1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan "Dialer"

Discussion in 'Security and Privacy' started by Master Green, 2004/01/01.

Thread Status:
Not open for further replies.
  1. 2004/01/01
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Hi,
    I am having a problem that appears others are having as well. I along with others virus protection is AVG. When it scans, it detects a Trojan called "Dialer ". Unofrtunately, Norton does not pick it up. Information I came across says to disable system restore (where AVG has been detecting it's location), go to files and folders, search the C/drive (the path attached to this trojan) and type in restore. Well restore does not find it, so I typed in "dialer" and came across the Trojan called "Phone Dialer" (that is the one known for dialing long distance calls) and deleted it. Lucky me, happy camper I was. But when I scan with AVG again, it continues to detect it. Does anyone have any clue as to what's happening here and can give me some guidance. I'm starting to wonder if AVG has the issue and not our computers ??? For informational purposes, this trojan or my computer are not creating any issues, just would like to get rid of it so the AVG will stop detecting it. Thanking you in advance...
     
  2. 2004/01/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Restore is a hidden file. Open C:, click tools>folder options>view tab and scroll down to show hidden files and check it. OK to close then do advanced search, checking in hidden files.
    When you find the dialer file right click it and scan with AVG to be sure you get the right one.
     

  3. to hide this advert.

  4. 2004/01/02
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Information I came across says to disable system restore (where AVG has been detecting it's location),
    =============
    Did you disable system restore ,, reboot then enable it again ?
    Disabling System Restore on Windows Me or Windows XP: http://www.pchell.com/virus/systemrestore.shtml

    third party programs cant clean when the file in question is there if they do or you manualy delete it would/could goof things up in the restore folder,, cousing even more problems.
    Please say so if you did manualy ? there is a fix

    also whats the whole name,, the virus avg finds,, we can search here for more info,, or have you already been there
    http://www.grisoft.cz/virbase/virbase.php

    Lonny
     
  5. 2004/01/02
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    I replied to your preious but zone alarm may have prevented my message from going out properly so if you received two replies from me I apologize.

    Anyways, yes I did disable "system restore ", and the re-enabled it. After I disabled it, I went (per instructions from www.itsecurity.com) into start, settings, files/folders and typed in "Dialer "...I found a few entries titled dialer but when I clicked on them they gave no indications they were the dialer I was in search of. However, I did come across the "Phone Dialer" which I was fortunate enough to have prior knowledge about and even though I did not know it was in my computer I deleted that bad boy. I have also gone into "startup" and the "registry" and was unable to find traces of it. I have done a few other things like have my "show file extensions" enabled, etc, etc in hopes of it showing up some where with no luck.

    You're assistance with this little rascal is very much appreciated.
     
  6. 2004/01/02
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Which operating system do you have? Does AVG specify the location of the file? You might wish to try this online scan
     
  7. 2004/01/02
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    I have Windows/Me...The AVG after it scans says:
    C:\Restore\temp\A0414765
    (Torjan Horse Dialer and it can not be quaruntined or deleted)

    Because it can't be removed, and it does not show up in any of the areas I have searched, plus I have come across a few others on the the computer who appear to be having the same problem I am starting to beleive that the AVG has picked up on something similiar in these computers and won't release it if you know what I mean. This is definetely challenging...
     
  8. 2004/01/02
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Clear your temporary internet files and then disable and re-enable system restore.
     
  9. 2004/01/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Which one is it?
    * Dialer.Aconti
    * Dialer.Comsoft
    * Dialer.ConnectParty
    * Dialer.Crosskirk
    * Dialer.Cyberbill
    * Dialer.Desire
    * Dialer.DialNet
    * Dialer.Dialpass
    * Dialer.DialXS
    * Dialer.Dilos
    * Dialer.DirectDialler
    * Dialer.Erostars
    * Dialer.Fite
    * Dialer.Flatfive
    * Dialer.Girlshost
    * Dialer.GizliGercekler
    * Dialer.Global
    * Dialer.GlobalDialer
    * Dialer.Gola
    * Dialer.Haldex
    * Dialer.Holistyc
    * Dialer.HotPleasure
    * Dialer.Indiax
    * Dialer.LiquidInc
    * Dialer.LiveVideo_fi
    * Dialer.Lohan
    * Dialer.Lovemenow
    * Dialer.LoveX
    * Dialer.Moneytree
    * Dialer.Myworld
    * Dialer.Paycenter
    * Dialer.Paydial
    * Dialer.Pecdialer
    * Dialer.Pornosex
    * Dialer.Pornostar
    * Dialer.Pornpaq
    * Dialer.Powerdial
    * Dialer.Prive
    * Dialer.Rampage
    * Dialer.Rapidblaster
    * Dialer.Rapidspark
    * Dialer.RASDialer
    * Dialer.SweetGirls_gb
    * Dialer.Target
    * Dialer.Trojan
    * Dialer.VividGal
    * Dialer.WebDialler
    * Dialer.Webview
    * Dialer.Winmuschi
    * Dialer.XXXAction
     
  10. 2004/01/02
    Dennis L Lifetime Subscription

    Dennis L Inactive Alumni

    Joined:
    2002/06/07
    Messages:
    2,557
    Likes Received:
    2
    Hi Broni

    I did a Google search on the first dialer on your list .... see the results... "Symantic Security Response" on top of the list ... the next 5 had the same results. Just copy the "Dialer Name" into Google search to checkout the rest of them. My assumtion.. they ALL will showup on Symantic list.
    For additional information for installed dialers...
    SpamAbuse.org - Helping Fight the War Against Spam. Spam ...
     
    Last edited: 2004/01/02
  11. 2004/01/02
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    I disabled "system restore" and emptied "Temp Internet Files" and then enabled "system restore" afterwards. Ran the AVG and "IT IS NOT DETECTING" the trojan "Dialer" at this time.

    I thank everyone for their help, it was great team work.
     
  12. 2004/01/02
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    I would still do one of the free online scans to be safe. Helped clean a computer couple weeks ago, AVG missed 3, Housecall got them.
     
  13. 2004/01/02
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Okay, I will try it per your recommendation and report back to you tomorrow (sat)...Thanks
     
  14. 2004/01/03
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Good news!
     
  15. 2004/01/03
    Master Green

    Master Green Inactive Thread Starter

    Joined:
    2002/12/03
    Messages:
    709
    Likes Received:
    2
    Howdy, I just wanted to do the final update. I ran the "Housecall" virus scan per the recommendation of a previous poster (aleekat) and it found nothing. So I guess we can close this case and once again I thank everyone for their assistance. Have no fear I will be back sooner rather than later with yet another challenging problem...Happy New Year to you all...
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.