It is currently Tue Sep 01, 2026 3:22 pm


Can't get rid of adware / dialer ...please help!

All versions of Window XP and 2003 including 32 bit and 64 bit

Moderator: icecube

Can't get rid of adware / dialer ...please help!

Postby dk » Wed Jun 30, 2004 1:24 pm

Hello - Sorry for the looonnnnggg post but I hope someone here can help me with this...

Our laptop was recently "invaded" by one of those annoying porn dialers..
It installed itself and automatically switched the connection to an expensive premium-rate line.

We used Spybot S&D to remove it, and even deleted the backups... But now,
whenever we connect to the internet after just a few minutes the same
pop-up appears and we're redirected to the same porn site!

We keep removing it with Spybot S&D and Ad-Aware but just can't seem to get rid of it permenantly!

Also, since this has happened, whenever we try to connect to the net we
can now no longer hear the dial-up...
The telephone number displayed in the dial-up box is the correct number for our ISP,
but whereas we used to hear the dial-tone (followed by the sound of a 'phone dialling the number,
followed by the familiar gurgling noise of the computer connecting to the net etc)
- now it is silent...

I've checked all the volume settings (including the volume setting in 'Modems' in the control
panel) and everything's turned right up.
I can only assume this is a symptom of the porn/adware thing to disguise the fact it's
actually dialling the wrong number (ie it's own premium rate line).

If anyone can suggest anhything else we could try to permantantly get rid of this problem,
I'd be most grateful.

Many, Many thanks in advance,
K.

Also, if it's any help, we ran HiJack This - the log is below:

Logfile of HijackThis v1.97.7
Scan saved at 12:42:53, on 30/06/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\AMD\POWERNOW!\GEMBACK.EXE
C:\PROGRAM FILES\AMD\PCTBACK\PCTBACK.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SHMAN.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\PEERGUARDIAN PR14\PEERGUARDIAN_1.99B_PR14.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\UNZIPPED\HIJACKTHIS_1.97.7\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://1-se.com/home.html (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pureseeker.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://1-se.com/home.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://1-se.com/home.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\homepage.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://1-se.com/home.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://1-se.com/home.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [AMD PowerNow!] "C:\Program Files\AMD\PowerNow!\GemBack.exe"
O4 - HKLM\..\Run: [PCTBackEXE] "C:\Program Files\AMD\PCTBack\PCTBack.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Windows Shell Library Loader] load shell.dll /c /set
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [NAVCheck] C:\WINDOWS\shman.exe /i
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O14 - IERESET.INF: START_PAGE_URL=http://portal.plus.net/
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
User avatar
dk
Newbie
Newbie
 
Posts: 4
Joined: Wed Jun 30, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Wed Jun 30, 2004 6:13 pm

After you've finished fixing this problem I strongly recommend that you visit the and download the Critical Updates.

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

Turn off the “[u]GoBack” Program if it is installed.)
Close all other open Windows and have HiJackThis Fix:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://1-se.com/home.html (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pureseeker.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://1-se.com/home.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://1-se.com/home.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\homepage.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://1-se.com/home.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://1-se.com/home.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
O4 - HKLM\..\Run: [Windows Shell Library Loader] load shell.dll /c /set
O14 - IERESET.INF: START_PAGE_URL=http://portal.plus.net/

Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby dk » Wed Jun 30, 2004 11:49 pm

Thanks for the reply Brad,

Should I just delete everything in the TEMP folder? Or just the individual files? (my TEMP folder seems to contain a few more folders within it) - and there were some .tmp files which I couldn't delete for some reason..

...I removed what you suggested using HiJack This... Unfortunately the problem with there being no sound when I dial-up persists... And I'd only been online for a minute or so when the dreaded porn pop-up returned, causing exactly the same problem as before! (re-conecting me to an expensive premium rate line)

Is there anything else I can try to get rid of this problem??

Will downloading the critical updates do anything to stop this.. or should I wait until after this problem is cleared up before I download them?

Sorry for the nagging questions... thanks for your time, it's very much appreciated..

x
User avatar
dk
Newbie
Newbie
 
Posts: 4
Joined: Wed Jun 30, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jul 01, 2004 12:41 am

Do all of this in "Safe Mode".
You can delete the whole darn folder, if your machine will let you, (Windows will replace it on the next boot) otherwise, delete everything in it.
Let's fix your current problems first. We'll deal with your Modem sounds after your Computer is "clean".
Post a fresh HJT Log File.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby dk » Fri Jul 02, 2004 2:46 am

OK, I've deleted the temp folder (in safe mode)...
Here's the new HJThis log:



Logfile of HijackThis v1.97.7
Scan saved at 02:42:17, on 02/07/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\AMD\POWERNOW!\GEMBACK.EXE
C:\PROGRAM FILES\AMD\PCTBACK\PCTBACK.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\UNZIPPED\HIJACKTHIS_1.97.7\HIJACKTHIS.EXE

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [AMD PowerNow!] "C:\Program Files\AMD\PowerNow!\GemBack.exe"
O4 - HKLM\..\Run: [PCTBackEXE] "C:\Program Files\AMD\PCTBack\PCTBack.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
User avatar
dk
Newbie
Newbie
 
Posts: 4
Joined: Wed Jun 30, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Fri Jul 02, 2004 7:37 am

Looks really good. Are you having any problems?
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby dk » Fri Jul 02, 2004 10:44 pm

Everything seems to be ok at the moment,
except that Spybot S&D's browser-helper keeps warning me that I'm "trying to download 'Avenue A Inc', this is a known threat"

This warning pops up every time I visit a new webpage (Yahoo, various forums etc) ... I can block the download with S&D's Browser-helper but I'm wondering why this is happening now?

thanks for helping us out with all this, Brad.. it's very much appreciated!
User avatar
dk
Newbie
Newbie
 
Posts: 4
Joined: Wed Jun 30, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Fri Jul 02, 2004 10:50 pm

Well, yes. It's a HiJacker. You could allow it but you'll just have to clean it out later. I do.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top


Return to Windows XP and 2003

Who is online

Users browsing this forum: No registered users and 1 guest

cron