Virus issue
Moderators: Bakhtosh, EvilHomer3k
- Peacedog
- Posts: 13148
- Joined: Tue Oct 12, 2004 7:11 pm
- Location: Despair, level 5
- Contact:
Virus issue
Ok, I've used the most recent, fully updated, free version of AVG to clean a machine. 81 files found, but only 76 fixed. The other 5 identify as Trojan Horse Dialer.10.X (where xs = some letter). I think some of them are the same, others are different verisions of the virus (I guess).
AVG can't fix them. any ideas on what can?
ANd it looks like Trojan Horse Dialer.10.AH is the main culprit.
Also, today I got to see up close and personal what happens when you take a typical, technologically ignorant, family and expose them to the internet. I hope never to have to do this again in my life.
AVG can't fix them. any ideas on what can?
ANd it looks like Trojan Horse Dialer.10.AH is the main culprit.
Also, today I got to see up close and personal what happens when you take a typical, technologically ignorant, family and expose them to the internet. I hope never to have to do this again in my life.
- LawBeefaroni
- Forum Moderator
- Posts: 56531
- Joined: Fri Oct 15, 2004 3:08 pm
- Location: Urbs in Horto, bonded and licensed.
Go to a security site and follow removal instructions. May involve registry work, etc.
There are a ton of similarly named trojans at Symantec:
Dialer.comsoft.html
Dialer.xxxAction(cool name!
)
Find yours if it's there and follow their instructions.
There are a ton of similarly named trojans at Symantec:
Dialer.comsoft.html
Dialer.xxxAction(cool name!

Find yours if it's there and follow their instructions.
" Hey OP, listen to my advice alright." -Tha General
"“I like taking the guns early...to go to court would have taken a long time. So you could do exactly what you’re saying, but take the guns first, go through due process second.” -President Donald Trump.
"...To guard, protect, and maintain his liberty, the freedman should have the ballot; that the liberties of the American people were dependent upon the Ballot-box, the Jury-box, and the Cartridge-box, that without these no class of people could live and flourish in this country." - Frederick Douglass
MYT
"“I like taking the guns early...to go to court would have taken a long time. So you could do exactly what you’re saying, but take the guns first, go through due process second.” -President Donald Trump.
"...To guard, protect, and maintain his liberty, the freedman should have the ballot; that the liberties of the American people were dependent upon the Ballot-box, the Jury-box, and the Cartridge-box, that without these no class of people could live and flourish in this country." - Frederick Douglass
MYT
- Gedd
- Technical Admin
- Posts: 2812
- Joined: Wed Oct 13, 2004 12:00 am
Definitely check Symantec first. If that doesn't work, give http://www.free-av.com a shot.
- Rip
- Posts: 26952
- Joined: Tue Oct 12, 2004 9:34 pm
- Location: Cajun Country!
- Contact:
Ahhaah, little problem with the ol porn dialers heh? Often when a file can't be repaired you can delete it. Occasionally even having to boot to safe mode with command prompt to do so.
Look up the info on the particular virus removal instructions at symantec, and the fact I'm a Symantec partner influences my opinion only slightly
Look up the info on the particular virus removal instructions at symantec, and the fact I'm a Symantec partner influences my opinion only slightly

“A simple democracy is the devil’s own government.”
— Benjamin Rush
--
— Benjamin Rush
--
- Peacedog
- Posts: 13148
- Joined: Tue Oct 12, 2004 7:11 pm
- Location: Despair, level 5
- Contact:
It's funny, this was at work but it isn't even work related (the machine is property of a friend of the bosses).
Adaware removed 480something spyware files. AVG removed 76 infected virus files. When I left, free-av seemed to be doing its thing quite well, we'll see how that went tomorrow I guess. 3 users use the computer, and that's clearly 3 to many from a "do you have any basic understanding of internet security" standpoint.
I also learned that Dell's proprietary OS sucks. That is all.
Adaware removed 480something spyware files. AVG removed 76 infected virus files. When I left, free-av seemed to be doing its thing quite well, we'll see how that went tomorrow I guess. 3 users use the computer, and that's clearly 3 to many from a "do you have any basic understanding of internet security" standpoint.
I also learned that Dell's proprietary OS sucks. That is all.
- Rip
- Posts: 26952
- Joined: Tue Oct 12, 2004 9:34 pm
- Location: Cajun Country!
- Contact:
For future reference another tactic I use sometimes is take the drive out and install as a second drive in a machine with Norton or whatever quality AV software and scan it from that. This will allow files that would have been in use to be dealt with.Peacedog wrote:It's funny, this was at work but it isn't even work related (the machine is property of a friend of the bosses).
Adaware removed 480something spyware files. AVG removed 76 infected virus files. When I left, free-av seemed to be doing its thing quite well, we'll see how that went tomorrow I guess. 3 users use the computer, and that's clearly 3 to many from a "do you have any basic understanding of internet security" standpoint.
I also learned that Dell's proprietary OS sucks. That is all.
“A simple democracy is the devil’s own government.”
— Benjamin Rush
--
— Benjamin Rush
--
- EvilHomer3k
- Forum Moderator
- Posts: 8088
- Joined: Tue Oct 12, 2004 10:45 pm
- Location: Cedar Rapids, IA
Some other things to consider when finished:
Install SP2
Set up Adaware/Spybot to run as scheduled tasks
delete Kazaa
You can also try stinger. It is a free virus removal tool that we use at work. Works pretty well. We use a combination of Norton, stinger, AdAware, and spybot for most of the computers we work on. At the beginning of the year, our office worked on over 200 computers for incoming students. Many of them had over 3000 pieces of spyware and several hundred viruses. The worst one had nearly 6000 instances of spyware. They complained that the computer was a bit slow. Hmm. I wonder why.
Install SP2
Set up Adaware/Spybot to run as scheduled tasks
delete Kazaa
You can also try stinger. It is a free virus removal tool that we use at work. Works pretty well. We use a combination of Norton, stinger, AdAware, and spybot for most of the computers we work on. At the beginning of the year, our office worked on over 200 computers for incoming students. Many of them had over 3000 pieces of spyware and several hundred viruses. The worst one had nearly 6000 instances of spyware. They complained that the computer was a bit slow. Hmm. I wonder why.
- Peacedog
- Posts: 13148
- Joined: Tue Oct 12, 2004 7:11 pm
- Location: Despair, level 5
- Contact:
Ok. AVG still recognizes Dialer.10.AH. there's lots of dialer stuff at Symantec, but nothing that looks like that.
So, AVG is not recognizing the name of the virus quite right, or .10.AH is AVG for "that Dialer over there".
The resident shield (the active scanner) is picking up a file in the windows/system/32 folder - wdm.dll. It's calling it Backdoor.Agent.BA. This is consistent with Backdoor.Agent.B according to symantec - right down to the .dll files with random characters in the name in that folder.
However, the Backdoor.Agent.B removal tool didn't find the particularl virus on the machine. So I feel like I am back to square one. FWIW, stinger didn't find anything. AntiVir did remove some stuff - but I still get these two particular issues.
Oh, and system restore is disabled right now. All commentary to this point is greatly appreciated (and fwiw, whenever the machine is up and running they'll have spybot, adaware, and something that isn't IE to work with). Will a clean windows install be of any benefit (my guess is no, but what do I know)?
So, AVG is not recognizing the name of the virus quite right, or .10.AH is AVG for "that Dialer over there".
The resident shield (the active scanner) is picking up a file in the windows/system/32 folder - wdm.dll. It's calling it Backdoor.Agent.BA. This is consistent with Backdoor.Agent.B according to symantec - right down to the .dll files with random characters in the name in that folder.
However, the Backdoor.Agent.B removal tool didn't find the particularl virus on the machine. So I feel like I am back to square one. FWIW, stinger didn't find anything. AntiVir did remove some stuff - but I still get these two particular issues.
Oh, and system restore is disabled right now. All commentary to this point is greatly appreciated (and fwiw, whenever the machine is up and running they'll have spybot, adaware, and something that isn't IE to work with). Will a clean windows install be of any benefit (my guess is no, but what do I know)?
- Rip
- Posts: 26952
- Joined: Tue Oct 12, 2004 9:34 pm
- Location: Cajun Country!
- Contact:
I would rename the file "wdm.dll" if it is in use you may have to boot to a safe command prompt to do so.Peacedog wrote:Ok. AVG still recognizes Dialer.10.AH. there's lots of dialer stuff at Symantec, but nothing that looks like that.
So, AVG is not recognizing the name of the virus quite right, or .10.AH is AVG for "that Dialer over there".
The resident shield (the active scanner) is picking up a file in the windows/system/32 folder - wdm.dll. It's calling it Backdoor.Agent.BA. This is consistent with Backdoor.Agent.B according to symantec - right down to the .dll files with random characters in the name in that folder.
However, the Backdoor.Agent.B removal tool didn't find the particularl virus on the machine. So I feel like I am back to square one. FWIW, stinger didn't find anything. AntiVir did remove some stuff - but I still get these two particular issues.
Oh, and system restore is disabled right now. All commentary to this point is greatly appreciated (and fwiw, whenever the machine is up and running they'll have spybot, adaware, and something that isn't IE to work with). Will a clean windows install be of any benefit (my guess is no, but what do I know)?
Reboot and if you get no errors yu are saft to delete it. I have read reports of people having to take ownership of this file and remove the read-only attribute to be able to delete it.
Also have you ran hijackthis and noted the results. E-mail it to me and I'll let you know if I see any alarming entries.
“A simple democracy is the devil’s own government.”
— Benjamin Rush
--
— Benjamin Rush
--
- Peacedog
- Posts: 13148
- Joined: Tue Oct 12, 2004 7:11 pm
- Location: Despair, level 5
- Contact:
Ok. . .
We went in and renamed it through the command prompt safe mode. Everything booted normally after that, but we couldn't delete it in normal mode. We tried deleting it through the command prompt, and still couldn't. Woooo. I don't know the ownership status of the file, but that's clearly something we'd need to do in normal safe mode, via the administrator.
Edit: we were having trouble doing that, but we finally figured out why. The file is gone. On to phase 2.
I think this is all that stands between me and freedom.
Our new theory here that this is the file that allows Uncle Bill to look at us through our monitors, fwiw.
We went in and renamed it through the command prompt safe mode. Everything booted normally after that, but we couldn't delete it in normal mode. We tried deleting it through the command prompt, and still couldn't. Woooo. I don't know the ownership status of the file, but that's clearly something we'd need to do in normal safe mode, via the administrator.
Edit: we were having trouble doing that, but we finally figured out why. The file is gone. On to phase 2.
I think this is all that stands between me and freedom.
No but I have it, and can run it after lunch.Also have you ran hijackthis and noted the results.
Our new theory here that this is the file that allows Uncle Bill to look at us through our monitors, fwiw.