VX2 plugin.dll aka 2search

November 11, 2006 on 4:28 pm | In Malware analysis | 1 Comment

Originally posted May 21 2005, 02:45 PM

Found by flrman1 here: http://forums.techguy.org/security/362582-solved-loads-rubbish.html#post2613176

Shows in a HijackThis log as:
O1 – Hosts: 69.20.16.183 auto.search.msn.com
O1 – Hosts: 69.20.16.183 search.netscape.com
O1 – Hosts: 69.20.16.183 ieautosearch

O2 – BHO: GoogleCatch.clsIESpy – {4508E20C-ACAD-11D2-9FC0-00550076E06F} – C:\Program Files\2search\plugin.dll
or
O2 – BHO: IEsearch.clsIESpy – {4508E20C-ACAD-11D2-9FC0-00550076E06F} – C:\PROGRAM FILES\2SEARCH\PLUGIN.DLL

Related files:
date.dat = 13 bytes
getst.exe = 28672 bytes
main.exe = 32768 bytes
msnnames.cab = 21634 bytes
this cab holds msnnames.ocx = 43544 bytes
plugin.dll = 53248 bytes
uninstall.exe = 32768 bytes

Uninstall.exe works exceptionally well if you let it connect to the internet
Only leaves the hosts file Hijack behind.

Total Uninstall log

Files
===============
(+)(FOLDER) C:\Program Files\2search
(+)(FOLDER) C:\WINDOWS\system32\feeds
(FOLDER) C:\WINDOWS\system32\drivers\etc
(*)(FILE) hosts
21:17 28-11-04 27748 bytes ==> 14:26 21-05-05 27760 bytes

Registry
===============
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\IEsearch.clsIESpy
(+)(REGISTRY VALUE) (Standaard) = ‘IEsearch.clsIESpy’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\IEsearch.clsIESpy\Clsid
(+)(REGISTRY VALUE) (Standaard) = ‘{4508E20C-ACAD-11D2-9FC0-00550076E06F}’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
(+)(REGISTRY VALUE) (Standaard) = ‘IEsearch.clsIESpy’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\Implemented Categories
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\InprocServer32
(+)(REGISTRY VALUE) (Standaard) = ‘c:\progra~1\2search\plugin.dll’
(+)(REGISTRY VALUE) ThreadingModel = ‘Apartment’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\ProgID
(+)(REGISTRY VALUE) (Standaard) = ‘IEsearch.clsIESpy’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\Programmable
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\TypeLib
(+)(REGISTRY VALUE) (Standaard) = ‘{68E774CB-72D1-4A52-B55B-C0B1011E013B}’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F}\VERSION
(+)(REGISTRY VALUE) (Standaard) = ‘3.0’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\Interface\{0EB61AF8-0B15-48B6-A971-1F206F2E3D5E}
(+)(REGISTRY VALUE) (Standaard) = ‘clsIESpy’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\Interface\{0EB61AF8-0B15-48B6-A971-1F206F2E3D5E}\ProxyStubClsid
(+)(REGISTRY VALUE) (Standaard) = ‘{00020424-0000-0000-C000-000000000046}’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\Interface\{0EB61AF8-0B15-48B6-A971-1F206F2E3D5E}\ProxyStubClsid32
(+)(REGISTRY VALUE) (Standaard) = ‘{00020424-0000-0000-C000-000000000046}’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\Interface\{0EB61AF8-0B15-48B6-A971-1F206F2E3D5E}\TypeLib
(+)(REGISTRY VALUE) (Standaard) = ‘{68E774CB-72D1-4A52-B55B-C0B1011E013B}’
(+)(REGISTRY VALUE) Version = ‘3.0’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}\3.0
(+)(REGISTRY VALUE) (Standaard) = ‘IEsearch’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}\3.0\0
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}\3.0\0\win32
(+)(REGISTRY VALUE) (Standaard) = ‘c:\progra~1\2search\plugin.dll’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}\3.0\FLAGS
(+)(REGISTRY VALUE) (Standaard) = ‘0’
(+)(REGISTRY KEY) HKEY_CLASSES_ROOT\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B}\3.0\HELPDIR
(+)(REGISTRY VALUE) (Standaard) = ‘c:\progra~1\2search’
(REGISTRY KEY) HKEY_LOCAL_MACHINE\SOFTWARE\Assembly Developers\TaskGuardian
(+)(REGISTRY KEY) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
(+)(REGISTRY VALUE) k = ‘k’
(+)(REGISTRY KEY) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\2search
(+)(REGISTRY VALUE) DisplayName = ‘Uninstall 2search’
(+)(REGISTRY VALUE) UninstallString = ‘C:\Program Files\2search\uninstall.exe’
(+)(REGISTRY KEY) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
(+)(REGISTRY KEY) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4508E20C-ACAD-11D2-9FC0-00550076E06F}
(+)(REGISTRY VALUE) M:\Manege\2search\getst.exe = ‘GetWebFile’
(+)(REGISTRY VALUE) M:\Manege\2search\main.exe = ‘GetWebFile’

 

1 Comment »

RSS feed for comments on this post. TrackBack URI

  1. Updated my script to deal with the IM-Names variant found at the Tech Support Forums:

    http://www.techsupportforum.com/security-center/hijackthis-log-help/139757-problems-hjt-log-attached.html#post789379

    Comment by metallica — February 18, 2007 #

Leave a comment

XHTML: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

Powered by WordPress with Pool theme design by Borja Fernandez.
Entries and comments feeds. Valid XHTML and CSS. ^Top^