This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unknown Dialer

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A unknown dialer is installed on my PC and start calling on dialup modem after some minutes I use the ADSL line. It seems that the malware start tasks named Vfie1 or Vfie2, Starting from this moment, the PC becames extremelly slow and sometimes an error on page appears. I try alreadu with ADWARE, SPYBOOT and EWIDO but without results.

I attached the log of HJJACK:

Logfile of HijackThis v1.99.1
Scan saved at 21.36.11, on 28/09/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\Programmi\ewido anti-spyware 4.0\guard.exe
E:\WINDOWS\Explorer.EXE
E:\Programmi\Norton AntiVirus\navapsvc.exe
E:\Programmi\Norton Internet Security\NISUM.EXE
E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\SOUNDMAN.EXE
C:\MediaKeyNT\MediaKey.exe
E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
E:\Programmi\iPod\iTunesHelper.exe
E:\Programmi\QuickTime\qttask.exe
E:\WINDOWS\System32\snmp.exe
E:\Programmi\Babylon\Babylon.exe
E:\PROGRA~1\NORTON~1\navapw32.exe
E:\Programmi\Norton Internet Security\IAMAPP.EXE
E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Temp\vfie1.exe
E:\Programmi\ewido anti-spyware 4.0\ewido.exe
E:\Programmi\Norton Internet Security\SymProxySvc.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\WINDOWS\system32\fxssvc.exe
E:\WINDOWS\System32\mqsvc.exe
E:\Programmi\Norton Internet Security\NISSERV.EXE
E:\WINDOWS\System32\mqtgsvc.exe
E:\Programmi\iPod\bin\iPodService.exe
E:\Programmi\Norton Internet Security\ATRACK.EXE
E:\Programmi\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/oggi/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gw.aliceadsl.it/home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {404E8B4C-6B40-33B0-B006-49C09745B821} - E:\WINDOWS\ejioe1.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\programmi\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ALiUSBfix] E:\WINDOWS\System32\ALiUSB20.exe
O4 - HKLM\..\Run: [MediaKey] C:\MediaKeyNT\MediaKey.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SSC_UserPrompt] E:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMLABTECMOUSE] E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Programmi\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ SystemBoot] E:\WINDOWS\Help\Help\services.exe
O4 - HKLM\..\Run: [iTunesHelper] "E:\Programmi\iPod\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Babylon Client] E:\Programmi\Babylon\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NAV Agent] E:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] E:\Programmi\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [bikini] bikini.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] "E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe"
O4 - HKLM\..\Run: [vfie5.exe] E:\WINDOWS\Temp\vfie5.exe
O4 - HKLM\..\Run: [vfie2.exe] E:\WINDOWS\Temp\vfie2.exe
O4 - HKLM\..\Run: [vfie1.exe] E:\WINDOWS\Temp\vfie1.exe
O4 - HKLM\..\Run: [!ewido] "E:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [_SystemBoot] E:\WINDOWS\Help\Help\services.exe
O4 - HKCU\..\Run: [Skype] "E:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = E:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Alice - {D555502E-C2E9-4993-88EF-1DDF7683F6E2} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O12 - Plugin for .pdf: E:\Programmi\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - https://safe.tele2.com/inc/accounthelper.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D77ED36C-1DAE-4038-A09B-3CE36D70E186}: NameServer = 193.12.150.2 212.247.152.2
O23 - Service: Ati HotKey Poller - Unknown owner - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - E:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - E:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - E:\Programmi\Norton Internet Security\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - E:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe (file missing)

The log of EWIDO:

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 21.19.56 28/09/2006

+ Scan result:



D:\CartellaW98\Documents\Programmi\Babylon.zip/Babylon/babylon.pro.5.0.1.r7.fixed.read.nfo.crack-tsrh.zip/start.exe -> Downloader.Small.gl : No action taken.
E:\Programmi\Babylon\start.exe -> Downloader.Small.gl : No action taken.
C:\System Volume Information\_restore{0A34A707-0581-474B-93BD-66FD5013C8C3}\RP157\A0160865.exe -> Trojan.LowZones.dt : No action taken.
C:\System Volume Information\_restore{0A34A707-0581-474B-93BD-66FD5013C8C3}\RP157\A0169751.exe -> Trojan.LowZones.dt : No action taken.


::Report end

Waiting for your help, regards

The Sailorman
Welcome to the forum :wavey:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {404E8B4C-6B40-33B0-B006-49C09745B821} - E:\WINDOWS\ejioe1.dll (file missing)

O4 - HKLM\..\Run: [ SystemBoot] E:\WINDOWS\Help\Help\services.exe

O4 - HKLM\..\Run: [bikini] bikini.exe

O4 - HKLM\..\Run: [vfie5.exe] E:\WINDOWS\Temp\vfie5.exe

O4 - HKLM\..\Run: [vfie2.exe] E:\WINDOWS\Temp\vfie2.exe

O4 - HKLM\..\Run: [vfie1.exe] E:\WINDOWS\Temp\vfie1.exe

O4 - HKCU\..\Run: [_SystemBoot] E:\WINDOWS\Help\Help\services.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Close the program.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

e:\windows\system32\bikini.exe <— file

e:\windows\help\help\services.exe <— file
(WARNING!!! DELETE THIS SERVICES.EXE IN THIS FOLDER ONLY!!!)

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Dear all,

I executed all instructions and the resulting log is the following.
Thanks a lot for your help, ciao

fabio

RESULTING LOG

Logfile of HijackThis v1.99.1
Scan saved at 8.27.38, on 03/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\System32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\Programmi\ewido anti-spyware 4.0\guard.exe
E:\Programmi\Norton AntiVirus\navapsvc.exe
E:\Programmi\Norton Internet Security\NISUM.EXE
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\System32\snmp.exe
E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmi\Norton Internet Security\SymProxySvc.exe
E:\WINDOWS\SOUNDMAN.EXE
C:\MediaKeyNT\MediaKey.exe
E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
E:\Programmi\iPod\iTunesHelper.exe
E:\Programmi\QuickTime\qttask.exe
E:\WINDOWS\system32\fxssvc.exe
E:\WINDOWS\System32\mqsvc.exe
E:\Programmi\Babylon\Babylon.exe
E:\PROGRA~1\NORTON~1\navapw32.exe
E:\Programmi\Norton Internet Security\NISSERV.EXE
E:\Programmi\Norton Internet Security\IAMAPP.EXE
E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe
E:\WINDOWS\System32\mqtgsvc.exe
E:\Programmi\ewido anti-spyware 4.0\ewido.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Programmi\Skype\Phone\Skype.exe
E:\Documents and Settings\Administrator\Desktop\HijackThis.exe
E:\Programmi\iPod\bin\iPodService.exe
E:\Programmi\Norton Internet Security\ATRACK.EXE
E:\WINDOWS\System32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice.it/oggi/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gw.aliceadsl.it/home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\programmi\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\programmi\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] E:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ALiUSBfix] E:\WINDOWS\System32\ALiUSB20.exe
O4 - HKLM\..\Run: [MediaKey] C:\MediaKeyNT\MediaKey.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SSC_UserPrompt] E:\Programmi\File comuni\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [FLMLABTECMOUSE] E:\Programmi\Labtec\Labtec Mouse Software\2.0\mouse32a.exe
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Programmi\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "E:\Programmi\iPod\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Babylon Client] E:\Programmi\Babylon\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NAV Agent] E:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] E:\Programmi\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [CnxDslTaskBar] "E:\Programmi\Trust\Trust MD3100 USB ADSL MODEM\CnxDslTb.exe"
O4 - HKLM\..\Run: [!ewido] "E:\Programmi\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "E:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = E:\Programmi\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Alice - {D555502E-C2E9-4993-88EF-1DDF7683F6E2} - http://gw.aliceadsl.it/alice (file missing) (HKCU)
O12 - Plugin for .pdf: E:\Programmi\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://gw.aliceadsl.it/home
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1159510295528
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159552162338
O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - https://safe.tele2.com/inc/accounthelper.cab
O23 - Service: Ati HotKey Poller - Unknown owner - E:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - E:\Programmi\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Programmi\File comuni\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Servizio Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - E:\Programmi\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - E:\Programmi\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\FILECO~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Programmi\File comuni\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - E:\Programmi\Norton Internet Security\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - E:\Programmi\File comuni\Symantec Shared\Security Center\SymWSC.exe (file missing)
Due to lack of feedback:

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI