PDA

View Full Version : Auto surfing to ad-w-a-r-e.com



Randomman42
2006-04-03, 22:41
About ad-w-a-r-e.com
This is a nasty site and its taken me two days to sort out my daughter's PC upto a point.
Something, and I don't know what, launches a browser window with this URL
http://www.ad-w-a-r-e.com/cgi-bin/PopupV3?ID={9D3D5E5F-E9F0-B085-0750-019A36760998}&type=normal&mSkip=1&rnd=2925At the same time my host file is filled with these entries
127.0.0.1 sds-qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 www.qoolaid.com
127.0.0.1 www.qoologic.com
127.0.0.1 www.CLKPrecision.com
127.0.0.1 www.urllogic.com
127.0.0.1 www.clkoptimizer.com
127.0.0.1 www.isearch.com
127.0.0.1 isearch.com
127.0.0.1 www.idownload.com
127.0.0.1 idownload.com
127.0.0.1 www.mytotalsearch.com
127.0.0.1 mytotalsearch.com
127.0.0.1 www.lop.com
127.0.0.1 lop.com
127.0.0.1 www.websearch.com
127.0.0.1 websearch.com
127.0.0.1 www.page-not-found.net
127.0.0.1 page-not-found.net
127.0.0.1 www.isearchhere.com
127.0.0.1 isearchhere.com
127.0.0.1 as.adwave.com
127.0.0.1 sr.adwave.com
127.0.0.1 www.adwave.com
127.0.0.1 adwave.com EVENT:HOST:127.0.0.1
127.0.0.1 www.pacimedia.com
127.0.0.1 www.exactsearch.net
127.0.0.1 www.contextplus.net
Before I blocked ad-w-a-r-e it was redirecting to one of these and installing viruses/adware - 80/8 removed
No visuses can now be found (3 different scans) and no adware found by Spybot S&D, yet the problem persists.
Clue No 1 . In the registry I have found this HEX string
{9D3D5E5F-E9F0-B085-0750-019A36760998}
in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
Clue No 2
If I sit and watch my firewall I see Explorer.exe connecting briefly, then System then firefox - then I get a new firefox window or tabconnecting to the url above. Blocked Ha!

Any help in locating this nasty piece of work would be appreciated.

tashi
2006-04-03, 22:47
Hi there.

If you are not being helped at another forum, please follow these instructions.
Before you post a log, and who will advise you. (http://forums.spybot.info/showthread.php?t=288)

Start a topic here:
Malware Forum (http://forums.spybot.info/forumdisplay.php?f=22[/url)

Someone will then take a look at the system and advise you as soon as available to do so.

Cheers.

md usa spybot fan
2006-04-03, 23:36
re: ad-w-a-r-e.com (and also a-d-w-a-r-e.com)

FYI

The following sites are placed in the Internet Explorer's restricted zone by Spybot's Immunize facility to prevent downloads and the storing to cookies (dots replaced by underscores (_) to pervent access from this post):
*_a-d-w-a-r-e_com
www_a-d-w-a-r-e_com[/url]
*_ad-w-a-r-e_com
www_ad-w-a-r-e_com
In addition the following entries are added to the HOSTS file by Spybot's HOSTS file facility to prevent access to the following sites entirely (dots replaced by underscores (_) to pervent access from this post):
ad-w-a-r-e_com
www_ad-w-a-r-e_com
a-d-w-a-r-e_com
www_a-d-w-a-r-e_com

tashi
2006-04-04, 00:33
Randomman42 has posted in the malware removal forum where the L2M infection will be attended to. ;)

http://forums.spybot.info/showthread.php?t=3470