|
|
Dialer.ASDPlugin Dialer Information
| Name: |
Dialer.ASDPlugin |
| Category: |
Dialer |
| Advice: |
Remove |
| Risk: |
High Risk
High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer. |
| Description:
|
Dialer.ASDPlugin is a premium-rate adult dialer.
Dialer.ASDPlugin will attempt to disconnect any current modem connections and then connect to a predefined number. The dialler will then open a web page with Internet Explorer.
When first run, Dialer.ASDPlugin will copy itself to the Windows system folder. In order to run automatically each time a user logs in, Dialer.ASDPlugin will set the following registry entry:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
ASDPLUGIN
Dialer.ASDPlugin will create internet shortcuts named "Launch DerBiz.com" on the Desktop and in the Start menu.
Dialer.ASDPlugin will change the Start page of Internet Explorer by setting the following registry entry:
HKCUSoftwareMicrosoftInternet ExplorerMain
Start Page
Dialer.ASDPlugin will create the following registry branch:
HKLMSOFTWAREASDPLUGIN
Dialer.ASDPlugin provides an apparent uninstallation option named "Uninstall Launch DerBiz.com" to be found in the Start menu. However, when this option is used, Dial/Playgrnd-B will remain connected to the premium rate number but hide this fact by removing the dial-up icon from the Taskbar and Network connections list. The user may then have difficulty in disconnecting from the service.
|
| Signatures:
|
process: dbaccess.exe: MD5 Hash: bc10b47a33402764a47...
process: portugal.exe: MD5 Hash: f82a736f6f54af28e29...
process: dbaccess.exe: MD5 Hash: 1f59530244cc97a6db2...
process: belgium_nm.exe: MD5 Hash: 5014f826fe8968618d2...
process: russia.exe: MD5 Hash: a9c63fee3198c48539d...
process: dbaccess.exe: MD5 Hash: d98519bd2fbcb5f00b3...
process: finland.exe: MD5 Hash: 7f29692d717e351366d...
process: canada.exe: MD5 Hash: 70180a922a378cc9ae0...
process: france.exe: MD5 Hash: 3af9e00c9195866a530...
process: dbaccess.exe: MD5 Hash: bca46022ad06d4b8ba3...
process: belgium_nm.exe: MD5 Hash: ec3e07dd383456647cb...
process: mexico.exe: MD5 Hash: 2f66eae28183fa73c1a...
process: geaccess.exe: MD5 Hash: a16757f777fd39f693b...
process: geaccess.exe: MD5 Hash: 9d388f1e968d887d2da...
process: dbaccess.exe: MD5 Hash: b5f8f5fa6c122ed3731...
process: geaccess.exe: MD5 Hash: 6acfa206c0856ec40af...
process: uk_nm.exe: MD5 Hash: 4d99249e0967f5cc937...
process: turkey.exe: MD5 Hash: c28728ad0cdc7edb8a9...
process: geaccess.exe: MD5 Hash: 5be8f42e260a028886f...
process: dslgeaccess.exe: MD5 Hash: c1469e3e34597c47abe...
process: 100171be.exe: MD5 Hash: 2071a45c65035f0e44a...
process: dslgeaccess.exe: MD5 Hash: 87330b021494511b156...
process: turkey.exe: MD5 Hash: e59e0520854a5a78865...
process: czech.exe: MD5 Hash: 9c97911157773da8ee6...
process: dbaccess.exe: MD5 Hash: 106066dde9097155b9c...
process: netherlands.exe: MD5 Hash: a1b9a53e16fda2866bd...
process: finland.exe: MD5 Hash: d29e9405c956cea5cc2...
process: uk_nm.exe: MD5 Hash: 3fda1bb0c79f540bf64...
process: netherlands.exe: MD5 Hash: 9d98c79df67ccb8987b...
process: dbaccess.exe: MD5 Hash: ee3f213b53728c12fae...
process: dsldbaccess.exe: MD5 Hash: 28fec798f890b87c7e3...
process: adult1.exe: MD5 Hash: 098c8e731b97a1bff08...
process: geaccess.exe: MD5 Hash: 2e9bee67f44be9d8209...
process: canada.exe: MD5 Hash: b8c85ca8cd68b4952f3...
process: uk_nm.exe: MD5 Hash: c36ecab552fc2efa1d0...
process: dbaccess.exe: MD5 Hash: cc37669a0e8d855798e...
process: geaccess.exe: MD5 Hash: cb5101832a273a95b19...
process: dbaccess.exe: MD5 Hash: 3488221707313891c40...
process: russia.exe: MD5 Hash: 8361ccf8923bc953d03...
process: greece_nm.exe: MD5 Hash: 634f69b8bc6c2914587...
process: dsldbaccess.exe: MD5 Hash: b12c9556ae8a7e4d750...
process: dsldbaccess.exe: MD5 Hash: 4869b77eef1c8fa189c...
process: geaccess.exe: MD5 Hash: b2fe5225790fa9df813...
process: france.exe: MD5 Hash: 94e4df4e66a2680b105...
process: netherlands.exe: MD5 Hash: 80d0b232e0212705bb8...
process: 100176br.exe: MD5 Hash: 1f020fd13dbadc69080...
process: turkey.exe: MD5 Hash: f7e01c3f961cc057e9a...
process: greece_nm.exe: MD5 Hash: 76e9f2a42bca29394c4...
process: dbaccess.exe: MD5 Hash: 28b1b9c0810c50fc883...
process: temp532.exe: MD5 Hash: 61d416a324907e7f97a...
process: canada.exe: MD5 Hash: af3a8ceddad1ebd93e8.. |
| Type: |
Dialer - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Dialer Visited Pages:
Pornosex.Sesso - 367 visits
Pornosex - 286 visits
Trojan:Win32/Adialer.HT - 47 visits
Nocreditcard Sex Dialer - 45 visits
BTWebControl - 42 visits
Central24 - 38 visits
Dialer.Thehun - 37 visits
TIBS Premium Rate Dialer - 35 visits
SexyBills - 35 visits
Dialer.Wink - Alias: AutoSearchBHO, MSInfoSys - 34 visits
Random Dialer Pages:
Telexcharge.PornDialer
Pornosex.Sesso
Nocreditcard Sex Dialer
StripPlayer
SystemMD
EGroup.IEAccess.surfya - Alias: surfya
NetPrank
Eros Dialer
Dialer.CCAccess
OnlineDialer
|
|