This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

highdialer.com

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Each time I start MS Internet Explorer, the location bar shows "C:\WINDOWS\system32\msblank.html". An examination of that file shows it links to "www.http://www.highdialer.com/m/m2.html. Hope you can help. Here's my HJT log

Logfile of HijackThis v1.99.1
Scan saved at 11:56:43 PM, on 8/14/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\HijackThis.exe
C:\WINDOWS\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\System32\msblank.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://lookfor.cc/sp.php?pin=93256
R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
R3 - URLSearchHook: (no name) - {EA0FF097-A378-8BD9-7964-395215EFFA5A} - RtlFindVal.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\wiiel.dll
O2 - BHO: (no name) - {48FC1409-9416-7FC1-8752-6D557FF42E6E} - C:\WINDOWS\System32\gmgjio.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\wiiel.dll
O3 - Toolbar: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\popcorn72.exe rundll.dll,LoadMouseProfile
O4 - HKCU\..\Run: [Rdta] C:\Documents and Settings\Michael\Application Data\hsha.exe
O4 - HKCU\..\Run: [Wuao] C:\Documents and Settings\Michael\Application Data\iaar.exe
O4 - HKCU\..\Run: [Webty] C:\WINDOWS\System32\l?ass.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/downloadget.php?…7fd6b3ff02edc90

REBOOT

Step #2

Please download and run Spybot 1.4 & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do a virus scan here >>> Trend Micro

Step # 4

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan and a new hijackthis log please.
Thanx for helping me out. Here's the new HJT log and ewido report Logfile of HijackThis v1.99.1 Scan saved at 10:04:04 PM, on 8/16/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Dell AIO Printer A940\dlbabmon.exe F:\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [!ewido] "F:\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe ewido anti-spyware - Scan Report ——————————————————— + Created at: 10:00:35 PM 8/16/2006 + Scan result: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005664.exe -> Adware.FindSpy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005666.exe -> Adware.Msnagent : Cleaned with backup (quarantined). C:\Documents and Settings\Michael\Application Data\hsha.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\Documents and Settings\Michael\Application Data\iaar.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005668.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001495.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\WINDOWS\system32\lѕass.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005665.dll -> Adware.SBSoft : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\mpha.exe -> Backdoor.Jeemp.c : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005669.exe -> Downloader.Agent.ay : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001596.exe -> Downloader.Agent.sy : Cleaned with backup (quarantined). C:\WINDOWS\system32\dgprpsetup.exe -> Downloader.Agent.sy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0001613.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0001622.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0001655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0002655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0003655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0004655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001429.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001465.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001470.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001480.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001491.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001502.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001518.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001535.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001544.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001553.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001576.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001593.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001601.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\WINDOWS\system32\cskso.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0000659.hta -> Downloader.Inor.cj : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\mwdexliw.exe -> Downloader.WinShow.af : Cleaned with backup (quarantined). C:\WINDOWS\win32.bmp -> Hijacker.JS : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005662.exe -> Hijacker.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005667.exe -> Hijacker.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\olehelp.exe -> Hijacker.StartPage.it : Cleaned with backup (quarantined). C:\WINDOWS\system32\favset.exe -> Trojan.Favadd.an : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0001618.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0001660.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0002660.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0003659.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005658.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005676.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005684.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005693.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005699.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005706.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005712.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP10\A0005719.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001435.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001474.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001484.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001497.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP8\A0001507.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001523.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001537.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001549.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001558.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001580.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\System Volume Information\_restore{E7A9684A-402C-4421-941E-3319D9090469}\RP9\A0001605.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\WINDOWS\system32\dmgrr.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\WINDOWS\system32\howiper.exe -> Trojan.Qhost.df : Cleaned with backup (quarantined). ::Report end
Hi, I did run HJT in regular mode…I am no longer seeing the highdialer, but for some reason I still cannot get on the internet :( …I have called my internet provider, so I know everything is correct on that end…Do you have any other suggestions? Thank you so much for all your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI