Dialer-257

Discussion in 'Malware Help (A Specialist Will Reply)' started by renasci, Oct 10, 2005.

  1. renasci

    renasci Private E-2

    Hello, once again my pc has gotten hit with something... and I'm not sure how to get rid of it. As a bit of a prelude, the only 2 browsers I have installed on my pc are IE and Netscape, and I would get rid of IE if I knew how... I say this because despite my *never* using IE (outside of BitDefender and Rav, and only because they require it) I've got a virus that runs through IE and I don't even know how that's possible.

    So here's what I do know about it. this virus is identified as "dialer-257" or that's what McAfee labels it as, and as far as I know mcafee is catching all the instances of it as they come, but it's the fact that they keep spawning that has me worried. A pop up button(or 10) will be on my desktop saying something along the lines of 'for instant access click yes' So naturally I hit the cancel button(red x, not a button that says 'cancel') and a tone plays and it closes. Everytime one of these windows pops up Mcafee pops up saying it has detected it, could not delete it, and has moved it to my quarantine folder. I also recently noticed that these same buttons are shown as a History item in IE called 'threexs.com' I've added it to the restricted list on the IE security tab.

    I have run all of my spyware programs in Safe mode, and then run them all again in Safe mode w/ networking (then used bitdefender and rav) but while those 2 virus programs seem to identify the problem, they are not able to clean/delete them.

    Also, in looking at the mcafee log i'm also seeing a few instances of 'alemod.e' virus, and a websearch on that says that it rewrites itself as 'wininet.dll' replacing the current, legitimate file.

    Any help is greatly appreciated.


    (yes, i have followed all the steps/procedures listed in your 'read this before posting' thread)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The read me first was just changed today. Did you follow the new steps or old ones?

    If old ones, please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. renasci

    renasci Private E-2

    Ok, the 2 scans I mentioned doing I did based off of the old post, and I have since followed the instructions in the new post as well.

    Unfortunately, the problem has not been remedied.

    For the online scans I used : Trend Micro, BitDefender, Rav Antivirus.

    All 3 of them came up positive with viruses/ infected files, and all 3 were unable to fix the viruses and could only clean some of the files. Also, it is worth noting that while I have done nothing different between yesterday and today, I am having new instances of problems. the IE history tab shows pages at the aforementioned 'threexs.com' as well as 3 new ones: 'search2k.net' 'patchyoursystem.com' 'securityerror.com'. Please, please help me.

    respectfully, -ren

    (HJT log attached)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run this and post the smitfiles.txt file it creates: Smitfraud and PSGuard Removal

    Then run HJT and select all the O18 line from Logitect and fix them. They look like:
    O18 - Protocol: bw+0s - {91835E34-3CDB-4603-8CED-96267A1B83CB} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

    Then post a new HJT log too.
     
  5. renasci

    renasci Private E-2

    Alright! did everything just as you said, and both logs are attached.

    Your help is very much appreciated.

    -ren
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There should be a smitfiles.txt file. That is what I wanted you to attach from SmitRem. However, it seems to have worked. So let's continue with a few other minor fixes.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: HomepageBHO - {3bf1f86f-b1a8-489b-8d8b-43781d51411f} - C:\WINDOWS\system32\hp9E24.tmp (file missing)

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now tell me how things are working.

     
  7. renasci

    renasci Private E-2

    Ok, i apologize for the delay (and also for posting the wrong .txt file) but smitrem seems to have taken care of the viruses and popups and all the rest of it, thankyou!0

    however... there seems to have been a side effect to it... unless initialized immediately after start up, i'm not getting any sound output from my speakers.

    For instance, if i restart my computer, i get the generic startup tones, and then I'll open iTunes and play a song. It'll start to play and then start to skip, and when i first open a browser i get an error message.

    It's a window that says there is an error with generic Win32 processes. After closing iTunes, and reopening songs will not start, and i have no sound at all(not just from mp3s, also Windows tones, and game bgm don't work)

    Your input would be greatly appreciated,

    -ren
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what is up with your sound problems. I have not seen this have anything to do with SmitFraud problems. If you still have the smitfiles.txt file, post it. That way I can see what it found and removed. Malware can hook itself into anything and cause all kinds of unsuspected issues while running and after cleaning it up.

    If you never open iTunes, do you run into sound problems. If not, perhaps you should try reinstalling iTunes.
     
  9. renasci

    renasci Private E-2

    Ok , i found the smitfiles.txt, and i'm going to attach it with this post. On a side note, it may be that this sound issue and smitrem were just coincidental. A little searching on the internet came back with a host of people who have had the same error message, but with different reactions by their computers (one for instance had the same sound issures, while another would have their computer restart whenever the message appeared).

    As always, thanks so much for your time.

    -ren
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Smitfraud did not actually find and delete anything.

    You did not answer my previous question.

    And also have you tried reinstalling iTunes?
     
  11. renasci

    renasci Private E-2

    Yes, the sound problems do occur regardless of whether i open itunes or not, and an error message pops up asking if i want to send and error report. I've clicked yes and it tells me that i need to have a working iternet connection to send(which i do, but it's not registering w/ this error for some reason)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your last HJT log, I do not think your sound problem is malware related. The root cause may have started with the malware infection but currently I do not see anything. Let's try a few more scans to see if they turn anything up.

    - Run Panda ActiveScan It will not fix anything, but will detect. Save the log and attach later.
    - Run the steps in Running Ewido Security Suite and post the log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds