Casinoplaza in Explorer.exe

Discussion in 'adware, spyware & hijack cleaning' started by miket, Jun 9, 2004.

Thread Status:
Not open for further replies.
  1. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Hi,
    Somehow the following item keeps putting a shortcut on my desktop and an entery into my Win XP Prof internet dialer and it also trys to dial the number and causes me to get drop off/outs
    The entry is as follows
    C:\program files\internet explorer\iexplore.exe http://www.casinoplaza.com/index.php?sourceid=101969
    And the phone dialer is as follows
    name of "rst*.au" the no is 12345
    I have tryed numeous spyware tools but nothing seem's to find it or remove it as yet i canot find any reference to it in REGEDIT
    Has anyone got an idea on removal please ?
    Mike t o_O
     
  2. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Removal of "casinoplazza.com"

    I have a problem with the above it places a shortcut on my desktop and inserts a dialer into my dial up area and causes dropouts
    The location of it is
    "program files\internet explorer\iexplore.exe" http://www.casinaoplaza.com/index.php?sourceid=101969

    The dialer is this RST*.au the no is 12345
    i have been unable to locate it useing "regedit"
    can anyone offer another fix please

    Mike T
     
  3. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi miket,

    Can you see if you can find this file: C:\WINDOWS\hxdefdrv.sys ?
    Let me know.

    And try to keep all your posts on this subject in one thread by using the Reply button. Thanks.

    Regards,

    Pieter
     
  4. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Hi,
    please pardon my ignorance, but where do i look,
    and how or what program do i use to read it when and if i find it
    should i be worrying if i cant find it ??

    Mike T
     
  5. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi miket,

    Use the Find/Files in Windows:
    Start > Run > Find
    I am looking for possible infections and what infected people have in common, so we can come to a solution that works for all.

    Regards,

    Pieter
     
  6. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Hi,
    i was unable to find the suggested file , i told it to look in all files includeing system files and folders

    Trend security finds it but is unable to quarantine it

    Thanks Mike t
     
  7. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Can you give me the filename and the full path to the file Trend finds?

    Regards,

    Pieter
     
  8. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Hi Pieter,
    Thanks for your time so far the registry add is as follows

    "c:\windows\ system\d3dbpgk.dll "

    I contacted Trend they suggested i look in this area and it was exactly where they said but i delete it and it returns , i have a feeling it is actually somwhere else and keeps dropping copies when it see's the entry has been removed , so far it hasn't done any damage that i can see but trend keeps flashing up alarms and this gets annoying and makes me wonder if its sending my info outwards

    Thanks Mike t
     
  9. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Sorry that should read "c:\windows\ system 32 \d3dbpgk.dll "
     
  10. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Please surf to http://www.billsway.com/vbspage/ and scroll down to
    Registry Search Tool
    Download, unzip and run RegSrch.vbs
    Copy and paste this in the dialog box: d3dbpgk.dll

    After a while a prompt will come up. Click OK to write the results to wordpad and post them.

    Regards,

    Pieter
     
  11. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Sorry all i get is a HTML file not a program and it opens in an obscure editor i was trialing

    Mike T
     
  12. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
  13. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    sorry if i am annoying you

    i can still only get the html file

    i recently removed Java runtime files could this be a problem ??

    mike t
     
  14. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    I think that "obscure editor" you were trialing has taken over some file associations it shouldn't have.

    Can you see if uninstalling it fixes it?

    Regards,

    Pieter
     
  15. miket

    miket Registered Member

    Joined:
    Jun 9, 2004
    Posts:
    15
    Hi,
    I have no hair left my eye's are going funny , I Give Up

    Looks like a 40 Gig re-format for me Like i really need this

    Thanks Mike T
     
Thread Status:
Not open for further replies.