Technical Discussion
  >> Windows Issues


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | 3 | 4 | 5 | 6 | 7 | >> (show all)   Print Thread
Standard User tomxlisa
(member) Fri 26-Apr-13 19:00:41
Print Post

iehighutil.exe Virus:


[link to this post]
 
Not sure if this is the right place to put this but i have a problem with a virus keep coming up, i have tried to close it in msconfig but for some reason that keeps coming up, the virus is iehighutil.exe i think it is a GPU virus, anyone know a tool to get rid of it once and for all?.
Standard User deleted
(deleted) Fri 26-Apr-13 19:11:49
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
I think Combofix may do it http://www.bleepingcomputer.com/combofix/how-to-use-...
Standard User camieabz
(sensei) Fri 26-Apr-13 19:24:08
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Download and run hijackthis, paste the logfile here and find the reference to it. Then paste what you've found to us.

It may have any amount of references. Just guessing, I would install CCleaner, boot into safemode and see if you can disable it in processes, services and anywhere else it might be coming from. You might need to disable or stop the process/service first though.

Reading online, it seems to be linked to bitcoins. I would get rid sharpish.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.


Register (or login) on our website and you will not see this ad.

Standard User ukhardy07
(fountain of knowledge) Fri 26-Apr-13 19:26:18
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
A combination of malware bytes
http://www.malwarebytes.org

& Norton Internet Security
Trial for 90 days at http://buy-download.norton.com/downloads/OEM/20.1/NI...

Always gets me sorted.

Any decent virus will not be removable in MSCONFIG
Most of them disguise as something legit such as attaching to explorer.exe so the only solution is something like malware bytes.
Standard User ukhardy07
(fountain of knowledge) Fri 26-Apr-13 19:26:57
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
This is a great free antivirus too

http://www.avira.com/en/avira-free-antivirus

Has one of the highest detection rates.
Standard User tomxlisa
(member) Fri 26-Apr-13 22:10:15
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
Have tried malwarebytes but didn't work?.
Standard User tomxlisa
(member) Fri 26-Apr-13 22:10:55
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
Will try it, am using microsoft security essentials right now but don't seem that great.
Standard User tomxlisa
(member) Fri 26-Apr-13 22:17:12
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
It come up with this in hijackthis when it found it (O4 - HKCU\..\Run: [iehighutil] "C:\Temporary\iehighutil.exe")
Standard User tomxlisa
(member) Fri 26-Apr-13 22:22:28
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
I will try this out.
Standard User tomxlisa
(member) Fri 26-Apr-13 22:25:50
Print Post

Re: iehighutil.exe Virus:


[re: deleted] [link to this post]
 
Tried this, and never worked?.
Standard User camieabz
(sensei) Fri 26-Apr-13 22:29:35
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Boot into safe mode, and delete it from the folder. Don't know your operating system, but I'll wager that specific temporary folder ought to be deleted too. Windows will recreate it if it's necessary.

If it doesn't allow it, it may be because the file is hidden, or you require elevated permissions to delete it. Do whatever you have to get it deleted from the folder.

Also look in the registry for a reference to it. Maybe:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

(You're looking for a specific reference to iehighutil.exe in the registry - don't touch anything else)

If you find that, or any other references to iehighutil in your registry, delete them.


Lastly, once you get rid of it, if you're in the habit of doing any sort of online banking or transactions, I strongly suggest you change any passwords, and change any other passwords that might be relevant, such as windows startup, router etc.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User tomxlisa
(member) Fri 26-Apr-13 22:32:38
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
Okay i will try that, scanning with that Avira program right now to see if that finds it, i will report back shortly, i will also do what you have said about changing passwords, i take it if i don't do the virus can get into the banking etc?.
Standard User tomxlisa
(member) Fri 26-Apr-13 22:51:42
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
I just done all this, it was in the registry so i deleted it out of there, also got rid of the temp folder out of c: drive also which i think it is in, thing is i've done all that but when i go in msconfig it is still in there, i have stopped it from running when windows starts though, does it still mean its on the computer if its still in msconfig or is that okay it being in there still?.

Edited by tomxlisa (Fri 26-Apr-13 22:52:43)

Standard User ukhardy07
(fountain of knowledge) Fri 26-Apr-13 22:59:50
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
What did avira find? Did it remove it?

I would hazard that the virus or whatever is stopping malware bytes from running as it knows it can remove it.

Edited by ukhardy07 (Fri 26-Apr-13 23:00:18)

Standard User tomxlisa
(member) Fri 26-Apr-13 23:18:33
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
I did all that camieabz said to do, boot to safe mode etc and deleted it from registry, the only place it seems to still be right now is in msconfig but i've disabled it from starting up but it still shows in there, malwarebytes did run but didn't find it, i've not done a scan with Avira yet, that is next on the list.
Standard User Deadbeat
(knowledge is power) Fri 26-Apr-13 23:22:34
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Boot to "Safe Mode With Networking", download and install Cleaner. Run the cleaner section and then run the registry section until no more errors are found.
Download, install (Untick trial offer) and update MBAM and run a full scan.
Now download and run HijackThis, run it and post the resulting logfile here.

Finally, if you have access to a clean machine, download and burn the Kaspersky Rescue Disk. Boot the infected system from the CD, update the definitions and run a full scan.

Got a function?
We've got it covered!

Edited by Deadbeat (Fri 26-Apr-13 23:30:12)

Standard User ukhardy07
(fountain of knowledge) Fri 26-Apr-13 23:58:00
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
Kaspersky really misses most of the unusual stuff. I have links to an IT security firm and kaspersky just didn't do the job good enough.
Standard User tomxlisa
(member) Fri 26-Apr-13 23:59:47
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
This is the log file, i have scanned with malwarebytes and it didn't find it, have deleted it from the registry now and temp files on the c: drive, how is the log file looking now, it did find it on there before but doesn't seem to have found it this time.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:57:40, on 26/04/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\tomxlisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Steam] "E:\Steam\Steam.exe" -silent
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs...
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9385 bytes
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 00:00:02
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Run avira in safe mode after updating it. It has the highest detection levels out of all of the tools suggested this far. I'm shocked that malware bytes didn't find anything it's often a really powerful tool

I never recommend using ccleaner. It's not a virus removal tool at all. It just removes 'junk' from your machine. Thing is it often deletes things that are not junk and CAN cause no end of issues. I understand why you are being asked to run it - so that hopefully it removes that virus from msconfig but it'll only do that once the virus is removed from another tool e.g. avira etc. At which state it doesn't matter if it's left anyway.

My two cents.
Standard User tomxlisa
(member) Sat 27-Apr-13 00:06:55
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
I think the virus is gone now, i have just posted the log file from hijackthis, before it found it but now it is not showing it, i have deleted it from the registry and the temp folder in c: drive, it seems to be gone but is still listed in msconfig, but it isn't starting up with windows cause i have stopped it from doing and hopefully it is gone now so couldn't start up anyway, this is the log file.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:57:40, on 26/04/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Safe mode with network support

Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\tomxlisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Steam] "E:\Steam\Steam.exe" -silent
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs...
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9385 bytes
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 00:11:39
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
All looks good and safe to me!
Standard User tomxlisa
(member) Sat 27-Apr-13 00:15:45
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
Hopefully it is.

Deleted it before but it come back but i think this was cause i forgot to delete it from the registry, made sure to do that this time, the virus is still showing in msconfig, is that such a big deal, even though it shows in there i take it the virus doesn't actually exist on my computer now, is there a way to remove it from the list in msconfig from what i can see you can only disable stuff?.
Standard User XRaySpeX
(eat-sleep-adslguide) Sat 27-Apr-13 00:26:33
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
In reply to a post by tomxlisa:
it seems to be gone but is still listed in msconfig
Where in MSCONFIG? Post the entry here. That should give a clue to how to get rid of it.

If you like you could run up REGEDIT and search for all the occurrences of "iehighutil" and delete them.

There should never be a folder entitled "Temporary"; they are usually called "TMP" or "TEMP".

Apparently iehighutil.exe is a virus that mines Bitcoins.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User tomxlisa
(member) Sat 27-Apr-13 00:30:40
Print Post

Re: iehighutil.exe Virus:


[re: XRaySpeX] [link to this post]
 
It is listed in (Startup) in msconfig, but it isn't listed to start up, i do think the virus is gone now, but is still showing in there and would feel more safer with it gone from there but there is no delete button in msconfig to get rid of it, i will do the search in regedit like you said to check if its still about in there but believe it is gone now, there isn't a folder on my computer called (temporary) now, it seems to have gone and not come back since deleting it and hopefully getting rid of the virus.

Edited by tomxlisa (Sat 27-Apr-13 00:31:41)

Standard User camieabz
(sensei) Sat 27-Apr-13 00:39:54
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
You never know with passwords, and if I ever discover any form of trojan / virus or the like on my system, my first move would be to change all passwords (at the bank's end of things too).

There might be an instance of it in MSconfig, but it should stay disabled, and you should be able to delete the instance of it. Since getting CCleaner, I can't say I've used MSconfig since. With CCleaner you can delete the instances of disabled processes. There used to be a way of doing it in simple text on W2K / XP, but I forget the trick (nad have no idea if it has continued onto Vista / Win7). Boot.ini rings a bell though.

Hope that fix works for you.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User tomxlisa
(member) Sat 27-Apr-13 00:40:47
Print Post

Re: iehighutil.exe Virus: *DELETED*


[re: tomxlisa] [link to this post]
 
Post deleted by tomxlisa
Standard User tomxlisa
(member) Sat 27-Apr-13 00:41:54
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
Searched for it again in the registry and it found other entries for it in there so deleted everything that the search found when i put the virus name in, looked in msconfig afterwards and it seems to have gone from there now so maybe that is what the entries was, as it was still listed in msconfig, i am guessing that the virus had gone but it was just listed still in msconfig which now it isn't, so hopefully all good now, shall i do a last hijackthis log file for you to look at?.

Edited by tomxlisa (Sat 27-Apr-13 00:42:35)

Standard User camieabz
(sensei) Sat 27-Apr-13 00:44:31
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Naw, the first one after the changes showed no instances of it. If the very first log did have it, then it's gone.

The proof is in the pudding though. Is your GPU behaving?

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User tomxlisa
(member) Sat 27-Apr-13 00:46:31
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
My drivers for my GPU was playing up and that is how i found out this virus existed but that is solved now since sorting this virus out, this is the new log file i have just done anyways, have a quick look over it and just double check everything looks good?.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:43:42, on 27/04/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Users\tomxlisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\tomxlisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Steam] "E:\Steam\Steam.exe" -silent
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs...
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9489 bytes
Standard User XRaySpeX
(eat-sleep-adslguide) Sat 27-Apr-13 00:47:22
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Yes, but what line that is listed in MSCONFIG/Startup?

It hasn't gone if MSCONFIG can see it; it's not making anything up.

Yes, MSCONFIG can't itself delete it but it can provide the clue to how to delete it.

I'm willing to bet the entry in MSCONFIG is:
iehighutil "C:\Temporary\iehighutil.exe" HKLM\Software\Microsoft\Windows\CurrentVersion\Run
You were advised to delete the registry entry under HKEY_CURRENT_USER. You also need to delete any in:

HKEY_LOCAL MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User tomxlisa
(member) Sat 27-Apr-13 00:52:36
Print Post

Re: iehighutil.exe Virus:


[re: XRaySpeX] [link to this post]
 
It doesn't seem to be in either of them now as i've just checked, searched for (iehighutil) and deleted everything it come up with which also seemed like it took the virus out of the list in msconfig which was a bonus, this is the hijackthis log that i've just done, everything looks okay?.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:53:57, on 27/04/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Users\tomxlisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\tomxlisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Steam] "E:\Steam\Steam.exe" -silent
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs...
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9489 bytes

Edited by tomxlisa (Sat 27-Apr-13 00:54:23)

Standard User XRaySpeX
(eat-sleep-adslguide) Sat 27-Apr-13 00:58:43
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Good, looks like a Registry Edit Search & Destroy has done the trick smile. It's the method I always prefer over these Registry Cleaners which are prone to false positives.

Hope it hasn't done too much damage. There are many reports of it on Net.

Doesn't look like your Avira anti-virus is on the ball.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User camieabz
(sensei) Sat 27-Apr-13 01:00:25
Print Post

Re: iehighutil.exe Virus:


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
You were advised to delete the registry entry under HKEY_CURRENT_USER. You also need to delete any in:

HKEY_LOCAL MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


Hence why I said to delete pretty much all entries of it. I figured getting the main one would stop it running, then one can look at what else is going on.


Tomxlisa:

That log has no mention of the nasty. You do need to update IE10 though. smile

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User tomxlisa
(member) Sat 27-Apr-13 01:01:25
Print Post

Re: iehighutil.exe Virus:


[re: XRaySpeX] [link to this post]
 
Yeah, it seems just manually going in the registry and deleting it has done the trick and deleting the tempoary folder, why doesn't it look as if my Avira is on the ball?.
Standard User camieabz
(sensei) Sat 27-Apr-13 01:02:15
Print Post

Re: iehighutil.exe Virus:


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
Doesn't look like your Avira anti-virus is on the ball.


I don't think it has an AV signature, as it's utilising the GPU, and not the CPU. Perhaps the GPU kernel doesn't get monitored by security (no idea about AV security software heuristics).

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User tomxlisa
(member) Sat 27-Apr-13 01:03:14
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
Yeah i did see that, i've only just installed it, IE10 should be all up to date, very odd.
Standard User tomxlisa
(member) Sat 27-Apr-13 01:04:43
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
In Avira's defence i wasn't using this software when i got the virus, i was using microsoft security essentials, but not saying that Avira would of picked it up if i had of been using it though.
Standard User XRaySpeX
(eat-sleep-adslguide) Sat 27-Apr-13 01:12:07
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
In reply to a post by tomxlisa:
why doesn't it look as if my Avira is on the ball?.
Cuz it never discovered this virus at the time it installed itself or at least warned you.

@camieabz: I can't see that whether the virus uses the GPU rather than CPU makes any diff. It's still stored code that runs initially on CPU. It's up to the AV companies to recognise it in time, decide its sig and propagate updates.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User XRaySpeX
(eat-sleep-adslguide) Sat 27-Apr-13 01:16:33
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
In reply to a post by camieabz:
You do need to update IE10 though.
What is that referring to?

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User camieabz
(sensei) Sat 27-Apr-13 01:21:50
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Just spotted this:

http://processes.glarysoft.com/iehighutil.exe/17516/

People should be aware that this bitcoin miner also comes with a rootkit, so simply removing the files will not suffice! The rootkit typically associated is going by the name \"0Access\" or \"ZeroAccess\".


No idea if that's true or not (take all comments on such sites with a pinch of salt - I've seen valid processes declared as malware by people that don't know any better). If you have a rootkit scan feature, it might be worth a scan. It may be perfectly safe as it is, but added scans can't hurt.

You might want to consider updating your Java version, then disabling the jusched.exe (automatic update scheduler). My own experience of Java is that you learn you need an update when an applet doesn't work.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User camieabz
(sensei) Sat 27-Apr-13 01:22:15
Print Post

Re: iehighutil.exe Virus:


[re: XRaySpeX] [link to this post]
 
His hijack this log said it's out of date.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User tomxlisa
(member) Sat 27-Apr-13 01:48:36
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
Things look okay as they are but that doesn't look good, might be a format job then, unless i just see how it goes from now on as it does seem to have gone now, how do i do this rookkit scan, might be worth a go, i was deleting the file before and it was coming back but wasn't deleting it out of the registry, so maybe it won't come back now i've deleted it out the registry too.

Edited by tomxlisa (Sat 27-Apr-13 01:50:15)

Standard User 4M2
(fountain of knowledge) Sat 27-Apr-13 02:04:43
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Scanning with both http://www.surfright.nl/en/hitmanpro/ and malwarebytes (which you have used) usually get rid of most nasties...try not to do any more manual deleting before you scan with hitmanpro though...

Good luck smile
Standard User tomxlisa
(member) Sat 27-Apr-13 02:22:29
Print Post

Re: iehighutil.exe Virus:


[re: 4M2] [link to this post]
 
http://www.surfright.nl/en/hitmanpro/ didn't seem to find the virus, take it that is a good thing?.
Standard User 4M2
(fountain of knowledge) Sat 27-Apr-13 02:41:04
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Probably smile

I just ran hitmanpro and it found something suspicious on my XP machine: smab.dll in system 32, so stuck it in Kaspersky's quarantine for a while because my hitmanpro free license expired ages ago...
Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 12:33:22
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
In reply to a post by ukhardy07:
Kaspersky really misses most of the unusual stuff. I have links to an IT security firm and kaspersky just didn't do the job good enough.

And Avira and Norton doesn't????? Just what sort of security firm is this?
Please give examples of what Kaspersky misses that these two find..... Not forgetting particularly the former's propensity for false positives.
VirusTotal results.

Got a function?
We've got it covered!
Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 12:42:27
Print Post

Re: iehighutil.exe Virus:


[re: 4M2] [link to this post]
 
Smab.dll is almost certainly a legitimate file although of course any executable can be infected via a secondary source. Upload it to Jotti.

Got a function?
We've got it covered!
Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 12:44:05
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Did you scan the system with the aforementioned Kaspersky Rescue Disk?

Got a function?
We've got it covered!
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 19:22:14
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
Calm down I'm just going from experience

Offices have had viruses that kaspersky missed in the past.
I've seen it time and time again with kaspersky. So much so that I lack respect for the product.
It is also a hog on resources & likes to consume high CPU levels like Mcafee does too.

Install Avira / norton / malware bytes and its picked up in most situations

Every antivirus has its strengths and weaknesses however our provider is constantly blocking people from our corporate Internet network & 99.99999% of times it turns out they were infected but had kaspersky installed (as we give it out for free - soon to be changed).

Edited by ukhardy07 (Sat 27-Apr-13 19:22:51)

Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 19:42:14
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
Avira is pretty much useless and I have to say that recent experience in the real world shows that the Norton products are once more slipping back into insecurity.
I find your last statement to be incredulous unless of course your serverside security is provided by one of the well known FP generators such as Avira. Please give examples of what Kaspersky has supposedly missed and I'll take it up with K Labs.

Got a function?
We've got it covered!

Edited by Deadbeat (Sat 27-Apr-13 19:43:16)

Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 19:52:38
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
As I say it's something I've noticed over a couple of years.

Back in the conficker days kaspersky didn't keep up with the various variants of it. Sophos and Avira both found it at the time. Machines were still infected with Kaspersky installed

I'm honestly not bothered enough to talk any further... We all have our opinions lets call it a day at that.
I don't like kaspersky never have and never will.
Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 20:37:06
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
As I recall, in 2008, KLabs announced the detection of what they branded "Kido" and warned of increasing activity in the near future. I may be wrong but believe that they were the first to release a standalone removal tool.

Got a function?
We've got it covered!
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 22:11:53
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
Still didn't manage to remove it.
Standard User camieabz
(sensei) Sat 27-Apr-13 22:13:53
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
In reply to a post by ukhardy07:
never have and never will.


Never is a very long time.

I started with Norton. Changed to KIS and may change back at next subscription renewal. The products' features and drawbacks ebb and flow, as with any range of products by several manufacturers.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 22:36:06
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
In reply to a post by ukhardy07:
Still didn't manage to remove it.

It most certainly was and is capable of removing Conficker and it's variants but of course, if Kaspersky were already properly installed, it wouldn't have to have removed it as infection would have been prevented.
Of course there are those who, despite the sternest of warnings from whatever their security software, choose to circumvent it. No useable security solution can cater for the stupidity of users.

Got a function?
We've got it covered!
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 22:38:20
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
Ok fair play I probably would switch back at some point.
Bold statement from me there.
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 22:40:46
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
This was as conficker was active & changing.

Kaspersky was behind some of the newest variants (as we're most antivirus).
It said it was clean when it wasn't.
Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 22:41:11
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
I've been in the same frame of mind for a couple of years now but I can't really find anything that I'm comfortable with. I had been leaning toward the Norton/Symantec range but a few machines I've seen over the last couple of months have put me right off it. G-Data looked promising at one point but that seems to have gone backwards.
I think I'll be using KIS for as long as I can configure it to my purposes and not the vendors tastes. However, that does seem to be becoming more difficult with every release.

Got a function?
We've got it covered!

Edited by Deadbeat (Sat 27-Apr-13 22:50:52)

Standard User Deadbeat
(knowledge is power) Sat 27-Apr-13 22:47:46
Print Post

Re: iehighutil.exe Virus:


[re: ukhardy07] [link to this post]
 
Well, you were using a different Kaspersky to the one I and many others were. It was one of the few solutions that actively monitored and actually forecast the variants:
Kido
Kido.bt
Kido.dv
Kido.fx
Kido.ih
Kido.ir
Maybe you were running with heuristics disabled?

Anyway, this has gone far enough off topic. If you wish to discuss the shortcomings of various security solutions, feel free to start a new thread in the relevant section.

Got a function?
We've got it covered!

Edited by Deadbeat (Sat 27-Apr-13 22:49:25)

Standard User camieabz
(sensei) Sat 27-Apr-13 22:58:10
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
Jan 2014 until I renew (two year sub).

Not happy with KIS and FF incompatibilities (URL advisor, anti-banner, virtual KB). Both blame each other.

Also, I don't care for KIS's default state in a license issue to be 'unprotected'. With Norton, it at least stayed protected to the last update.

I'll start looking around December, and might consider others too. AV Comparatives and top-ten reviews will be first points of call.

~ Camieabz ~

All Connection Data ~ Some plusnet links

I've forgotten more about broadband than I care to remember.
Standard User ukhardy07
(fountain of knowledge) Sat 27-Apr-13 23:04:59
Print Post

Re: iehighutil.exe Virus:


[re: Deadbeat] [link to this post]
 
It was the one used in business not commercial so not sure about heuristics
Standard User Pipexer
(eat-sleep-adslguide) Sun 28-Apr-13 00:33:54
Print Post

Re: iehighutil.exe Virus:


[re: camieabz] [link to this post]
 
Sunbelt VIPRE is probably my first recommendation for those paranoid about security and associated threats. Lightweight antivirus yet including very good anti malware capability.

Personally, I use Windows Defender (built in) on my Windows 8 machines and system center endpoint protection on my non-Windows 8 machines. (i.e., security essentials if you like)

Zen 8000 Pro
Standard User deleted
(deleted) Sun 28-Apr-13 19:10:16
Print Post

Re: iehighutil.exe Virus:


[re: tomxlisa] [link to this post]
 
Try this.

1. Use Tune Up 2010 - 2013.
2. Open configure system start.
3. Turn off iehighutil.exe
4. Delete iehighutil.exe in system start.
5. Open Manage running programs.
6. Terminate process iehighutil.exe
7. Close Tune Up.
8. Open C:
9. Delete C:\Temporary
10. C:\Temporary\iehighutil.exe should now be deleted.
11. You can now empty the Trash.
Standard User tomxlisa
(member) Mon 13-May-13 11:13:15
Print Post

Re: iehighutil.exe Virus: [Update]


[re: deleted] [link to this post]
 
Just noticed that this virus seems to be back on my computer, any ideas what to do next?.
Pages in this thread: 1 | 2 | 3 | 4 | 5 | 6 | 7 | >> (show all)   Print Thread

Jump to