Dialer? Username/password changes!
Results 1 to 6 of 6

Thread: Dialer? Username/password changes!

  1. #1
    Registered User
    Join Date
    Nov 2004
    Posts
    27

    Dialer? Username/password changes!

    Hello everyone,

    This just happened to me today, just out of the blue. I try to connect to my internet provider and the username, password, number and security settings are changed! I change them to normal only to have them come back again! Also when on my connection (normal) and the computer tries downloading a file. The username it gives me is this:
    109607.186.28406.10 And the phone number is this: 0043810444449217. It also changes the security settings from Typical to a custom setting (that i always revert to normal everytime i dial). I ran Ad-Aware with the latest definitions but found nothing. Any idea to get rid of this POS? Thanks!

    **Update**
    I downloaded "HijackThis" and did a scan and got this log, figured i should post it. Thanks again for any help/suggestions! ^_^

    Logfile of HijackThis v1.97.7
    Scan saved at 9:01:53 PM, on 1/27/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\WINDOWS\system32\usbn.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\WINDOWS\slrundll.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Abdullah\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = proxy.saudi.net.sa:8080
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [usbn] C:\WINDOWS\system32\usbn.exe -go -c7 -w10
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\wx.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\wx.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1105537911682
    O16 - DPF: {A8482EAF-A1F3-4934-AE3F-56EB195A50BF} (DeskUpdate - Activex Control) - http://support.fujitsu-siemens.de/De...pi/activex.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{12481685-5549-4A7C-8D1A-C63BC8C96C88}: NameServer = 212.118.133.101 62.149.114.7
    O17 - HKLM\System\CS1\Services\Tcpip\..\{12481685-5549-4A7C-8D1A-C63BC8C96C88}: NameServer = 212.118.133.101 62.149.114.7
    Last edited by Inspiron83; January 27th, 2005 at 01:09 PM.

  2. #2
    Registered User
    Join Date
    Aug 2002
    Location
    San Juan, PR
    Posts
    29
    Welcome to WD:

    Please download newer version (1.99) of hijack this and upload copy of log file in http://www.hijackthis.de This will give you analysis of your system. Be careful when you fix or delete any keys that may be flagged but are valid for your system.

    Good luck!

    Andiol

  3. #3
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    I would also go get Spybot Search and Destroy
    Spybot Search+Destroy

    install it update it and scan with it

    and do the same for Adaware
    Adaware

    Scan fully after updating with both
    Gigabyte 990FXA-UD3
    AMD FX 8350 4ghz OCTO-Core
    Windows 8.1 PRO 64
    Adata 256 gig SSD
    Kingston HyperX 1600 16 Gigs
    Sapphire R9 280 2gig
    Enermax Liberty Modular 620
    www.northernaurora.net
    http://www.northernaurora.net/page/chat.html

  4. #4
    Registered User
    Join Date
    Nov 2004
    Posts
    27
    Thanks for you'r help! Anyways, i used "Hijack This", "Spybot", Add-Aware, and A-Squared updated in safe mode with all updates and found several things. My dialup account stays the same now (no more changes) but every time i connect, within 10-15 seconds...it tries downloading a file from some location (www7. something) and i just cancel it before it goes any further then i am usualy good to go. Further scans reveal nothing. I did delete these lines:
    O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\wx.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\wx.cab

    But they keep comming back everytime i restart the computer...any ideas how it keeps trying to download a file (probably more infected junk). Thanks for any help/suggestions!

  5. #5
    Registered User Green_Eyed's Avatar
    Join Date
    Feb 2001
    Location
    Just this side of normal
    Posts
    189
    Quote Originally Posted by Inspiron83
    Thanks for you'r help! Anyways, i used "Hijack This", "Spybot", Add-Aware, and A-Squared updated in safe mode with all updates and found several things. My dialup account stays the same now (no more changes) but every time i connect, within 10-15 seconds...it tries downloading a file from some location (www7. something) and i just cancel it before it goes any further then i am usualy good to go. Further scans reveal nothing. I did delete these lines:
    O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\wx.cab
    O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\wx.cab

    But they keep comming back everytime i restart the computer...any ideas how it keeps trying to download a file (probably more infected junk). Thanks for any help/suggestions!
    Whenever I get entries in HiJack this that I don't recognize, I'll do a search in my registry.

    Those three entries that you listed, those are the ones that keep coming back? I would search the registry for those cabs and also look at those folders to see if there's any more information you can get from them, company name, executable, etc.

    Also, I noticed that your first HiJack This scan listed a proxy, is that normal for you?

  6. #6
    Registered User
    Join Date
    Nov 2004
    Posts
    27
    Quote Originally Posted by Green_Eyed
    Whenever I get entries in HiJack this that I don't recognize, I'll do a search in my registry.

    Those three entries that you listed, those are the ones that keep coming back? I would search the registry for those cabs and also look at those folders to see if there's any more information you can get from them, company name, executable, etc.

    Also, I noticed that your first HiJack This scan listed a proxy, is that normal for you?
    Yes, the proxy should be a normal thing as the internet here goes through a proxy server (at a national level). Also an intresting fact, if i use Firefox instead of IE...the download never happens and everything seems alright. But as soon as i connect and fire up IE within 10-15 seconds that file tries downloading. So now i am using Firefox while trying to eventualy get to the root of it all. I also found a few suspecting in the "Downloaded Program Files" folder in Windows and i deleted them, as well as something called "dialer" in the main Windows folder! After those were deleted the number stoped changing. Thanks for the help thus far

Similar Threads

  1. Live Shows Dialer Follow-up
    By Curt in forum Spyware & Antivirus - Security
    Replies: 2
    Last Post: October 21st, 2002, 03:32 AM
  2. Telephone Dialer Problem
    By mbaldridge in forum Windows 95/98/98SE/ME
    Replies: 1
    Last Post: May 2nd, 2002, 02:24 PM
  3. How to get rid of old SPRY dialer?
    By Wayward Clam in forum Tech-To-Tech
    Replies: 2
    Last Post: May 19th, 2001, 03:04 AM
  4. [RESOLVED] dialer
    By briz in forum Internet and Networking
    Replies: 1
    Last Post: March 29th, 2001, 12:43 AM
  5. 98se dialer popup
    By c4a in forum Windows 95/98/98SE/ME
    Replies: 1
    Last Post: July 23rd, 2000, 07:13 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •