¡¡¡¡AYUDAAAAAAAAA¡¡¡ CON EXDIALER

Responder
MALPORRO
Mensajes: 1
Registrado: 13 May 2004, 00:39

¡¡¡¡AYUDAAAAAAAAA¡¡¡ CON EXDIALER

Mensaje por MALPORRO » 13 May 2004, 00:53

ESTOY DESESPERADO.. TENGO UN DIALER QUE SE LLAMA EXDIALER QUE EL MUY HIJO DE P.... ME APARECE SIN DARME CUENTA , ME CORTA LA CONEXION A INTERNET Y ME LLAMA A UN NUMERO DE ESOS DE PAGO... PERO TODO ESTO SIN DARTE APENAS CUENTA.



LO HE INTENTADO TODO.. AD-AWARE,SPYBOT Y OTROS.. NO SE QUE HACER YA...



ESTARIA MUY AGRADECIDO SI ME AYUDARAIS





SALUDOS DE MALPORRO...[/code]

cañera
Mensajes: 1468
Registrado: 09 Mar 2004, 21:02
Ubicación: la palma s/c tenerife

Mensaje por cañera » 13 May 2004, 01:56

mira si puedes solucionarlo si no,nos pasas los datos del hijackthis;

https://foros.zonavirus.com/viewtopic.php?t=693&highlight=dialer

cuentanos como te fue.
Antes de preguntar - Normas Basicas - Mensajes Privados - Repetir Temas - Continuar Temas - Titulos del Tema - Antivirus Online
No me quieras por lastima.
quiereme por lo que soy... no por lo que esperes de mi.(Anonimo,mio mismo)

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 14 May 2004, 14:06

Mira lo indicado por Symantec sobre un EXDIALER, por si fuera tu caso:



Dialer.ExDialer

Last Updated on: December 30, 2003 08:46:39 AM













Type: Dialer



Name: exDialer





Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Systems Not Affected: Linux, Macintosh, OS/2, UNIX



Removal: Low

Damage: Low









Intelligent Updater Definitions*

December 30, 2003





LiveUpdate™ Definitions **

December 31, 2003





*

Intelligent Updater definitions are released daily, but require manual download and installation.

Click here to download manually.



**

LiveUpdate definitions are usually released every Wednesday.

Click here for instructions on using LiveUpdate.











This threat can be detected only by Symantec products that support expanded threats. For more information on expanded threats, please go here.







Behavior

Dialer.ExDialer is a dialer program that gives the user access to premium services of a third-party Web site by dialing a high cost number using a modem.



Symptoms

Your Symantec antivirus program detects Dialer.ExDialer.



Transmission

Usually installed through a third-party Web site by embedding the executable in an .html file.













File names: varies



When Dialer.ExDialer is activated, it performs the following actions:





Moves itself to %System%\ShellExt\d.exe.





--------------------------------------------------------------------------------

Note: %System% is a variable. The dialer locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

--------------------------------------------------------------------------------





Creates the registry keys:



HKCU\Software\Freeware

HKCU\Software\Freeware\{FFB51760-344E-4FFB-BFFF-4B18C7AC1D63}

HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCD4F5CD-C5BC-4645-BF61-9F4EEBDD19CC}



which holds various configuration information for the dialer.



May create the registry value:



"exDialer"="%System%\ShellExt\d.exe"



in the registry key



HKLM\Software\Microsoft\Windows\CurrentVersion\Run









The following instructions pertain to all Symantec antivirus products that support Expanded Threat detection.





Update the definitions.

Uninstall exDialer using the Add/Remove Programs utility.

Run a full system scan and delete all the files detected as Dialer.ExDialer.

Delete the value that was added to the registry.



For specific details on each of these steps, read the following instructions.



1. Updating the definitions

To obtain the most recent definitions, start your Symantec program and run LiveUpdate.



2. Uninstalling the Adware

Do one of the following:

On the Windows 98 taskbar:

Click Start > Settings > Control Panel.

In the Control Panel window, double-click Add/Remove Programs.

On the Windows Me taskbar:

Click Start > Settings > Control Panel.

In the Control Panel window, double-click Add/Remove Programs.

If you do not see the Add/Remove Programs icon, click "...view all Control Panel options."

On the Windows 2000 taskbar:

By default, Windows 2000 is set up the same as Windows 98. In that case, follow the Windows 98 instructions. Otherwise, click Start, point to Settings, point to Control Panel, and then click Add/Remove Programs.

On the Windows XP taskbar:

Click Start > Control Panel.

In the Control Panel window, double-click Add or Remove Programs.

Click exDialer.



--------------------------------------------------------------------------------

Note: You may need to use the scroll bar to view the whole list.

--------------------------------------------------------------------------------



Click Add/Remove, Change/Remove, or Remove (this varies with the operating system). Follow the prompts.



3. Scanning for and deleting the files

Start your Symantec antivirus program and run a full system scan.

If any files are detected as Dialer.ExDialer, click Delete.





--------------------------------------------------------------------------------

Notes:

If your Symantec antivirus product reports that it cannot delete a detected file, write down the path and file name. Then use Windows Explorer to locate and delete the file.

If you ran the Add/Remove programs applet as described in the previous section, it is possible that all files were removed and therefore none will be detected.

--------------------------------------------------------------------------------



4. Deleting the values from the registry



--------------------------------------------------------------------------------

WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

--------------------------------------------------------------------------------





--------------------------------------------------------------------------------

Note: This is done to make sure all keys are removed. They may not be there if they were removed by the uninstaller.

--------------------------------------------------------------------------------





Click Start, and then click Run. (The Run dialog box appears.)

Type regedit



Then click OK. (The Registry Editor opens.)





Navigate to the key:



HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run





In the right pane, delete the value:



"exDialer"="%system%\ShellExt\d.exe"





Navigate to and delete the registry keys:



HKCU\Software\Freeware

HKCU\Software\Freeware\{FFB51760-344E-4FFB-BFFF-4B18C7AC1D63}

HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCD4F5CD-C5BC-4645-BF61-9F4EEBDD19CC}





Exit the Registry Editor.





__________________________________________





Si encontraras dentro de tu directorio de sistema, la carpeta ShellExt y dentro de ella, el fichero d.exe , envianoslo a zonavirus@satinfo.es y trataríamos de hacer una utilidad especial de eliminacion especifica. Si es el caso, envianoslo anexadoi a un mail dirigido a zonavirus@satinfo.es , cuyo texto sea un copiar y pegar de este post



saludos



ms, 14-05-2004

Responder

Volver a “Foro Virus - Cuentanos tu problema”