Welcome, Guest

Go Back   TechieHQ - Computer Help Forum · » Operating Systems · System Infection Support
Reload this Page Dial Up connection infected

Dial Up connection infected

System Infection Support Support for virus, spy-ware, ad-ware, mal-ware and any other type of system infection.

Reply
 
Thread Tools Display Modes
  #1  
Old Jan 29th, 07, 11:48 AM
Nickweb's Avatar
Nickweb
Resident Filmaker
Posts: 2,100
Status: Offline
shield_mod.gif
 
From: North Wales, Britain
Joined: Nov 2003
Rep: Nickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geekness
flickr.gif
Dial Up connection infected

hello guys, I'm making my second attempt at cleaning my dial up connection, on the family computer, and run HiJack this, anyone have a look at it for me? cheers

Logfile of HijackThis v1.98.2
Scan saved at 20:13:38, on 28/01/2007
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2919.6304)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\TWINMOS\MOBILE DISK V3.0\MOBMON.EXE
C:\PROGRAM FILES\TWINMOS\MOBILE DISK V3.0\USBTD.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\BTMODEMPROTECTION.EXE
C:\PROGRAM FILES\VISIONEER ONETOUCH\ONETOUCHMON.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\WINDOWS\SYSTEM\MSWHEEL.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\PROGRAM FILES\DIALERZAPPER\DIALERZAPPER.EXE
C:\PROGRAM FILES\MSWORKS\CALENDAR\WKCALREM.EXE
C:\PROGRAM FILES\3COM\MODEMMGR\PROGRAM\MDMMGR.EXE
C:\PROGRAM FILES\WINDOWS MEDIA COMPONENTS\ENCODER\WMENCAGT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\MY DOCUMENTS\HIJACKTHIS1-98-2.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
F1 - win.ini: run=HPFSCHED
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [POINTER] C:\PROGRA~1\MICROS~1\point32.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [UFD Monitor] C:\Program Files\TwinMOS\Mobile Disk V3.0\MobMon.exe
O4 - HKLM\..\Run: [UFD Utility] C:\Program Files\TwinMOS\Mobile Disk V3.0\UsbTD.exe
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [BTModemProtection] BTModemProtection.lnk
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKLM\..\Run: [avgctrl] "C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [schedm] "C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [DialerZapper] C:\PROGRAM FILES\DIALERZAPPER\DIALERZAPPER.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\MSWorks\Calendar\WKCALREM.EXE
O4 - Startup: 3Com Modem Manager.lnk = C:\Program Files\3Com\ModemMgr\Program\mdmMgr.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Encoder Agent.lnk = C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O18 - Protocol: asksam - {F9FF9EDA-4916-11D1-B6C1-002018305A61} - C:\PROGRAM FILES\ASKSAM\SURFSAVER\AS_AIPP.DLL (file missing)

I dont really want to have to wipe the disk and start again, as I think I've lost the disk with the dellnet free net access (Still have to pay for phone bill) and I dont want to have to go to broadband, too pricey at the moment

cheers guys



__________________
My Blog
www.filmsbynick.com
http://www.youtube.com/filmsbynick
For my comp specs, check out my profile
Reply With Quote
Advertisement
  #2  
Old Jan 29th, 07, 12:45 PM
Codex85's Avatar
Codex85
Mouse Potato
Posts: 693
Status: Online!
techie.gif
 
From: US
Joined: Apr 2005
Rep: Codex85 is a splendid one to beholdCodex85 is a splendid one to beholdCodex85 is a splendid one to beholdCodex85 is a splendid one to beholdCodex85 is a splendid one to beholdCodex85 is a splendid one to beholdCodex85 is a splendid one to behold
Trojan Downloader:

O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab



__________________

Reply With Quote
  #3  
Old Jan 29th, 07, 4:21 PM
Nickweb's Avatar
Nickweb
Resident Filmaker
Posts: 2,100
Status: Offline
shield_mod.gif
 
From: North Wales, Britain
Joined: Nov 2003
Rep: Nickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geekness
flickr.gif
Ok, so how do I go about fixing this? I know cra* all about the registry settings, and stuff, is there anything in there that could be a rogue dialler?



__________________
My Blog
www.filmsbynick.com
http://www.youtube.com/filmsbynick
For my comp specs, check out my profile
Reply With Quote
  #4  
Old Jan 29th, 07, 5:30 PM
Fenis-Wolf's Avatar
Fenis-Wolf
Addicted to THQ
Posts: 2,974
Status: Offline
shield_mod.giftechie.gif
 
From: Ann Arbor, Mi
Joined: Apr 2003
Rep: Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
Remove these entries. Reboot. Run HijackThis to verify they're gone. Download AVG AntiVirus and AdAware. Update them to the newest versions, and run a full system scan with them both. Should help a lot.

C:\PROGRAM FILES\DIALERZAPPER\DIALERZAPPER.EXE
O4 - HKCU\..\Run: [DialerZapper] C:\PROGRAM FILES\DIALERZAPPER\DIALERZAPPER.EXE
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O18 - Protocol: asksam - {F9FF9EDA-4916-11D1-B6C1-002018305A61} - C:\PROGRAM FILES\ASKSAM\SURFSAVER\AS_AIPP.DLL (file missing)



Reply With Quote
  #5  
Old Jan 30th, 07, 11:46 AM
Nickweb's Avatar
Nickweb
Resident Filmaker
Posts: 2,100
Status: Offline
shield_mod.gif
 
From: North Wales, Britain
Joined: Nov 2003
Rep: Nickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geekness
flickr.gif
sorry to be very very dumb, but how do I remove them, is it inside HiJackThis? Step by steps would be the best way to help me on this, as I know crap all about registry settings/entries.

I have tried to run AVG and downloaded AdAware on my laptop and copied over to my family comp, but I think that my proc is not fast enough to run them, its a P3 455 mhz, off the top of my head.



__________________
My Blog
www.filmsbynick.com
http://www.youtube.com/filmsbynick
For my comp specs, check out my profile
Reply With Quote
  #6  
Old Jan 30th, 07, 3:42 PM
Fenis-Wolf's Avatar
Fenis-Wolf
Addicted to THQ
Posts: 2,974
Status: Offline
shield_mod.giftechie.gif
 
From: Ann Arbor, Mi
Joined: Apr 2003
Rep: Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
It will run them, it will just take forever.
To remote the entries in HijackThis you either check or uncheck the box next to the entry you want to remove, then click 'Fix' down at the bottom.



Reply With Quote
  #7  
Old Jan 31st, 07, 11:47 AM
Nickweb's Avatar
Nickweb
Resident Filmaker
Posts: 2,100
Status: Offline
shield_mod.gif
 
From: North Wales, Britain
Joined: Nov 2003
Rep: Nickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geekness
flickr.gif
thanks, I'll give it a whirl tonight, when I go home from uni



__________________
My Blog
www.filmsbynick.com
http://www.youtube.com/filmsbynick
For my comp specs, check out my profile
Reply With Quote
  #8  
Old Feb 15th, 07, 12:57 PM
Nickweb's Avatar
Nickweb
Resident Filmaker
Posts: 2,100
Status: Offline
shield_mod.gif
 
From: North Wales, Britain
Joined: Nov 2003
Rep: Nickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geekness
flickr.gif
Ok, sorry for the looooooong delay in replying to this, but I tried it last night, and then dialled up, i have BT Modem Protection active which tells me if another number is being dialled, and i got no messages, so it looks like it worked.

Now, the thing is, its a 28k modem (go on, laugh..) SO, if i rip it out, and whack a 56k modem in, would I keep the dial up settings? as i think i had to enter a password when we set it up 4-5 years ago, and I am certain I've lost the password



__________________
My Blog
www.filmsbynick.com
http://www.youtube.com/filmsbynick
For my comp specs, check out my profile
Reply With Quote
  #9  
Old Feb 26th, 07, 1:45 PM
Nickweb's Avatar
Nickweb
Resident Filmaker
Posts: 2,100
Status: Offline
shield_mod.gif
 
From: North Wales, Britain
Joined: Nov 2003
Rep: Nickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geeknessNickweb has much to be proud of his / her geekness
flickr.gif
Ok, no it hasnt worked, I got another dial made last night, it only seems to happen when I go on hotmail, I'm thinking its got something to do with MSN messenger, you know, when MSN will download temporarally download messenger while you are on a .net site? I really dont know whats doing this now, but Its really getting on my nerves, as last time I had a bill for £45 more than usual



__________________
My Blog
www.filmsbynick.com
http://www.youtube.com/filmsbynick
For my comp specs, check out my profile
Reply With Quote
  #10  
Old Feb 26th, 07, 7:09 PM
Fenis-Wolf's Avatar
Fenis-Wolf
Addicted to THQ
Posts: 2,974
Status: Offline
shield_mod.giftechie.gif
 
From: Ann Arbor, Mi
Joined: Apr 2003
Rep: Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
Did you run Spybot?



Reply With Quote
Reply

Tags
connection, dial, infected


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected...HJT Log TheOneGreatX System Infection Support 6 Jul 7th, 06 10:48 AM
dial up scbanjoman Internet 3 Nov 19th, 04 4:06 AM
Trojan RC5.A I'm Infected... DaVo System Infection Support 5 Apr 6th, 04 3:18 PM
Infected Files . . SwitCh System Infection Support 5 Feb 15th, 04 9:01 PM
Am i infected by spammer software? Ruler1 System Infection Support 6 Dec 5th, 03 11:34 PM


All times are GMT +1. The time now is 7:02 PM.