Results 1 to 5 of 5

Thread: Auto surfing to ad-w-a-r-e.com

  1. #1
    Junior Member
    Join Date
    Apr 2006
    Posts
    3

    Default Auto surfing to ad-w-a-r-e.com

    About ad-w-a-r-e.com
    This is a nasty site and its taken me two days to sort out my daughter's PC upto a point.
    Something, and I don't know what, launches a browser window with this URL
    http://www.ad-w-a-r-e.com/cgi-bin/PopupV3?ID={9D3D5E5F-E9F0-B085-0750-019A36760998}&type=normal&mSkip=1&rnd=2925At the same time my host file is filled with these entries
    127.0.0.1 sds-qckads.com
    127.0.0.1 status.qckads.com
    127.0.0.1 www.qoolaid.com
    127.0.0.1 www.qoologic.com
    127.0.0.1 www.CLKPrecision.com
    127.0.0.1 www.urllogic.com
    127.0.0.1 www.clkoptimizer.com
    127.0.0.1 www.isearch.com
    127.0.0.1 isearch.com
    127.0.0.1 www.idownload.com
    127.0.0.1 idownload.com
    127.0.0.1 www.mytotalsearch.com
    127.0.0.1 mytotalsearch.com
    127.0.0.1 www.lop.com
    127.0.0.1 lop.com
    127.0.0.1 www.websearch.com
    127.0.0.1 websearch.com
    127.0.0.1 www.page-not-found.net
    127.0.0.1 page-not-found.net
    127.0.0.1 www.isearchhere.com
    127.0.0.1 isearchhere.com
    127.0.0.1 as.adwave.com
    127.0.0.1 sr.adwave.com
    127.0.0.1 www.adwave.com
    127.0.0.1 adwave.com EVENT:HOST:127.0.0.1
    127.0.0.1 www.pacimedia.com
    127.0.0.1 www.exactsearch.net
    127.0.0.1 www.contextplus.net
    Before I blocked ad-w-a-r-e it was redirecting to one of these and installing viruses/adware - 80/8 removed
    No visuses can now be found (3 different scans) and no adware found by Spybot S&D, yet the problem persists.
    Clue No 1 . In the registry I have found this HEX string
    {9D3D5E5F-E9F0-B085-0750-019A36760998}
    in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
    Clue No 2
    If I sit and watch my firewall I see Explorer.exe connecting briefly, then System then firefox - then I get a new firefox window or tabconnecting to the url above. Blocked Ha!

    Any help in locating this nasty piece of work would be appreciated. Here's my Hijackthis data:-


    Logfile of HijackThis v1.99.1
    Scan saved at 21:06:50, on 03/04/2006
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ALISNDMG.EXE
    C:\WINDOWS\LTSMMSG.EXE
    C:\PROGRAM FILES\ACER\POWERKEY\POWERKEY.EXE
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.EXE
    C:\PROGRAM FILES\COMMON FILES\FILSECLAB\FILMSG.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\REGEDIT.EXE
    C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
    C:\WINDOWS\NOTEPAD.EXE
    C:\HJT\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
    O1 - Hosts: ;I cleared it again
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [ALiSndMgr] ALiSndMg.exe
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [AcerPowerkey] "C:\Program Files\Acer\Powerkey\Powerkey.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb03.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKLM\..\Run: [xfilter] "C:\Program Files\Filseclab\xfilter\xfilter.exe" –a
    O4 - HKLM\..\Run: [twister] "C:\Program Files\Filseclab\Twister\twister.exe" -a
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Filseclab Messenger.lnk = C:\Program Files\Common Files\Filseclab\FilMsg.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    Note xFilter is my firewall & twister is a secvond AV prog by the same guys.

  2. #2
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Hi Randomman42

    Thats a look2me infection
    Please download L2m9xfix (by Swandog46) from one of these locations:
    GeeksToGo
    GeeksToGo
    Noidea.us
    Save it to the desktop and run it. Extract the files, and then open the l2m9xfix folder you just created and run RunThis.bat.
    A window will open, and your desktop will disappear, then reappear. Please be patient until the batch says it is completed.
    Then please restart your computer, and post a new HijackThis log as well as the entire text of the log.txt file which should be in the same folder as RunThis.bat.

  3. #3
    Junior Member
    Join Date
    Apr 2006
    Posts
    3

    Thumbs up Sorted

    Lonny
    Success
    Thank you for your prompts and accurate assistance.
    As requested here are my two log files
    -------Highjackthis ----------------------
    Logfile of HijackThis v1.99.1
    Scan saved at 20:53:04, on 04/04/2006
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\TREND PC-CILLIN 2000\PCCIOMON.EXE
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\KEYMAP.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\TREND PC-CILLIN 2000\POP3TRAP.EXE
    C:\PROGRAM FILES\TREND PC-CILLIN 2000\WEBTRAP.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ALISNDMG.EXE
    C:\WINDOWS\LTSMMSG.EXE
    C:\PROGRAM FILES\ACER\POWERKEY\POWERKEY.EXE
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
    C:\PROGRAM FILES\FILSECLAB\XFILTER\XFILTER.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\FILSECLAB\TWISTER\TWISTER.EXE
    C:\PROGRAM FILES\COMMON FILES\FILSECLAB\FILMSG.EXE
    C:\HJT\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [VolKey] C:\WINDOWS\SYSTEM\Keymap.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [keyboard] C:\WINDOWS\KEYBOARD7.exe
    O4 - HKLM\..\Run: [mousepad] C:\WINDOWS\MOUSEPAD7.exe
    O4 - HKLM\..\Run: [Launch App] c:\DMSINFO\launapp.exe
    O4 - HKLM\..\Run: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.EXE"
    O4 - HKLM\..\Run: [pop3trap.exe] "C:\Program Files\Trend PC-cillin 2000\pop3trap.exe"
    O4 - HKLM\..\Run: [WebTrap.exe] "C:\Program Files\Trend PC-cillin 2000\WebTrap.exe"
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [ALiSndMgr] ALiSndMg.exe
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [AcerPowerkey] "C:\Program Files\Acer\Powerkey\Powerkey.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb03.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
    O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
    O4 - HKLM\..\Run: [xfilter] "C:\Program Files\Filseclab\xfilter\xfilter.exe" -a
    O4 - HKLM\..\Run: [twister] "C:\Program Files\Filseclab\Twister\twister.exe" -a
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [PCCIOMON.EXE] "C:\Program Files\Trend PC-cillin 2000\PCCIOMON.EXE"
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Startup: Filseclab Messenger.lnk = C:\Program Files\Common Files\Filseclab\FilMsg.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O10 - Unknown file in Winsock LSP: c:\program files\filseclab\xfilter\xfilter.dll
    O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
    O16 - DPF: {719433EA-60DE-45A8-8255-115826F16D5B} (STConnectivityAgent Control) - http://communicate.domtech.co.uk/sam...TConnAgent.cab
    O16 - DPF: Sametime Meeting Room Client ST31 - http://communicate.domtech.co.uk/sam...RoomClient.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...29/mcfscan.cab

    -----------L2M9xfix log.txt -----------------
    Log of L2M9XFix v1.01a

    ************

    Running from directory:
    C:\WINDOWS\Desktop\l2m\l2m9xfix

    ************

    Files found:

    C:\WINDOWS\system\AFFSIPC.DLL
    C:\WINDOWS\system\ATVIEW32.DLL
    C:\WINDOWS\system\DBDRM.DLL
    C:\WINDOWS\system\ddvxdec_0411.dll
    C:\WINDOWS\system\dhdmo.dll
    C:\WINDOWS\system\DSDRM.DLL
    C:\WINDOWS\system\IGNPSTUB.DLL
    C:\WINDOWS\system\MBSCP.DLL
    C:\WINDOWS\system\MHYUV.DLL
    C:\WINDOWS\system\OCFOX32.DLL
    C:\WINDOWS\system\PVTOREC.DLL
    C:\WINDOWS\system\QYAP.DLL
    C:\WINDOWS\system\SPTUPAPI.DLL
    C:\WINDOWS\system\uzicows.dll
    C:\WINDOWS\system\VGRUN300.DLL
    C:\WINDOWS\system\WABCHECK.DLL
    C:\WINDOWS\system\WBICORE.DLL
    C:\WINDOWS\system\WOPLOC.DLL

    ************

    Registry entries found:

    [HKEY_CLASSES_ROOT\CLSID\{AB76B9BD-1EFD-4E9F-863C-F2D551274023}\InprocServer32]
    @="C:\\WINDOWS\\system\\ddvxdec_0411.dll"
    [HKEY_CLASSES_ROOT\CLSID\{0A6755F1-1A57-4E77-8280-F4AFDD856C68}\InprocServer32]
    @="C:\\WINDOWS\\SYSTEM\\SPTUPAPI.DLL"


    ************

    Killing Explorer
    Done!

    Killing Rundll32
    Done!

    Removing malicious CLSID(s)
    Done!

    Restarting Explorer
    Done!

    Deleting malicious files
    Done!


    Finished!
    ------------
    Randomman42:dancing-c

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Start Hijackthis and place a check next to these items If there.

    O4 - HKLM\..\Run: [keyboard] C:\WINDOWS\KEYBOARD7.exe
    O4 - HKLM\..\Run: [mousepad] C:\WINDOWS\MOUSEPAD7.exe

    Optional fix >
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    ====================================
    Hit fix checked and close Hijackthis.
    Restart the PC
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Replace the Hosts file
    http://www.mvps.org/winhelp2002/hosts.htm
    How To Download and Extract the HOSTS file:
    http://www.mvps.org/winhelp2002/hosts2.htm
    Replace it about once monthly to keep it updated

    Post back with another log . let us know of any problems.

  5. #5
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Im Glad we could help
    Since the problems are solved Im going to close the topic now, this keeps others with similar problems from posting there logs/question here, they should start a new topic.
    If you should need to post another log for the same PC let Me or Tashi know.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •