
and the desktop looking like this :

The "Click here" part doesnt work for me either , so I cant even give them any of my money..
---------------------------------
Sites / IP's logged :
---------------------------------
QUOTE
hxxp://82.179.170.11/dia489/
.www.pfl-enlarge.com
66.235.192.134
hxxp://dl.ad-ware.cc/qUl3xBTG6Ifg_Po6L8aR.chm
hxxp://dl.ad-ware.cc/OaeTHxQtGmyf683m1ZPk.chm
hxxp://dl.ad-ware.cc/c1-BlB9oRO4-YJDYrd6m.chm
hxxp://dl.ad-ware.cc/PARggnRP-9wvtzmvjDHG.chm
hxxp://www.britroadsters.com/enter.php
hxxp://www.karupsgirls.net/news.html
hxxp://www.karupsgirls.net//style.css
hxxp://www.tendomain.com/loader83.exe
hxxp://alfaportal.com/c/l/83.0.51WP2600
.www.pfl-enlarge.com
66.235.192.134
hxxp://dl.ad-ware.cc/qUl3xBTG6Ifg_Po6L8aR.chm
hxxp://dl.ad-ware.cc/OaeTHxQtGmyf683m1ZPk.chm
hxxp://dl.ad-ware.cc/c1-BlB9oRO4-YJDYrd6m.chm
hxxp://dl.ad-ware.cc/PARggnRP-9wvtzmvjDHG.chm
hxxp://www.britroadsters.com/enter.php
hxxp://www.karupsgirls.net/news.html
hxxp://www.karupsgirls.net//style.css
hxxp://www.tendomain.com/loader83.exe
hxxp://alfaportal.com/c/l/83.0.51WP2600
--------------------------------------
Outpost HTTP Log1:
http://www.bluetack.co.uk/H4X0RZ/hijacks/h...llbilly_log.txt
--------------------------------------
Files used :
on.exe
windows\downloaded program files\open.exe
a.bat
local settings/temp/oiho.exe
loader83.exe
WINDOWS\system32\intell32.exe
WINDOWS\system32\wppp.html
WINDOWS\uninstIU.exe
WINDOWS\System32\oleext.dll
WINDOWS\System32\oleext32.dll
Inside on.exe :
CODE
'hxxp://www.tendomain.com/loader83.exe',0
'hxxp://www.tendomain.com/krabz.exe',0
'82.179.170.11',0
'dl.ad-ware.cc',0
'dia489',0
'boards.cexx.org',0
'adultwebmasterinfo.com',0
'spywareinfo.',0
'dialerschutz.de',0
'webmasterworld.com',0
'crutop.nu',0
'isdn',0
'modem',0
'explorer.exe',0
'hxxp://www.tendomain.com/krabz.exe',0
'82.179.170.11',0
'dl.ad-ware.cc',0
'dia489',0
'boards.cexx.org',0
'adultwebmasterinfo.com',0
'spywareinfo.',0
'dialerschutz.de',0
'webmasterworld.com',0
'crutop.nu',0
'isdn',0
'modem',0
'explorer.exe',0
On reboot wininet.dll will be renamed/replaced by oleext32.dll
C:\WINDOWS\System32\oleext32.dll

----------------------------
Hijack this log entries :
----------------------------
CODE
C:\WINDOWS\System32\intell32.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} -
ms-its:mhtml: file://C: \foo.mht ! hxxp://dl.ad-ware.cc/PARggnRP-9wvtzmvjDHG.chm : : /on.exe
O16 - DPF: {11111111-1111-1111-1111-222222222222} -
ms-its:mhtml : file://d: \foo.mht ! hxxp://www.karupsgirls.net//style.css : : /open.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\System32\intell32.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} -
ms-its:mhtml: file://C: \foo.mht ! hxxp://dl.ad-ware.cc/PARggnRP-9wvtzmvjDHG.chm : : /on.exe
O16 - DPF: {11111111-1111-1111-1111-222222222222} -
ms-its:mhtml : file://d: \foo.mht ! hxxp://www.karupsgirls.net//style.css : : /open.exe
---------------------------------------
www.tendomain.com
10 Domains
www.Barberpole.biz
www.Car8au.com
www.Exitrafic.net
www.Gomduri.info
www.K-time.info
www.Korearent114.com
www.Search4best.net
www.Searchingwww.net
www.Tendomain.com
www.Usedsale.info
218.38.13.220
218.38.13.0 - 218.38.13.255
Hanaro Telecom Inc.
Shindongah Bldg, 43, Taepyeongno2-ga, Jung-gu
SEOUL
100-733
Korea, Republic of
----------------------------------
www.britroadsters.com
www.pfl-enlarge.com
5348 domains
63.241.136.205
hosting105.secureserver.net
63.240.0.0 - 63.242.255.255
CERFnet
----------------------------------
66.235.192.134
186 Domains
66.235.192.0 - 66.235.223.255
iPowerWeb, Inc
-----------------------------------
www.karupsgirls.net
64.202.166.208
64.202.160.0 - 64.202.191.255
Go Daddy Software, Inc.
-----------------------------------
dl.ad-ware.cc
www.Cool-bookmark.com
www.Searcher.ws
www.Startpage.ws
www.The-right-start.com
www.The-startpage.com
195.225.177.22
ip177-22.netcathost.com
195.225.176.0 - 195.225.179.255
NetcatHosting
Ukraine
----------------------------------
alfaportal.com
69.31.85.154
69.31.80.0 - 69.31.87.255
Pilosoft, Inc
Domain servers:
NS1.HARDCOREOVER.COM - 66.250.130.200
NS2.HARDCOREOVER.COM - 69.31.80.114
Administrative Contact:
Magel, Irgi
na Prikope 16
Praha, PG 16300
CZ
723101427
--------------------------------
hxxp://82.179.170.11/dia489/
82.179.170.11
82.179.160.0 - 82.179.175.255
netname: RUNNET-ILCA1
descr: ICS TM, JSC
descr: 70 Bolshoy pr. V.O.
descr: 199002 St.-Petersburg
country: RU
---------------------------
Happy snaps :
---------------------------








@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
More info here on infection and removal:
Win32.Alemod.H
http://www3.ca.com/securityadvisor/virusin...s.aspx?id=43729
http://securityresponse.symantec.com/avcen...ophijack.c.html
http://www.greatis.com/appdata/d/_/_sysdir...dll_Removal.htm
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@










