Dialer hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lacey_to, Aug 19, 2004.

  1. lacey_to

    lacey_to Private E-2

    hello am new on the site so please bare with me.I think i have a dialer problem or my dailer has been hijacked.A programme called "ww14" creates an icon on my desktop and disconnects me from the internet and tries to reconnect using its own ISP.I've tried all known spyware,malware,adware e.t.c removal programmes but none of it works.can someone help please???

    Tony
     
  2. Kaotic

    Kaotic Private E-2

  3. lacey_to

    lacey_to Private E-2

    I've tried CWShredder too but it got rid of other problems just like the otheres but did not get rid of the dialer.Is there anything else i can try?
     
  4. Kaotic

    Kaotic Private E-2

  5. lacey_to

    lacey_to Private E-2

    Heres the copy of the results from hijack this.
     

    Attached Files:

    Last edited by a moderator: Aug 19, 2004
  6. Kaotic

    Kaotic Private E-2

    Ok run highjackthis again and remove the following. Then reboot.

    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe"


    O9 - Extra button: Bajar Programas - {C8950078-94A4-4C32-BB9C-4666357965AF} - C:\bajartodo\index.htm

    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.13/573/online.chm::/on-line.exe

    O16 - DPF: {2C0F2AEA-3A9B-46DB-A7BE-80FF329E415D} (PremiumInternacional Class) - http://www.accesoplugin.com/dialerc...ternacional.cab

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05c6210...ip/RdxIE601.cab

    O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} (UCSearch.ucUCSearch) - http://www.zuvio.com/opnste/UCSearch.CAB
     
  7. lacey_to

    lacey_to Private E-2

    Thanks Koatic,it seems to have gone.So appreciated thnx.Abbey sure i did not need to be refferred to that thread beacause i had been referred to before.
    Tony
     
  8. Kaotic

    Kaotic Private E-2

    You are very welcome, glad I could help. I just have one more suggestion for you. I use a program called SpywareBlaster. What it does is it catches spyware before it installs. It is not full proof but it is a very handy program to have. You can download it here : http://majorgeeks.com/download2859.html . Just make sure to read the instructions and check for updates about once every other week. This will help prevent future infections. Take care.
     
  9. lacey_to

    lacey_to Private E-2

    Hey Koatic thnx i'll install that.The dialer hijack software is still present in my computer cuz i was using the internet today and it appeared and did exactly the same thing as before.Should i run hijack this again?or what should i do??
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From your first HJT log you should have also fixed:
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: Bromas y chistes - {068C36CF-483E-4CA8-A7F2-10EFFDA49C45} - http://www.accesoplugin.com/prom/a_bromas2/?l=bajartodo&ver=1&t=new (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Corel Network monitor worker - {313099C8-22C5-48BB-AA52-D631B52C11AC} - (no file)
    O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {313099C8-22C5-48BB-AA52-D631B52C11AC} - (no file)
    O9 - Extra button: Antivirus - {4358161B-A4B8-498E-8019-3DAB50DFD578} - http://www.accesoplugin.com/prom/a_virus2/?l=bajartodo&ver=1&t=new (file missing)
    O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
    O9 - Extra button: Corel Network monitor worker - {313099C8-22C5-48BB-AA52-D631B52C11AC} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {313099C8-22C5-48BB-AA52-D631B52C11AC} - (no file) (HKCU)

    However, I'm not sure that this will solve the dialer problems though. But they need to be fixed.

    Questions:
    1) Have you run CCleaner
    2) Have you run Trendmicro & PandaSoftware online scans
     
  11. lacey_to

    lacey_to Private E-2

    I have already run CCleaner but did not solve the problem.Am yet to try Trendmicro & Pandasoftware.Do you think that will solve the dialer problem??
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never know! Run them and we will see. Did you fix the other lines with HijackThis?

    By the way, have you looked in Control Panel, Add/Remove Programs for anything you do not recognize. Perhaps something is in there. It may not use the name ww14. Searching on ww14 brings up a hit on something called Weekend Wars. Seems to be related to some type of LAN gaming.
     
    Last edited: Aug 21, 2004
  13. lacey_to

    lacey_to Private E-2

    Yeh i fixed the lines with hijack this thanx.I have also looked in the control panel add or remove software but nothing alien showed up.Am yet to try trendmicro and the other.I think that "ww14" has something to do with online cassino games,and this is not the first time i've been attacked by them.when u ran the search,did you find something telling you how to unistall their software?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you complete running all the items indicated here: READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    we cannot go any further. What are you waiting for? Run the online scans that I gave you and the above link also gave you.
     
  15. lacey_to

    lacey_to Private E-2

    Yeh yeh done it now,nothing alien came up or it did not detect anything.and the link you gave me doesn't work,you might want to send it again i think theres a problem with it!!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I forgot to make it a clickable link. This is the link: http://forums.majorgeeks.com/showthread.php?t=35407

    Just make sure you have down everything with the correct versions.

    Then download HijackThis from: http://www.majorgeeks.com/download3155.html
    And post a log as an attachment.
    See guidelines on HijackThis here: http://forums.majorgeeks.com/showthread.php?t=38752
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds