win32 dialer

Discussion in 'Malware Help (A Specialist Will Reply)' started by squidvault, Mar 31, 2006.

  1. squidvault

    squidvault Private E-2

    help

    i have a problems with this virus...
    it always asking to do a dial up connection on my computer even when the telephone cable is unpluged....

    when i checked the task manager, there are several process named sorry i forgot, but it seems to be like this : blablabla.temp.exe

    and these process are using so much of my resources....
    help me

    n sorry for my bad english...
    oya im using avast
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. squidvault

    squidvault Private E-2

    thank you mr chaslang.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Just attach the three logs when you finish all the steps.
     
  5. squidvault

    squidvault Private E-2

    ha...

    this dialer drives me crazy !!!!
    everytime i get connected to the internet, it infects my computer.

    sorry mr chaslang...
    im not done yet to download HijackThis to get the log and here i am found myself infected again..

    any suggestion to block this virus???
    avast can only detect it not block/delete it
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't worry about whether you are infected again or not! Just complete ALL steps in the READ & RUN ME. How much of the READ AND RUN ME have you completed. HijackThis is the last step that we want performed. Have you run the online scans from step 6? Can you run them? If so, attach the logs from the two online scanners. If you cannot run the online scanners, just tell me and continue on to step 7. And then attach the HijackThis log (make sure you follow the instructions in step 7 or you will not have it installed properly).

    Do you have a software firewall installed?
     
  7. squidvault

    squidvault Private E-2

    mr chaslang, im sorry.

    i only can give you the hijackthis log.
    can't do online scan, can't download the panda AV
    coz here in my country the internet connection is highly cost and slow...

    sorry again, i hope you can do something with just this hijackthis log (should be bitdefender, panda, and hijackthis)

    thx
     

    Attached Files:

  8. squidvault

    squidvault Private E-2

    firewall software installed???

    dont have any:rolleyes:
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well we will try to get you fixed but without the other scans, we may miss some things. First you MUST follow the directions in step 7 exactly and get HijackThis installed correctly. You have it exactly where we ask that it not be installed. Do this before continuing with the below!

    Downloading - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it to run it.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filename into KILL BOX. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click YES and it will reboot.

    C:\WINDOWS\SYSTEM32\wineil32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. After this reboot, do not run anything but what I request. DO NOT open any browsers!

    Now after reboot run HijackThis and select any of the following lines (if they still exist) and then click Fix checked:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0_01) -
    O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
    O20 - Winlogon Notify: wineil32 - C:\WINDOWS\SYSTEM32\wineil32.dll <--- this line may something about (file missing) Fix it anyway.

    Now exit HJT

    And attach a new HJT log. Also tell me how things are working.
     
  10. squidvault

    squidvault Private E-2

    done
    all steps done..

    i hope everythings fine
    thank you for your kindne ss and favor mr chaslang ;)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Your log is clean! However you never installed HijackThis properly as requested. Too late for this round, but you need to get it installed properly.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds