Syndic8 Yahoo Browser Hijack - Virus, Trojan, Spyware, and Malware Removal Help
Common Information
Type Value
UUID 67951ee5-158e-4f34-94f6-5e1c431b9069
Fingerprint 37502a1072ceefc7
Analysis status DONE
Considered CTI value 2
Text language
Published July 27, 2023, 2:49 p.m.
Added to db July 27, 2023, 9:59 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Syndic8 Yahoo Browser Hijack
Title Syndic8 Yahoo Browser Hijack - Virus, Trojan, Spyware, and Malware Removal Help
Detected Hints/Tags/Attributes 98/3/312
Attributes
Details Type #Events CTI Value
Details Domain 2
microsoft.management.services
Details Domain 285
microsoft.net
Details Domain 1
me.blueone.win
Details Domain 1
app.fflboss.com
Details Domain 1
texas-foodstamps.org
Details Domain 1
www.share-games.com
Details Domain 1
www.urbanoutfitters.com
Details Domain 1373
twitter.com
Details Domain 295
amazon.com
Details Domain 1
crxupdate.com
Details Domain 368
microsoft.com
Details Domain 1
glance.net
Details Domain 1
images-20230629t042242z-001.zip
Details Domain 87
regid.1991-06.com.microsoft
Details Domain 24
microsoft.windows.photos
Details Domain 50
microsoft.photos
Details Domain 8
on2.com
Details Domain 10
mbam.zone
Details Domain 19
sharepoint.com
Details Domain 1
pisd-files.sharepoint.com
Details Domain 1
bin.net
Details File 2
c:\users\user\downloads\frst64.exe
Details File 1
bluemail.exe
Details File 1260
explorer.exe
Details File 6
applemobiledeviceprocess.exe
Details File 1
qbwebconnector.exe
Details File 127
c:\windows\system32\rundll32.exe
Details File 15
c:\program files\realtek\audio\hda\rtkngui64.exe
Details File 35
googlecrashhandler.exe
Details File 33
googlecrashhandler64.exe
Details File 128
msedge.exe
Details File 8
c:\windows\system32\musnotifyicon.exe
Details File 16
c:\program files\ccleaner\ccleaner64.exe
Details File 1
fufaxrcv.exe
Details File 1
fufaxstm.exe
Details File 306
services.exe
Details File 1
intunewindowsagent.exe
Details File 9
smsvchost.exe
Details File 198
msmpeng.exe
Details File 87
nissrv.exe
Details File 1122
svchost.exe
Details File 49
c:\windows\immersivecontrolpanel\systemsettings.exe
Details File 85
c:\windows\system32\dllhost.exe
Details File 67
c:\windows\system32\smartscreen.exe
Details File 1
c:\program files\minitool shadowmaker\smmonitor.exe
Details File 1
c:\users\user\appdata\local\vipre\setup\cartsdk\sbrc.exe
Details File 2
c:\users\user\appdata\local\microsoft\teams\update.exe
Details File 1
c:\users\user\appdata\local\webex\webexhost.exe
Details File 99
c:\windows\explorer.exe
Details File 1
c:\windows\system32\e_ylmbkde.dll
Details File 8
c:\windows\system32\enppmon.dll
Details File 1
c:\windows\system32\hpinkstsbe2alm.dll
Details File 61
chrmstp.exe
Details File 2
intuitdataprotect.exe
Details File 12
qbupdate.exe
Details File 19
qbw32.exe
Details File 2
c:\program files\microsoft office\office15\onenotem.exe
Details File 42
adobearm.exe
Details File 12
watchdog.exe
Details File 17
c:\program files\ccleaner\ccupdate.exe
Details File 14
c:\program files\ccleaner\ccleanerbugreport.exe
Details File 15
c:\program files\ccleaner\ccleaner.exe
Details File 105
googleupdate.exe
Details File 1
c:\program files\hp\hp laserjet m14-m17\bin\hpcustpartic.exe
Details File 1
clienthealtheval.exe
Details File 2
c:\program files\common files\microsoft shared\office15\olicenseheartbeat.exe
Details File 2
c:\program files\microsoft office\office15\msoia.exe
Details File 2
c:\windows\system32\deviceenroller.exe
Details File 2
c:\windows\system32\omadmclient.exe
Details File 1
c:\windows\system32\edpcleanup.exe
Details File 97
mpcmdrun.exe
Details File 6
scheduler.exe
Details File 1
updates.php
Details File 16
npspwrap.dll
Details File 19
c:\program files\adobe\acrobat dc\acrobat\air\nppdf32.dll
Details File 1
npglance.dll
Details File 6
npmeetingjoinpluginoc.dll
Details File 38
armsvc.exe
Details File 6
c:\program files\ccleaner\ccleanerperformanceoptimizerservice.exe
Details File 2
pmaservice.exe
Details File 7
c:\windows\system32\escsvc64.exe
Details File 2
c:\program files\minitool shadowmaker\agentservice.exe
Details File 2
c:\program files\minitool shadowmaker\schedulerservice.exe
Details File 2
fcs.exe
Details File 38
c:\program files\windows defender advanced threat protection\mssense.exe
Details File 7
c:\program files\teamviewer\teamviewer_service.exe
Details File 1
usbappcontrol.exe
Details File 1
workflowappcontrol.exe
Details File 15
c:\windows\system32\drivers\applekmdffilter.sys
Details File 15
c:\windows\system32\drivers\ssudbus2.sys
Details File 5
c:\windows\system32\driverstore\filerepository\e1d.inf
Details File 5
e1d.sys
Details File 4
c:\windows\system32\drivers\netaapl64.sys
Details File 1
c:\windows\system32\prwntdrv.sys
Details File 2
c:\windows\system32\pwdrvio.sys
Details File 2
c:\windows\system32\pwdspio.sys
Details File 1
c:\windows\system32\drivers\sctdriverv1011.sys
Details File 3
c:\windows\system32\drivers\sivx64.sys
Details File 12
c:\windows\system32\drivers\ssudmdm.sys
Details File 8
c:\windows\system32\drivers\ss_conn_usb_driver2.sys
Details File 5
c:\windows\system32\drivers\vbaudio_vmvaio64_win10.sys
Details File 70
c:\windows\system32\drivers\wd\wdboot.sys
Details File 70
c:\windows\system32\drivers\wd\wdfilter.sys
Details File 70
c:\windows\system32\drivers\wd\wdnisdrv.sys
Details File 1
applelowerfilter.sys
Details File 1
c:\users\user\downloads\156127945109.jpeg
Details File 1
c:\users\user\downloads\frst.txt
Details File 1
c:\frst 2023-07-27 01:02 - 2023-07-27 01:02 - 000001268 _____ c:\windows\system32\serviceconfig.xml
Details File 7
v2.bin
Details File 1
c:\users\user\appdata\local\bitdefender 2023-07-27 00:27 - 2023-07-27 00:27 - 027157968 _____ c:\users\user\downloads\bitdefender_2023_uninstall_tool.exe
Details File 1
c:\users\user\downloads\bobbie3.pdf
Details File 1
c:\users\user\downloads\bobbie2.pdf
Details File 1
c:\programdata\bdlogging 2023-07-26 23:39 - 2023-07-26 23:39 - 000000391 _____ c:\windows\system32\sbrc.dat
Details File 1
c:\users\user\downloads\superantispyware.exe
Details File 1
c:\users\user\downloads\vipre-advanced-security-trial.exe
Details File 1
c:\users\user\downloads\360ts_setup_mini.exe
Details File 1
c:\windows\system32\httpproxy.json
Details File 2
c:\windows\system32\ctc.json
Details File 1
c:\windows\system32\caad.db
Details File 1
c:\users\user\downloads\bitdefender_avfree.exe
Details File 1
c:\users\user\desktop\rkill.txt
Details File 1
c:\users\user\desktop\jrt.txt
Details File 1
c:\users\user\downloads\blitzblank.exe
Details File 1
c:\users\user\downloads\jrt.exe
Details File 1
c:\users\user\downloads\minitoolbox.exe
