/>\nO4 &#8211; HKLM\\..\\Run: [ATICCC] &#8220;C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe&#8221;<br \/>\nO4 &#8211; HKLM\\..\\Run: [Broadcom Wireless Manager UI] C:\\Windows\\system32\\WLTRAY.exe<br \/>\nO4 &#8211; HKLM\\..\\Run: [ISUSScheduler] &#8220;C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe&#8221; -start<br \/>\nO4 &#8211; HKLM\\..\\Run: [dscactivate] c:\\dell\\dsca.exe 3<br \/>\nO4 &#8211; HKLM\\..\\Run: [ECenter] C:\\Dell\\E-Center\\EULALauncher.exe<br \/>\nO4 &#8211; HKLM\\..\\Run: [LogitechQuickCamRibbon] &#8220;C:\\Program Files\\Logitech\\Logitech WebCam Software\\LWS.exe&#8221; \/hide<br \/>\nO4 &#8211; HKLM\\..\\Run: [iTunesHelper] &#8220;C:\\Program Files\\iTunes\\iTunesHelper.exe&#8221;<br \/>\nO4 &#8211; HKLM\\..\\Run: [RegWork] C:\\Program Files\\RegWork\\RegWork.exe<br \/>\nO4 &#8211; HKLM\\..\\Run: [MSConfig] &#8220;C:\\Windows\\System32\\msconfig.exe&#8221; \/auto<br \/>\nO4 &#8211; HKLM\\..\\Run: [Adobe Reader Speed Launcher] &#8220;C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe&#8221;<br \/>\nO4 &#8211; HKLM\\..\\Run: [Adobe ARM] &#8220;C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe&#8221;<br \/>\nO4 &#8211; HKLM\\..\\Run: [QuickTime Task] &#8220;C:\\Program Files\\QuickTime\\QTTask.exe&#8221; -atboottime<br \/>\nO4 &#8211; HKLM\\..\\Run: [SigmatelSysTrayApp] sttray.exe<br \/>\nO4 &#8211; HKLM\\..\\Run: [SunJavaUpdateSched] &#8220;C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe&#8221;<br \/>\nO4 &#8211; HKCU\\..\\Run: [ehTray.exe] C:\\Windows\\ehome\\ehTray.exe<br \/>\nO4 &#8211; HKCU\\..\\Run: [EA Core] &#8220;C:\\Program Files\\Electronic Arts\\EADM\\Core.exe&#8221; -silent<br \/>\nO4 &#8211; HKCU\\..\\Run: [Speech Recognition] &#8220;C:\\Windows\\Speech\\Common\\sapisvr.exe&#8221; -SpeechUX -Startup<br \/>\nO4 &#8211; HKCU\\..\\Run: [jhcelcof] C:\\Users\\Jenny\\AppData\\Local\\yhirmkvkp\\dthcdneshdw.exe<br \/>\nO4 &#8211; HKCU\\..\\Run: [Sidebar] C:\\Program Files\\Windows Sidebar\\sidebar.exe<br \/>\nO4 &#8211; HKCU\\..\\Run: [BitTorrent DNA] &#8220;C:\\Users\\Jenny\\Program Files\\DNA\\btdna.exe&#8221;<br \/>\nO4 &#8211; HKCU\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe<br \/>\nO4 &#8211; HKCU\\..\\Run: [Google Update] &#8220;C:\\Users\\Jenny\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe&#8221; \/c<br \/>\nO4 &#8211; HKCU\\..\\Run: [EADM] &#8220;C:\\Program Files\\Origin\\Origin.exe&#8221; -AutoStart<br \/>\nO4 &#8211; HKCU\\..\\Run: [WMPNSCFG] C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe<br \/>\nO4 &#8211; HKCU\\..\\RunOnce: [FlashPlayerUpdate] C:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe -update activex<br \/>\nO4 &#8211; Global Startup: Digital Line Detect.lnk = C:\\Program Files\\Digital Line Detect\\DLG.exe<br \/>\nO4 &#8211; Global Startup: QuickSet.lnk = ?<br \/>\nO8 &#8211; Extra context menu item: Google Sidewiki&#8230; &#8211; res:\/\/C:\\Program Files\\Google\\Google Toolbar\\Component\\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll\/cmsidewiki.html<br \/>\nO8 &#8211; Extra context menu item: StumbleUpon PhotoBlog It! &#8211; res:\/\/StumbleUponIEBar.dll\/blogimage<br \/>\nO11 &#8211; Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br \/>\nO16 &#8211; DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} (Panasonic Network Camera) &#8211;\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/62.2.213.149\/SysCamInst.cab\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/62.2.213.149\/SysCamInst.cab<\/a><br \/>\nO16 &#8211; DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} &#8211;\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/platformdl.adobe.com\/NOS\/getPlusPlus\/1.6\/gp.cab\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/platformdl.adobe.com\/NOS\/get&#8230;<\/a><br \/>\nO16 &#8211; DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} &#8211;\u00a0<a href=\"https:\/\/web.archive.org\/web\/20121026014852\/http:\/\/content.systemrequirementslab.com.s3.amazonaws.com\/global\/bin\/srldetect_cyri_4.4.16.0.cab\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/content.systemrequirementsla&#8230;<\/a><br \/>\nO22 &#8211; SharedTaskScheduler: Component Categories cache daemon &#8211; {8C7461EF-2B13-11d2-BE35-3078302C2030} &#8211; C:\\Windows\\system32\\browseui.dll<br \/>\nO23 &#8211; Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) &#8211; Unknown owner &#8211; C:\\Program Files\\Adobe\\Elements Organizer 8.0\\PhotoshopElementsFileAgent.exe (file missing)<br \/>\nO23 &#8211; Service: Apple Mobile Device &#8211; Apple Inc. &#8211; C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe<br \/>\nO23 &#8211; Service: Ati External Event Utility &#8211; ATI Technologies Inc. &#8211; C:\\Windows\\system32\\Ati2evxx.exe<br \/>\nO23 &#8211; Service: Bonjour Service &#8211; Apple Inc. &#8211; C:\\Program Files\\Bonjour\\mDNSResponder.exe<br \/>\nO23 &#8211; Service: DSBrokerService &#8211; Unknown owner &#8211; C:\\Program Files\\DellSupport\\brkrsvc.exe (file missing)<br \/>\nO23 &#8211; Service: FLEXnet Licensing Service &#8211; Acresso Software Inc. &#8211; C:\\Program Files\\Common Files\\Macrovision Shared\\FLEXnet Publisher\\FNPLicensingService.exe<br \/>\nO23 &#8211; Service: Google Update Service (gupdate) (gupdate) &#8211; Google Inc. &#8211; C:\\Program Files\\Google\\Update\\GoogleUpdate.exe<br \/>\nO23 &#8211; Service: Google Update Service (gupdatem) (gupdatem) &#8211; Google Inc. &#8211; C:\\Program Files\\Google\\Update\\GoogleUpdate.exe<br \/>\nO23 &#8211; Service: InstallDriver Table Manager (IDriverT) &#8211; Macrovision Corporation &#8211; C:\\Program Files\\Common Files\\InstallShield\\Driver\\11\\Intel 32\\IDriverT.exe<br \/>\nO23 &#8211; Service: iPod Service &#8211; Apple Inc. &#8211; C:\\Program Files\\iPod\\bin\\iPodService.exe<br \/>\nO23 &#8211; Service: Process Monitor (LVPrcSrv) &#8211; Logitech Inc. &#8211; C:\\Program Files\\Common Files\\LogiShrd\\LVMVFM\\LVPrcSrv.exe<br \/>\nO23 &#8211; Service: My Web Search Service (MyWebSearchService) &#8211; Unknown owner &#8211; C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\mwssvc.exe (file missing)<br \/>\nO23 &#8211; Service: PnkBstrA &#8211; Unknown owner &#8211; C:\\Windows\\system32\\PnkBstrA.exe<br \/>\nO23 &#8211; Service: RoxMediaDB9 &#8211; Sonic Solutions &#8211; C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxMediaDB9.exe<br \/>\nO23 &#8211; Service: Roxio Hard Drive Watcher 9 (RoxWatch9) &#8211; Sonic Solutions &#8211; C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxWatch9.exe<br \/>\nO23 &#8211; Service: stllssvr &#8211; MicroVision Development, Inc. &#8211; C:\\Program Files\\Common Files\\SureThing Shared\\stllssvr.exe<br \/>\nO23 &#8211; Service: StumbleUponUpdateService &#8211; stumbleupon.com &#8211; C:\\Program Files\\StumbleUpon\\StumbleUponUpdateService.exe<br \/>\nO23 &#8211; Service: Dell Wireless WLAN Tray Service (wltrysvc) &#8211; Unknown owner &#8211; C:\\Windows\\System32\\WLTRYSVC.EXE<br \/>\nO23 &#8211; Service: XAudioService &#8211; Conexant Systems, Inc. &#8211; C:\\Windows\\system32\\DRIVERS\\xaudio.exe<\/p>\n<p>thank you very much to anyone willing to give me advice<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"iawp_total_views":81},"question-category":[56],"question_tags":[],"class_list":["post-7192","question","type-question","status-publish","hentry","question-category-security"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question\/7192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question"}],"about":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/types\/question"}],"author":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/comments?post=7192"}],"wp:attachment":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/media?parent=7192"}],"wp:term":[{"taxonomy":"question-category","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question-category?post=7192"},{"taxonomy":"question_tags","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question_tags?post=7192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}