PDA

View Full Version : Being redirected to btcar.com



coldnorth
05-19-2006, 01:45 AM
I have some new bit of scumware on my computer that is redirecting me to a site called btcar.com. Anyone have any idea what it might be and how to get rid of it? Thanks

peat moss
05-19-2006, 02:13 AM
This one ? http://btcar.com/

coldnorth
05-19-2006, 03:17 AM
Yep, that looks like it

peat moss
05-19-2006, 03:40 AM
What antispyware are you running , never heard of that one . Browser hijack I'm guessing but easy to fix I'm sure .


Have you tryed an online scan , like Trend Micro or the like ? Giant or a similar antisptware has a option to revert back to default settings .


I'm thinking you have to tighting up your anti malware programs , sounds easy I know but I'm surprised that Ive never heard of that btcar. cookie or what ever you what to call it .


After some thought it would piss me off to have to suffer with the malware crap .

Hijackthis may be of some help . I'll be honest and admit I don't understand all the entries but still : http://www.hijackthis.de/

coldnorth
05-19-2006, 01:10 PM
I have run Trend, which did find a lot of garbage but left this, also ad-aware and spybot. I have also noticed a lock.exe file popping on and off now and then. It's located in C:\program files\internet explorer. Is this a valid windowns file?

peat moss
05-21-2006, 01:03 PM
Funny just had a similar problem yesterday friend had 12 Trojans , Trend Micro found but could n't correct . Hijackthis helped but still had a browser hijack .

I D/L a Trojan remover it was a 30 day trial but fixed the problem after countless tries . :dry:


http://www.majorgeeks.com/download903.html

coldnorth
05-21-2006, 03:29 PM
I'll give it a try peat. Still have something left on here that is being a pain.

coldnorth
05-21-2006, 03:34 PM
I can't get to the site peat moss. Might not be the site, but whatever is on this computer. I have noticed that whenever I try to visit any site like Trend or Panda I either get re-directed or it simply will not load. I'll run hi-jack this and see what I can find and then try the site again.

peat moss
05-21-2006, 05:58 PM
Have a look at whats starting at start up , maybe post your hijackthis log here and someone will help .

Patience friend it took me all morning yesterday , to solve my friends puter it was a combination of things that helped me solve it . Good luck .

coldnorth
05-22-2006, 09:43 PM
I'll post a hi-jact this log on a couple of minutes. I have looked at the log and didn't notice anything to get too upset about, but I might have missed something.

coldnorth
05-22-2006, 09:52 PM
Here's the log peat

Logfile of HijackThis v1.98.2
Scan saved at 4:51:31 PM, on 5/22/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Documents and Settings\Dallas\Desktop\Programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myway.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O1 - Hosts: auto.search.msn.com 127.0.0.1
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - C:\WINDOWS\system32\winbrume.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [Microsoft RPM Security] msrpm.exe
O4 - HKLM\..\RunServices: [Microsoft RPM Security] msrpm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft RPM Security] msrpm.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124249103391
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4011E080-89B0-4568-975C-1FC132EBC210}: NameServer = 207.40.103.4 207.40.103.5

RealitY
05-22-2006, 10:02 PM
Try this...
http://www.hijackthis.de/

coldnorth
05-23-2006, 01:28 AM
Thanks Reality, I'll check it out.

dodgy368
05-23-2006, 02:35 PM
Clear out your temporary internet folder and also remove winbrume.dll, it's a browser hijacker.;)

coldnorth
05-23-2006, 03:54 PM
Thanks. I have removed the winbrume.dll file but still having a bit of problem. I no longer seem to be re-directed to the btcar site but I am having other difficutlies. For instances, one particular site I go to often I can view and access the main page but am not able to access any of the stories on sub-pages.

dodgy368
05-23-2006, 04:46 PM
Thanks. I have removed the winbrume.dll file but still having a bit of problem. I no longer seem to be re-directed to the btcar site but I am having other difficutlies. For instances, one particular site I go to often I can view and access the main page but am not able to access any of the stories on sub-pages.

If you were on that site when you emptied your temp folder then you'll need to refresh the page.:)

If not, what's the site and I'll have a look?

coldnorth
05-24-2006, 01:08 AM
Thanks. The sit is http://www.rightnation.us/news.php but I am fairly certain the problem is with me, not them.

peat moss
05-24-2006, 01:44 AM
There was something so simple I forgot to point it out , turn off System Restore . It sounds like your getting closer tho .

I don't have a problem with that page using IE or FF . I copied your log file on Hihjackthis de . as Reality suggested if you just fix the "nasties" your half way there. Upgrade your IE browser too and if using Spybot enable the Tea timer thing ?

Still say to tighten up your Malware program and try a different browser
see if that solves the problem . :)

peat moss
05-24-2006, 01:59 AM
Thanks. The sit is http://www.rightnation.us/news.php but I am fairly certain the problem is with me, not them.



Wholly shit you read that stuff ? You belong in the Drawing Room Buddie ! :D
Which ain't a bad thing by the way . :)

coldnorth
05-24-2006, 07:04 AM
ok, I admit it, I'm a right winger. Cold hearted republican and all that stuff.


I did clear the temp. internet folder and no changes. Anyone have any ideas?

Thanks everyone

peat moss
05-27-2006, 12:19 AM
Well if you tried all of the above I don't know what else to suggest other than formatting and reinstall .

As I said it took me many tries on my friends computer . My own system I would of just booted from Winxp and be done with it , but I "Back Up" religiously so its not a problem .

coldnorth
06-03-2006, 01:59 AM
Thanks everyone. This one is puzzling. I really do not want to reformate or reinstall XP so I'll keep messing with it a while. Thanks again