It is currently Tue Sep 01, 2026 2:46 pm


Trojan Horse dialer.11.AU

All versions of Window XP and 2003 including 32 bit and 64 bit

Moderator: icecube

Trojan Horse dialer.11.AU

Postby living1 » Fri Oct 29, 2004 5:42 am

I recently received a PC running ME, infected with the above virus. I ran Ad-Aware after AVG said it had detected and cleaned the virus and it instantly re-appeared. HJT would not launch on this machine, it seemed as if the virus had some code to prevent it running. I searched online and could find no reference to dialer.11.AU. I eventually went to Trend's online scanner, which detected and 'removed' the trojan. Ran Ad-Aware again and there it was once more. There seemed to be two files operating, explorer.exe and internet.exe, which I know are part of various Trojans, etc.

In the end, I formatted the drive and re-installed the software, but it seemed a clumsy way of defeating the thing. The owner now has Ad-Aware, Spybot, Spyware Blaster, Zone Alarm, Firefox and AVG and has been warned to update frequently, butt I wonder if anyone can tell me what I might have done differently.

Thanks.
User avatar
living1
Newbie
Newbie
 
Posts: 4
Joined: Thu Oct 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby icecube » Fri Oct 29, 2004 6:11 am

You need to get a system with something that persistant into safe mode and then do your cleanup.

Basically what I do on a machine in for repairs, is to get the name of the virus, trojan etc. Then go to google and type in the name and the word "removal" Read the info, the solution is there.

If you are somewhat familiar with the registry, Mcafee has a very good virus library with excellent registry removal techniques. Sometimes if you type in the exact full name of the virus, you get nothing back. Just type in the most general part of it, like ie blaster, not the w32.blaster.3a--you'll get more hits

If you don't feel comfortable messing with the registry, then go to www.norton.com. They offer free removal tools for most of the popular virus. You really need to read the removal instructions, safe mode is often the recommended way to run the tools

Good luck
User avatar
icecube
Moderator
Moderator
 
Posts: 1209
Joined: Wed Mar 10, 2004 1:00 am
Location: San Marcos Ca

Thanks given:0
Thanks received:0
Top

Postby Cactus » Fri Oct 29, 2004 6:24 am

Hi living1 welcome to the Forum ... :)
I agree with Icecube...
All Trojan horses are hidden files so you would need to go to the Files Option (click the View tab)at Control Panel and uncheck both the *Hide file extension for known file types & *Hide protected operating system files (Recommended)-boxes, then OK yourself out. You will then need to restart your computer and and go into Safe Mode by holding the F8 key down -(kind of at the beginning of bootup). When you're at the DeskTop screen go to Start/ Search/ For Files and Folders and type up the NAME OF THE FILE & EXT which would have shown up on your Anti-Virus software, you can delete this file from here. Also, make sure to empty your Recycle Bin and TEMP Files.

There are Applications that will search your HDD for the HIDDEN Files and also allow you to delete them.
Hope that helped... :wink:

Cactus
User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Fri Oct 29, 2004 1:29 pm

Hiya living1
Everyone has their own way of removing Trojans and viruses. My way of course usually always works for me. I normally set the infected h.d.d. as a slave to a pc that is used mainly for this purpose. When you set a h.d.d as slave and scan for viruses it is much easier to remove because the infected h.d.d is not booted therefore the removal is much easier than when the pc is booted and all the processes are running. Theres no need to show hidden files and folders it just deletes the infected ones.
I've been using this method for years and it has never failed me yet. :)

Hope this info has been helpful
Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Thanks Guys

Postby living1 » Sat Oct 30, 2004 2:15 am

I had done everything Cactus & Icecube suggested, without success. Did not want to put every detail of the saga on the post, you'd have gone to sleep!
Geekgirl's suggestion of hanging the hdd off an IDE cable as slave was one that occurred to me, but since this seemed such a sneaky Trojan, I was a little nervous. The owner did not really want me to format, but it seemed the 'safest' way to kill the little ****. He's happy now it's gone and I saved all his data and re-loaded it.

Has any one else come across one that was 'launched' by Ad-Aware and disabled Hijack This?

Thank you all so much for your welcoming notes and the fast, helpful replies. :cool:
User avatar
living1
Newbie
Newbie
 
Posts: 4
Joined: Thu Oct 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Sat Oct 30, 2004 4:17 am

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Sneaky thing

Postby living1 » Tue Nov 02, 2004 1:02 am

It was only detected by AVG resident shield during a run of Ad-Aware. I would then launch AVG and it would remove the two .exes that were running. Everything would seem to be ok until I ran Ad-Aware again, then the process would be repeated. The only reference to the file names that I could find seemed to be in connection with a hijacker, but this puppy was a dialler. The poor guy had a huge phone bill to prove it.

I uninstalled Ad-Aware and did a virus scan and nothing showed-up. Re-installed and ran it once and nothing happened. Ran it again and bingo! There it was once more

Trend's online scanner found the Trojan and said it was removed - until I ran Ad-Aware again..... It killed Hijack This on launch, I was unable to run it at all on this machine. In retrospect, I probably could have put the hdd on an old machine I have here, but the virus' bizarre behaviour made me over-cautious. The guy is delighted to be rid of it, needless to say.

I'm not really seeking any more answers, just hoping to warn others.

Thanks for all your input Geek Girl. :wink:
User avatar
living1
Newbie
Newbie
 
Posts: 4
Joined: Thu Oct 28, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Windows XP and 2003

Who is online

Users browsing this forum: No registered users and 0 guests

cron