Details File 2
c:\users\user\downloads\rkill.exe
Details File 1
c:\users\user\downloads\ffl-list.xls
Details File 1
c:\users\user\downloads\0511-ffl-list-texas.xls
Details File 1
c:\users\user\downloads\web images-20230629t042242z-001.zip
Details File 1
c:\users\user\downloads\flexfit_2023-catalog_v4_digital-small.pdf
Details File 1
c:\windows\system32\drivers\wd 2023-07-27 00:34 - 2019-12-07 04:03 - 000000000 ____d c:\windows\cbstemp 2023-07-27 00:28 - 2019-12-07 04:13 - 000000000 ____d c:\windows\inf 2023-07-27 00:16 - 2021-06-28 03:39 - 000971870 _____ c:\windows\system32\perfstringbackup.ini
Details File 1
c:\users\user\appdata\roaming\qtproject 2023-07-27 00:11 - 2020-11-09 09:42 - 000000000 ____d c:\users\user\appdata\roaming\microsoft\teams 2023-07-27 00:09 - 2021-06-28 03:40 - 000000006 ____h c:\windows\tasks\sa.dat
Details File 38
c:\dumpstack.log
Details File 6
c:\windows\system32\mpsigstub.exe
Details File 24
c:\windows\system32\fntcache.dat
Details File 54
c:\windows\syswow64\printconfig.dll
Details File 1
c:\programdata\microsoft\windows\start menu\programs\microsoft office 2013 2023-07-12 12:03 - 2018-09-15 02:31 - 000000167 _____ c:\windows\win.ini
Details File 59
c:\windows\system32\mrt.exe
Details File 1
c:\users\user\appdata\roaming\jolly.log
Details File 1
c:\users\user\appdata\roaming\vidiot.ini
Details File 1
c:\users\user\appdata\roaming\voicemeeterdefault.xml
Details File 86
frst.txt
Details File 70
onedrivesetup.exe
Details File 34
win.rar
Details File 2
c:\program files\windowsapps\21336v3tapps.mov
Details File 6
c:\program files\adobe\acrobat dc\acrobat\adnotificationmanager.exe
Details File 13
addinloader.dll
Details File 1
grammarlyshim64.dll
Details File 1
c:\users\user\appdata\local\webex\webex64\meetings\atucfobj.dll
Details File 1
activex.dll
Details File 2
c:\users\user\appdata\local\microsoft\teams\current\teams.exe
Details File 19
c:\program files\winrar\rarext.dll
Details File 19
c:\program files\winrar\rarext32.dll
Details File 9
c:\windows\system32\igfxdtcm.dll
Details File 7
c:\windows\syswow64\vp6vfw.dll
Details File 1
ebpd4fax.dll
Details File 1
fuadrfil.dll
Details File 1
fufaxcfg.dll
Details File 1
fufaxcsr.dll
Details File 1
fufaxldb.dll
Details File 1
fufaxtif.dll
Details File 1
fuimgcdc.dll
Details File 1
fulepp.dll
Details File 1
fustmmsg.dll
Details File 1
fusvcclt.dll
Details File 1
fuusbhlp.dll
Details File 1
fuverdlg.dll
Details File 1
fudevcom.dll
Details File 1
fudrvutl.dll
Details File 1
fuprbdev.dll
Details File 1
fusnmput.dll
Details File 1
fucmnmsg.dll
Details File 1
fufaxcfgres.dll
Details File 1
fufaxrcv.dll
Details File 1
fufaxstm.dll
Details File 1
fuleppres.dll
Details File 1
fuprbdevres.dll
Details File 1
encm.dll
Details File 1
ennw.dll
Details File 1
enutil.dll
Details File 1
c:\program files\minitool shadowmaker\bearer\qgenericbearer.dll
Details File 1
c:\program files\minitool shadowmaker\bearer\qnativewifibearer.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qgif.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qicns.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qico.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qjpeg.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qsvg.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qtga.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qtiff.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qwbmp.dll
Details File 1
c:\program files\minitool shadowmaker\imageformats\qwebp.dll
Details File 1
c:\program files\minitool shadowmaker\platforms\qwindows.dll
Details File 1
c:\program files\minitool shadowmaker\qt5svg.dll
Details File 1
c:\users\user\downloads\bitdefender_2023_uninstall_tool.exe
Details File 1
c:\program files\microsoft office\office15\ochelper.dll
Details File 1
c:\program files\microsoft office\office15\grooveex.dll
Details File 10
ochelper.dll
Details File 3
grooveex.dll
Details File 1
helpasyncpluggableprotocol.dll
Details File 2
c:\program files\microsoft office\office15\msosb.dll
Details File 4
c:\windows\syswow64\mscoree.dll
Details File 92
c:\windows\system32\svchost.exe
Details File 87
skype.exe
Details File 2
c:\program files\microsoft office\office15\ucmapi.exe
Details File 3
c:\program files\microsoft office\office15\lync.exe
Details File 1
c:\program files\hp\hp laserjet m14-m17\bin\hpnetworkcommunicatorcom.exe
Details File 1
c:\program files\hp\hp laserjet m14-m17\bin\devicesetup.exe
Details File 1
c:\program files\hp\hp laserjet m14-m17\bin\ewsproxy.exe
Details File 1
vban2midi.exe
Details File 2
ts4.exe
Details File 2
ts4_x64.exe
Details File 1
zebraproxy3.exe
Details File 8
itunes.exe
Details File 76
msedgewebview2.exe
Details File 6
c:\program files\teamviewer\teamviewer.exe
Details File 271
chrome.exe
Details File 1
c:\windows\system32\drivers\etc\hosts detection origin: local machine detection type: concrete detection source: real-time protection process name: c:\users\user\appdata\local\microsoft\teams\current\teams.exe
Details File 5
antimalware_provider64.dll
Details File 91
addition.txt
Details sha1 1
321e9c3b7c8e360b434912ed44cc222f08280048
Details sha1 1
018b67599606f0589ea4ca42ad4cc6b5c24388a0
Details sha1 1
4465e01c1ed0ae4228c3e5242c6c686557088ca7
Details IPv4 1
27.0.1.254
Details IPv4 6
75.75.75.75
Details IPv4 4
75.75.76.76
Details IPv4 1
10.5.0.74
Details IPv4 10
1.0.2.0
Details IPv4 4
3.1.4.0
Details IPv4 1
4.2.0.38
Details IPv4 1
2.0.30.1
Details IPv4 8
2.5.8.0
Details IPv4 1
120.7.3.55
Details IPv4 1
3.9.9.57
Details IPv4 1
3.9.9.69
Details IPv4 1
1.53.204.0
Details IPv4 12
3.72.0.0
Details IPv4 10
1.4.0.0
Details IPv4 3
1.4.0.7
Details IPv4 24
1.0.1.0
Details IPv4 109
1.0.0.0
Details IPv4 1441
127.0.0.1
Details IPv4 31
2.0.0.0
Details Microsoft Patch Numbers 2
KB2850036
Details Microsoft Patch Numbers 2
KB4484289
Details Url 1
https://app.fflboss.com/login
Details Url 1
https://texas-foodstamps.org
Details Url 1
https://www.share-games.com
Details Url 1
https://www.urbanoutfitters.com
Details Url 24
https://twitter.com
Details Url 1
https://crxupdate.com/crx/updates.php
Details Url 1
https://pisd-files.sharepoint.com
Details Url 2
https://go.microsoft.com/fwlink/?linkid=37020&name=settingsmodifier:win32
Details Windows Registry Key 68
HKLM\...\Run
Details Windows Registry Key 50
HKLM-x32\...\Run
Details Windows Registry Key 4
HKLM\...\Policies\Explorer
Details Windows Registry Key 44
HKLM\SOFTWARE\Policies\Microsoft\Windows
Details Windows Registry Key 8
HKLM\Software\Policies\...\system
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\Run
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\Policies\Explorer
Details Windows Registry Key 12
HKLM\...\Print\Monitors\EPSON
Details Windows Registry Key 7
HKLM\...\Print\Monitors\EpsonNet
Details Windows Registry Key 10
HKLM\...\Print\Monitors\HP
Details Windows Registry Key 59
HKLM\Software\Microsoft\Active
Details Windows Registry Key 10
HKLM\SOFTWARE\Policies\Google
Details Windows Registry Key 14
HKLM\SOFTWARE\Policies\Microsoft\Edge
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001
Details Windows Registry Key 4
HKLM\...\Edge\Extension
Details Windows Registry Key 19
HKLM-x32\...\Edge\Extension
Details Windows Registry Key 18
HKLM\...\Chrome\Extension
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension
Details Windows Registry Key 39
HKLM-x32\...\Chrome\Extension
Details Windows Registry Key 77
HKLM-x32
Details Windows Registry Key 5
HKLM-x32\...\Audacity_is1
Details Windows Registry Key 16
HKLM\...\CCleaner
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\ActiveTouchMeetingClient
Details Windows Registry Key 1
HKLM-x32\...\Collagerator_is1
Details Windows Registry Key 4
HKLM-x32\...\EaseUS
Details Windows Registry Key 7
HKLM-x32\...\EPSON
Details Windows Registry Key 12
HKLM\...\EPSON
Details Windows Registry Key 55
HKLM-x32\...\Google
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\GrammarlyForWindows
Details Windows Registry Key 3
HKLM-x32\...\ImgBurn
Details Windows Registry Key 2
HKLM-x32\...\LAME_is1
Details Windows Registry Key 1
HKLM-x32\...\MediaHuman
Details Windows Registry Key 68
HKLM-x32\...\Microsoft
Details Windows Registry Key 1
HKLM\...\Office15.PROPLUSR
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\OneDriveSetup.exe
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\Teams
Details Windows Registry Key 10
HKLM\...\Microsoft
Details Windows Registry Key 2
HKLM-x32\...\MT-75D7C412-925B-4AD0-90DC-5E4FEE22EAE1_is1
Details Windows Registry Key 1
HKLM-x32\...\NAPS2
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\roblox-player
Details Windows Registry Key 2
HKLM-x32\...\SeaTools
Details Windows Registry Key 1
HKLM-x32\...\Shotcut
Details Windows Registry Key 6
HKLM\...\TeamViewer
Details Windows Registry Key 2
HKLM-x32\...\VB
Details Windows Registry Key 1
HKLM-x32\...\WeblinkDesktop
Details Windows Registry Key 1
HKLM\...\321E9C3B7C8E360B434912ED44CC222F08280048
Details Windows Registry Key 1
HKLM\...\018B67599606F0589EA4CA42AD4CC6B5C24388A0
Details Windows Registry Key 1
HKLM\...\4465E01C1ED0AE4228C3E5242C6C686557088CA7
Details Windows Registry Key 30
HKLM\...\WinRAR
Details Windows Registry Key 1
HKLM-x32\...\ZebraDesigner
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001_Classes\CLSID
Details Windows Registry Key 16
HKLM\...\Drivers32
Details Windows Registry Key 16
HKLM\Software\Microsoft\Internet
Details Windows Registry Key 14
HKLM\Software\Wow6432Node\Microsoft\Internet
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\sharepoint.com
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\Control
Details Windows Registry Key 98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Details Windows Registry Key 15
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\StartupApproved\StartupFolder
Details Windows Registry Key 1
HKU\S-1-5-21-2425515040-3522767705-525624033-1001\...\StartupApproved\Run