Trojan.Win32.Dialer

Discussion in 'Malware Help (A Specialist Will Reply)' started by BillRat9, Apr 24, 2006.

  1. BillRat9

    BillRat9 Private E-2

    I have been battling the Trojan.Win32.Dialer for a few days now with no success. It simply continues to re-install itself every time I try to delete it.

    I am running W2k SP4.

    I've tried following the "Read Before Posting" Rules and I apologize if I'm making newbie boo-boos.

    Any help would be greatly apprciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I do not see MS Windows Defender install or the CounterSpy subsitute for Windows Defender if it could not be run for some reason. Also the CounterSpy log would have to be attached.

    Also you did not complete the instructions in step 6 of the READ ME. You must run both online scanners and attach the logs. This must be done before using HijackThis.
     
  3. BillRat9

    BillRat9 Private E-2

    My apologies. I had only read the brief "READ ME" before my first post.

    I have followed the instructions and in doing so, ran across the following.

    The S&D problems found were (and have been):
    CoolWWWSearch.BadZoneMap
    Settings
    ...flingstone.com\*!=W=4
    CooldWWWSearch.WinRes
    Trusted Sites
    ...offshoreclicks.com\*!=W=4
    However, CWShredder did not find Cool Web on the system. These may be false positives, but I'm not sure.

    Also, when opening in Safe Mode, I continuously get the error
    "svchost.exe has generated errors and will be closed by Windows...."
    This also happened when I tried to open browsers in Safe Mode, so I ran BirDefender and Panda in regular boot mode.

    Also, I was unable to open Windows Defender Services in Safe Mode and got the error:
    "Application failed to initialize: 0x800106ba. A problem caused Windows Defender Services to stop....." I rebooted and ran it in normal boot mode and it ran fine.

    As I am typing this reply, the Trojan.Win32.Dialer has tried (or succeeded in) re-installing itself three times. I have Shield Anti-Virus and it is set to delete the files, but they keep trying to re-install.

    I am on Intel Pentium 4 CPU 1.60 GHz 512 MB RAM VGA, running W2k SP4.

    Hopefully, I have managed this correctly this time and I really thank you in advance for any assistance.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the below and then attach the smitfiles.txt log:

    SpywareQuake Removal Procedure

    Also, You forgot to empty your Norton Nprotect folder as step 0 indicates. Do this and then continue to the below.

    Goto Add/Remove programs and uninstall the below:
    Viewpoint Manager

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.
    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    c:\winnt\system32\ld70D8.tmp
    c:\winnt\system32\1024
    C:\WINNT\SYSTEM32\winbjv32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    O15 - Trusted Zone: http://www.cdcovers.cc
    O20 - Winlogon Notify: winbjv32 - C:\WINNT\SYSTEM32\winbjv32.dll

    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (we already deleted them with killbox but we are double checking):
    C:\WINNT\SYSTEM32\winbjv32.dll
    c:\winnt\system32\ld70D8.tmp
    c:\winnt\system32\1024

    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log

    Also tell me how things are working!
     
    Last edited: Apr 26, 2006
  5. BillRat9

    BillRat9 Private E-2

    I am not currently at the machine that is infected. I will perform the steps outlined in the morning. But first I wanted to ask about the Norton quarantine files.

    I removed Norton Internet Security from my machine several months ago. I had the problem of being asked for my registration key every time I rebooted until I was told that my trial version had expired (even though I had paid for it long before). Their fix didn't solve the problem nor did several hours on the phone with them....so I got rid of it. I followed the instructions from Symantec support on how to "completely" remove NIS from my system and thought that this would remove the quarantine file as well. Apparently it didn't. Still I looked for the quarantine folder while following the "READ & RUN" directions and I couldn't find it. Symantec's guide calls for running Norton in order to empty the quarantine, but I couldn't run it since it was "removed."

    Can you tell me where the folder is on my system or how to empty it without being able to run Norton?

    Thanks SO MUCH for all of your help. You guys are amazing!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well first, you still have all the Symantec software installed.
    And what I was referring to for your case was the Norton Nprotect feature (not the Quarantine). Norton Nprotect is a feature to protect/backup the Recycle Bin (dumb feature - that winds up being a spyware collection bin). It must be emptied separately from the Recycle Bin. I gave a link to instructions on doing this.

    Let's check what is still installed (at least what your PC thinks is still installed)!

    Get an installed programs list from HijackThis!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  7. BillRat9

    BillRat9 Private E-2

    Alrightey then...

    I went ahead and emptied the Norton Nprotect folder as outlined in the support article and began the steps outlined in your earlier post.

    I was unable to run Add/Remove Programs in Safe Mode so I rebooted into normal mode and Spyware Quake did not appear. Looking in the System32 folder, none of the drivers listed were there. Also, none of the files or folders listed near the end of the Quake Removal page were there. I took this as a good thing.

    I had already removed Viewpoint Manager earlier.

    I followed your instructions re: KillBox and all went well.

    I fixed the entries in HijackThis, although three of them had apparently been fixed in earlier procedures.

    Things seem to going well...so far.

    I am attaching the requested files.

    Thanks Again!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is still showing in your HJT logs. That was why I said uninstall it. We will have to fix it manually.

    Please note that you never installed the proper version of Ad-Aware SE. You are still using the very old Ad-aware 6 Personal. As the READ ME indicates, you must always click the links to see what we have in them for download to make sure you have the correct versions. Both software version numbers & reference files (detection's databases) must both be current. Uninstall this old version and download, install, update and run the new version.

    The same is problem is true for Spybot! Your version is more than a year out of date!

    And to top it off, you still never followed the directions in step 7 of the READ & RUN ME to install HJT properly. You installed it exactly where the directions indicate not to install it.

    So in essence, you have never actually followed and completed the READ & RUN ME properly.

    By the way, you have Morpheus 1.9 installed which comes bundled with malware. You should uninstall this.

    Okay.....onto the removal of Symantec and Viewpoint!

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Symantec Core LC... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Symantec Core LC

    If you get any error messages while performing the above steps, just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe <--- this should already be gone after running the above fixes.

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Viewpoint <-- the whole folder
    C:\Program Files\Common Files\Symantec Shared <-- the whole folder

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Apr 26, 2006
  9. BillRat9

    BillRat9 Private E-2

    I just meant to say that i had already tried to remove Viewpoint Mgr. in Add/Remove. Obviously that didn't completely uninstall it.

    I have installed new versions of AdAware and Spybot and Run them. I am also running HJT through C/Program FIles/HJT.

    I have tried several times in the past to uninstall Morpheus but nothing happens in Add/Remove.

    The Viewpoint folder was not there when I rebooted into Safe Mode.

    Also, during this process my Google Toolbar has been removed from my browser window. Is it unsafe?

    I hope I'm getting this stuff right now. Sorry for being such a pain.

    Thanks.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use HijackThis to uninstall a program!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Choose the program you wish to uninstall by selecting it in the window.
    • Now Click Delete this entry
    Did that help!

    No it is not safe! If you need it, perhaps you will need to reinstall it. It still shows in your HijackThis log but it was never installed properly. It should not be running from the Downloaded Program Files folder. But this is not a topic for this forum. My opinion of toolbars is to uninstall them to avoid wasting system resouces.


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  11. BillRat9

    BillRat9 Private E-2

    Thank You SO much for your help!! I know I've been less than the ideal patient but it is wonderful that you folks are willing to take the time to help.

    It is greatly appreciated.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Can I assume that you were able to remove Morpheus with those steps?
     
  13. BillRat9

    BillRat9 Private E-2

    I'm not at that computer tonight, but I will try to remove it tomorrow. I haven't used that program in over a year so, hopefully, any malware that came bundled with it has been removed. But I'll let you know. Thanks.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let me know the results.
     
  15. BillRat9

    BillRat9 Private E-2

    Worked like a charm.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! Then I assum we are all done! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds