Dialer-257 (Please Help Me)

Discussion in 'Malware Help (A Specialist Will Reply)' started by eagles2880, Dec 27, 2005.

  1. eagles2880

    eagles2880 Private E-2

    Hello. I guess I should start out by saying that this is my first post here so if I'm doing anything wrong please tell me and I'll be happy to fix it. I would just really like to solve this problem and I'm sure you guys would be able to help me. So here it goes.

    Sometime late last night McAfee popped up while I was browsing the web when it detected potential viruses and spyware. When something like this happens, which isn't very often, it usually takes care of this problem right away but this time it was unable to clean the virus so it moved it instead. McAfee identified it as a Dialer-257 (and I have no idea what that means). Also, when my computer first starts up I receive a pop-up message identical to the one in the previous instance of Dialer-257 on this forum posted by renasci. Other than these two things, my computer does not show any other signs of being infected.

    I don't know much about computers but I know enough to realize that there is now something wrong with my system. I searched the internet for some help and found a good starting point here. The previous thread on this website started by renasci presented a problem extremely similar to mine. In fact, identical as far as I can tell. I read through that for some insight and performed all of the tasks that were suggested in the "READ AND RUN ME FIRST" thread. Just as it had not with the previous instance of this problem, it did not take care of mine.

    This is what I have for you so far: Ccleaner apparently made a couple fixes but I'm pretty sure it was nothing significant. Ad-Aware SE and Spybot were kind of useless. Bitdefender and Panda ActiveScan were at least able to confirm that there was something wrong with my computer but they didn't do anything to fix it. The logs for these two scans, as well as a HijackThis log are attached to this post...hopefully.

    So as I said, I feel as if I have already done all that I can on my own but with your help we should be able to take care of this thing. If there is any additional information you need to help me solve this problem please let me know and I will get back to you with it as soon as possible. I intend on checking the thread frequently to get this problem fixed as quickly as possible. Thanks in advance for all of your help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use a LinkSys piece of hardware that the below would be related too?

    C:\Linksys Driver\Wusb11v2.5 Driver 072002\Utility\data1.cab[WUSB11Cfg.exe]
    C:\Program Files\LINKSYS\WUSB11 v25 Config Utility\WUSB11Cfg.exe

    These are probably a false positive.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way Welcome to MG's (and a fellow New Jersian :) )

    You forgot to use the link given in the READ ME to convert the BitDefender log into a text file. What you posted was raw HTML code saved into a text file. Take a look. Don't worry about it right now. I can view it anyway.

    Can you see the below file?
    C:\WINDOWS\SYSTEM32\BUM501.EXE

    Can you delete it?

    You also need to post you HJT log from normal boot mode, not safe mode. And per the HJT instructions in the step 7 you must not use msconfig to block items from loading.
    See this line in your log:
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    Please follow the dircections to get a proper HJT log an attach it.
     
  4. eagles2880

    eagles2880 Private E-2

    Yes, my computer uses LinkSys to send and receive internet access when I'm at home. It is not used at school but I leave the software installed for convenience so I don't need to reinstall it every time I come home for break. I don't know about those specific paths you pointed out but if I were to guess I would say that they are probably okay.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! See message # 3 and also answer the below.

    Do you know what this next line is for? Seems suspicious!
    O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\system32\private.exe internat.dll,LoadMouseCarpetProfile
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Darn you have a bunch of unusual stuff. Do you recognize the below:

    O4 - HKLM\..\Run: [NAVNet] "C:\WINDOWS\system32\voi973.exe" /m

    Is this something for GPS? It also seems suspicious.

    I have found othe problems that must be fixed but I'm first collecting all the info I need to give you a full fix.
     
  7. eagles2880

    eagles2880 Private E-2

    Okay I'm back in Normal Mode now. First of all I just want to say that my computer is really scary now. The background is changed to a warning that I have spyware (did one of the scans I ran do this?), I'm getting more some more pop-ups, and some program called WinHound just sprung out to clean out Spyware but I've never heard of this program in my life. I just wanted to tell you that I was able to delete that file you asked me to.

    "Can you see the below file?
    C:\WINDOWS\SYSTEM32\BUM501.EXE

    Can you delete it?"

    I'm gonna get to the HJT scan right now. For your most recent post...I do not know what that particular entry is for. But like I said, I'm not great with computers so there is probably a lot of stuff I don't know about. I'll get back to you soon.
     
  8. eagles2880

    eagles2880 Private E-2

    Okay and it's randomly adding new sites to my Favorites. I really need to get back into Safe Mode quick!!!
     
  9. eagles2880

    eagles2880 Private E-2

    Here is the new HJT logfile and I hope to God that I did it right this time.

    I do not recognize "O4 - HKLM\..\Run: [NAVNet] "C:\WINDOWS\system32\voi973.exe" /m" either.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! All hell has broken loose. You have a bunch of different issues. One of them is a nasty HSA hijacker. Let's se if we can make a little progress while I look at the rest of your log.

    Please download About:Buster and follow directions for using it on the download page. This means it should be run twice. Afterwards come back here and post the logs from it.
     
  11. eagles2880

    eagles2880 Private E-2

    Safe Mode sounds good to me. I'm scared to go back to normal until this problem is somewhat rectified. This seems to have taken a turn for the worse. Can you give me some confidence that this can be saved?! Haha. I ran that program you suggested and the log is attached. Please get back to me when you can.

    Woops almost forgot to run it twice. I'm a little on edge right now. The logfile should be what you want now. I believe nothing was detected in the second scan which may be a good sign.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry we will get it fixed! Just be patient and only follow the steps I give you. Don't do anything else. Also after posting HJT logs it will be important that you do not power down or reboot your PC or the problems could mutate or spread. So only power down or reboot if I specifically tell you to.

    That log from AB looks like you only ran it once. Run it again and post another log. It is fixing some problems. I want to see if it keeps finding any.
     
  13. eagles2880

    eagles2880 Private E-2

    Yes I originally ran it only once. Then I tried to edit my post and change the attachment to the new log file with two runs. I might have messed that up by mistake. By now I have run it about 4 times just for self-reassurance so this should be right this time.

    And don't worry I have no intention of playing around with this myself. Especially no reboots or changes back into Normal Mode. Normal Mode scares the hell out of me right now, lol.

    So what's next? :)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also please post a new HJT log after running AB again. I'm then going to start giving you steps to work on directly removing any remaining problems. Just in case we need it (and we often do) I want you to download and extract to its own folder the following tool: Pocket KillBox

    Don't run it yet. Just have it ready to go if I ask you to run it. It is used to delete stubborn files by putting them into a queue which is removed upon reboots.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will have to reboot into normal mode so make sure you read my directions carefully. There will be words like "reboot into normal mode" . When you see that, you must reboot in normal mode.
     
  16. eagles2880

    eagles2880 Private E-2

    Do I have to go back into Normal Mode to get the new HJT log? I was hoping I could avoid Normal Mode. I feel like my problems multiply for every second I'm there. But I'll do it if I must! I'm downloading that program now.

    Okay we were posting at the same time, lol. Got it. Back to normal mode I go.
     
  17. eagles2880

    eagles2880 Private E-2

    I am back to Normal Mode and things are looking slightly better. I'm back to a Blue desktop instead of the crazy screen that tells me my computer is infected. The SpyHound program or whatever it was opened up so I closed it out. Other than that nothing suspicious yet. No Pop-ups and no Virus warnings from McAfee and I've been in Normal Mode for a couple of minutes now. What's next?

    Oh my God, I totally forgot that you told me to get the new log. My brain has turned to mush under all of this stress, lol. I'll get that for you right now and get back to you!
     
  18. eagles2880

    eagles2880 Private E-2

    Here is the new HJT log taken from Normal Mode. Am I doing these logs right for you? I just noticed that there was a drop down menu for "Encoding" when I went to save so I just used the default option. NOW what's next? I was jumping the gun before and getting ahead of myself, lol.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'm going to start working up the remaining fix now. While I do that you should goto Add/Remove programs and uninstall any of the below that you find:
    Viewpoint or Viewpoint Manager
    WinHound
     
  20. eagles2880

    eagles2880 Private E-2

    I deleted WinHound and Viewpoint Manager as you said. Also Viewpoint Media Player just to be safe. I don't know, it seemed like the right thing to do. Even if it wasn't corrupt I never heard of the thing and sure won't miss it. Does this mean we're coming close to a conclusion or is this just the calm before the storm? Haha.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All the Viewpoint stuff is garbage from AOL that they install without asking you. No one uses or need it. Anytime you install anything from AOL (their online stuff or AIM) you will get this junk. And you can always just uninstall again.

    Almost there!!!!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: AdBlock APToolBarHelper Class - {54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E} - C:\WINDOWS\Downloaded Program Files\APHelper.dll
    O2 - BHO: Class - {64B4C959-F47C-E57E-A0E5-F99C903141A2} - C:\WINDOWS\system32\javabi.dll (file missing)
    O2 - BHO: Class - {A3E8BBF8-81F7-DEB8-824C-AF76F0A72CC3} - C:\WINDOWS\system32\sdkex32.dll (file missing)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [rscn] C:\WINDOWS\system32\bum501.exe ymmud
    O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\system32\private.exe internat.dll,LoadMouseCarpetProfile
    O4 - HKLM\..\Run: [NAVNet] "C:\WINDOWS\system32\voi973.exe" /m
    O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
    O4 - HKLM\..\Run: [15.tmp] C:\DOCUME~1\Greg\LOCALS~1\Temp\15.tmp.exe
    O4 - HKLM\..\Run: [14.tmp] C:\DOCUME~1\Greg\LOCALS~1\Temp\14.tmp.exe
    O4 - HKLM\..\Run: [WinHound] C:\Program Files\WinHound\WinHound.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O9 - Extra button: AdBlock - {7E34CCAC-2531-450E-8746-80DA107ADAF5} - C:\WINDOWS\Downloaded Program Files\APHelper.dll
    O9 - Extra button: (no name) - {D1E435DB-EE0C-4A71-84A8-A270F03B3EE7} - C:\WINDOWS\Downloaded Program Files\APHelper.dll
    O9 - Extra 'Tools' menuitem: AdBlock Configuration - {D1E435DB-EE0C-4A71-84A8-A270F03B3EE7} - C:\WINDOWS\Downloaded Program Files\APHelper.dll
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {93829908-07C2-44A2-95DB-F78F201A9B48} (AdBlock APInstaller Class) - http://adblock.linkz.com/APHelper.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (some may not be found):
    C:\Program Files\WinHound <--- the whole folder
    C:\Program Files\AWS <--- the whole folder
    C:\Documents and Settings\Greg\Local Settings\Temp\15.tmp.exe <-- in fact delete all file in this Temp folder it lets you delete.
    C:\Documents and Settings\Greg\Local Settings\Temp\14.tmp.exe
    C:\WINDOWS\system32\bum501.exe
    C:\WINDOWS\system32\voi973.exe
    C:\WINDOWS\system32\intell32.exe
    C:\WINDOWS\system32\winyp32.exe
    C:\WINDOWS\d3sm32.exe

    Additional step to delete C:\WINDOWS\Downloaded Program Files\APHelper.dll:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s APHelper.dll
    del APHelper.dll
    exit

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just noticed I missed adding one file to the delete list. Delete the one below if found:

    C:\WINDOWS\system32\private.exe
     
  23. eagles2880

    eagles2880 Private E-2

    I didn't get the post to delete C:\WINDOWS\system32\private.exe until now when I was about to post my new HJT log. So I will go back into safe mode and delete this file as soon as you respond to this post. I just wanted to let you know that things look good so far. Nothing really out of the ordinary compared to what I had before this Dialer virus surfaced. But when I was following your last instructions I was unable to locate and delete C:\WINDOWS\system32\winyp32.exe and C:\WINDOWS\d3sm32.exe

    I found a "winpy.ime" and a "winpy.MB" but did not touch them. They were the closest things. Also, when typing in the cmd window the APHelper.dll was "not found." I went through explorer to look for the file and was unable to locate it that way either. What do you make of this situation?

    As long as I can find the private.exe file consider it gone. I will go into Safe Mode and take care of that along with whatever you suggest for the problem mentioned directly above.

    ...Here is the HJT file that I have as of right now.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why couldn't you delete those two files? Did you get an error message? Did you actually find them?

    No DO NOT delet winpy.ime and winpy.MP . They are valid.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to be running out for a while. But your log is looking good. If you have no more malware issues, you next step is to follow the below:

    How to Protect yourself from malware!


    Where are you in NJ? Must be close to PA with a name like eagles! ;)
     
  26. eagles2880

    eagles2880 Private E-2

    I was unable to delete the two files that I mentioned only because I was unable to find them. They were nowhere in sight when I was going through the files in that particular folder. I will now go back into Safe Mode and take care of the private.exe file. It will be gone by the time you read this. I will post a new HJT log in a few minutes just so you can make sure everything seems okay.

    I'm actually not very close to PA. I live in Northern NJ (Morris County), I just happen to like the Eagles. Got pulled in to them by Randall Cunningham at QB when I first started watching football and have just stuck with them since.

    I'm pretty surprised that this episode happened with my computer. I've really not had many or any problems in the past as I protect fairly well using the advice you provided in the link. That's mostly stuff that I have been doing.

    I think I will probably call it a night on this issue so you can get back to me whenever you have the chance, whether it be later tonight or tomorrow. I may check back later tonight but definitely in the morning when I wake up. I don't really have total closure yet because I want to make sure everything is back to the way it was for the most part. Also, I want your approval to say that my log is malware free so I can take care of Step 1 of the READ AND RUN ME.
     
  27. eagles2880

    eagles2880 Private E-2

    mmmkay nevermind. I couldn't find C:\WINDOWS\system32\private.exe either. Does this and the others I cannot locate still show up in my log? Is it possible that one of the other programs may have eliminated them?

    My system seems to be functional again. Thank you so much for your help. I have no idea what you do or how you figure out what to do to save a system like mine that's on the verge of self-destruction but it's pretty amazing. Not to mention the fact that you ask nothing in return. Is there anything else I need to do to get things back to normal?
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about those files. If you cannot find them, they are gone. AB removed a couple and HJT may have removed private.exe while fixing that line.

    You are all clean and yes it is time to go back to step 1 of the READ ME and do that.

    I work in Morris County and live in Bergen County.
     
  29. eagles2880

    eagles2880 Private E-2

    Okay then it looks like all is well again. I can't thank you enough for your help. Finding this messageboard was just the miracle I needed. Thanks again.
    (This past summer I worked in Bergen County and lived in Morris County, haha)

    Now I guess I know where to come if any problem like this ever resurfaces, but I'm hoping it won't have to come to that. Thanks again. Thank you Thank you Thank you!
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds