Virus infection -- Dialer.28.A / Dialer CID

Discussion in 'Malware Help (A Specialist Will Reply)' started by APClark, Oct 9, 2006.

  1. APClark

    APClark Private E-2

    Hi,
    My computer seems to have picked up a problem this morning. I'm being hit by a series of issues, including pop-ups and seemingly false alerts encouraging me to download new software. In additon, new icons have appeared on my start menu and desktop ("Online Security Guide" and "Security Troubleshooting").
    My problems appear to be very similar to those described in a thread just below (http://forums.majorgeeks.com/showthread.php?t=104117), in that AVG has identified two trojans -- Dialer.28.A and Dialer.CID -- but can't heal them properly. I've also seen the pop-up saved as a screen capture in this thread.
    I've followed the instructions as per the "READ AND RUN ME FIRST" thread. Unfortunately, the problems don't seem to have been resolved.
    I've attached below the 5 files as suggested in this thread. Any help would be hugely appreciated.
    Best wishes,
    Andrew.
     

    Attached Files:

  2. APClark

    APClark Private E-2

    (And the other attachments)
     

    Attached Files:

  3. APClark

    APClark Private E-2

    I should add also that SpyBot is finding 25 problems falling under the description "Smitfraud.c", which it can't fix (even on rebooting of the machine and re-running of the application).
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is my second message. Make sure you have follow the first procedure before doing the below.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.

    Now attach new logs from:
    - GetRunKey
    - ShowNew
    - HJT
     
  6. APClark

    APClark Private E-2

    Thanks very much for your help here, chaslang.

    I've completed the first part of your post and attach the requested file here.
     

    Attached Files:

  7. APClark

    APClark Private E-2

    ...and here's the second rapport.txt file.
     

    Attached Files:

  8. APClark

    APClark Private E-2

    Finally, here are the remaining attachments.
    Many thanks for your help on this again.
    Andrew.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run this about:Buster follow the steps in the download link for using it. Attacht the log when you finish the scans.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot your PC!


    After reboot locate the below folder and delete it if found:
    C:\Program Files\Common Files\{BC21B62D-056A-1033-1017-01092900002c}

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Clark\Local Settings\TEMP

    Now run CCleaner!

    Now Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  10. APClark

    APClark Private E-2

    Chaslang,

    Again, many thanks. I've followed your instructions and attach the posts below.

    No problems with running any of the processes, although the about:Buster application didn't give me the option of updating -- it just went straight through to the main program, from where I launched the scan.

    I did indeed find this folder.

    The problems of earlier at least appear to have gone (for now). The computer is running smoothly...it seems.

    Andrew.
     

    Attached Files:

  11. APClark

    APClark Private E-2

    (The other attachments.)
     

    Attached Files:

  12. APClark

    APClark Private E-2

    PS I ran all this with the computer in Normal mode -- hope that's OK.
    Andrew.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download DelDomains and unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    (Please note if you have Spybot S&D installed you will need to "Immunize" again because deldomains will remove all of the sites Spybot adds.)


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Network Security Service (NSS) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK" (You must use copy and paste to enter these characters):

    %AF夶À¨

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot, look for the below file and delete if found:
    C:\WINDOWS\system32\addgu32.exe

    Now attach a new HJT log.
     
  14. APClark

    APClark Private E-2

    Again, thank you.
    I have done as instructed. On this section --

    -- the check box was already on "Stop Service". I've disabled the start-up type, as requested.

    I did not find this file.

    I've attached the log file below.
    Thanks,
    Andrew.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now!

    So how are things working?

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds