Question

How to remove Trojan Horse Dialer

Asked by: tato374

AVG Free Edition has identified Trojan Horse Dialer in 2 files   [bodystudio(installer).exe and body_st.exe in my Shareaza\Downloads dir.  But it can't move them.

Originally, there were 7 files of which Trend Micro's House-scan identified and deleted 5 (but not the others!)

I've tried the Trend, Panda and Symantec on-line scans which didn't recognise it. I've tried Spybot S&D and Moosoft's The Cleaner - which didn't recognise it.

I did stupidly perhaps try to move the files to a floppy but the system crashed. Otherwise there seem to be no ill-effects to the computer since this morning's scan identified the trojan.

I'm on Broadband so I presume this trojan, which is supposed to make expensive international calls, can't operate.

I cant use the AVG Rescue Disk floppy which I'd already made, because for some reason my computer won't boot from the floppy (despite altering the BIOS Setup) or the CD.

So any ideas how I can destroy these unwelcome guests? Any ways of deleting them directly? A system restore perhaps? (I'm an Athlon XP 1800, Win XP NTFS ).

Many thanks for any help.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2003-02-21 at 09:14:20ID20524124
Tags

trojan

,

horse

,

dialer

,

remove

,

how

Topic

Anti-Virus Applications

Participating Experts
11
Points
0
Comments
18

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. IRC Trojans
    Not quite sure if this is the right place for this question, but wanted as broad a spectrum of expertise as possible looking at it. I have a telecommutter working from home, running W2K Pro, on three partitions ("C"=OS Only, "D"= Apps, and "e"=L...
  2. CoolWebSearch trojan
    My computer has been hijacked by the cool web search trojan. I did an ad-aware scan, Spybot search & destroy and a Norton anti-virus check and nothing worked. I also tried the cws shredder but to no avail. Is there anybody out there who could help me. I've spent quite a f...
  3. Trojan removal software
    Anyone have any opinions on the software Trojan Remover by Simply Super Software? Do you recommend anything else for removing trojans?

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: guidwayPosted on 2003-02-21 at 11:07:52ID: 7994806

do you have any filesharing programs installed like Kazaa. That installs all kinds of programs to the computer and some of them can get detected as trojans. I'm thinking that maybe this is just a false alarm and that it is a mistake from your virus scanner. I could be wrong though...

 

by: tato374Posted on 2003-02-21 at 15:53:22ID: 7996355

oh yes - the files came in the form of a program d/l by mistake from P2P network, Shareaza - "bodystudio"  "bodystudioinstaller.exe" - I thought it might be a graphics program! ..but it presumably dials to a porn site...

I have discovered something else ... Windows seems to have locked the files... it gives "Access is denied" when I run Moosoft's The Cleaner on the relevant folder so that may be blocking the antivirus/trojan programs. [I have Win XP Pro SP1]

Thanks for interest. Any more ideas?

 

by: FlamingSwordPosted on 2003-02-21 at 16:59:36ID: 7996583

> Originally, there were 7 files of which Trend Micro's House-scan identified and deleted 5 (but not the others!)

Thanks for saying so. I had same luck (incomplete) with them on a virus.

> seems to have locked the files... it gives "Access is denied" when I run Moosoft's

That product is also rather stupid. Especially concerning False positives on MS products and no clear knowledge of what essential programs it is not supposed to touch. Be thankful it was stopped by OS from doing all that it tries.

I don't know what this one is, but I do know that sometimes it pays to rebuild the unit from scratch, to save the debugging time and get back to more productive time.

You might consider other AV or adware, if that is what this is. If you are not intimidated by RegEdit, you might look here:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run

 

by: FlamingSwordPosted on 2003-02-21 at 17:08:36ID: 7996619

http://securityresponse.symantec.com/avcenter/venc/data/dialer.trojan.html
Dialer.Trojan  
Discovered on: January 09, 2001  
Last Updated on: April 15, 2002 04:46:10 PM
This Trojan dials phone numbers that have a 900 area code.
Also Known As: TROJ_PORNDIAL.A, PORNDIAL.1, PORNDIAL.A, PornDial
Wild:

Number of infections: 0 - 49
Number of sites: 0 - 2
Geographical distribution: Low
Threat containment: Easy
Removal: Easy  
   
Wild: Low
Damage: Low
Distribution: Low
 
-------------------------------

Looks lame enough, no regedits listed there.

You really should try booting a diskette, but you probably skipped the step for creating one, and the older boot diskettes won't work with NTFS. That gives alternative delete method by using different OS that doesn't lock file. oR IS IT LOCKKED WELL?

Use explorer to find files, then review their properties. Undo anything that makes them hidden or system files. hen delete.


 

by: stevenlewisPosted on 2003-02-21 at 17:13:36ID: 7996638

look in the add/remove programs

 

by: tato374Posted on 2003-02-21 at 19:45:33ID: 7997192

thanks guys for comments. here's what I did - which I think raises an important question about how to deal with trojans/viruses. And I'd be grateful for feedback.

First of all, I had no joy with any of various programs for Trojans/viruses etc. Anti-Trojan actually crashed the system again.

So, being impatient, I took a risk (which may prove to be stupid) ..-

I went into Command [I'm on XP Pro] and vaguely remembering my DOS, went into the trojan's directory, and after a lot of fiddling to get the names right, deleted the files. Was that OK or dumb?

[The files are now gone, and AVG detects nothing, but who knows what tomorrow may bring?]

Is that a legitimate way of dealing with trojans or viruses? For example, AVG has created a virus vault for 2 previous viruses - could I delete them from Command [is it DOS by the way?] Oh I'm Win XP Pro NTFS.

If this is an OK approach, it's worth knowing. If not, pray for me.

 

by: tato374Posted on 2003-02-21 at 19:52:37ID: 7997225

just to say thanks again FlamingSword and StevenLewis for taking the trouble

 

by: stevenlewisPosted on 2003-02-21 at 19:57:55ID: 7997250

>Is that a legitimate way of dealing with trojans or viruses? For example, AVG has created a virus vault for 2 previous viruses - could I delete them from Command [is it DOS by the way?] Oh I'm Win XP Pro NTFS
actually this is a good way to do it :~)

 

by: PikaPosted on 2003-03-08 at 05:29:32ID: 8093682

when you try to delete the trojan file and you get an access violation error, that's because windows is running that program. to delete it, just go to safe mode (with a boot floppy) and then delete it.

 

by: Shadow_HawkPosted on 2003-03-10 at 03:42:33ID: 8102072

>> I no longer have problems w: Trojans/Dialers/Keyloggers/Hijackers/Trackers/BDE Projectors/etc...

Anyone having problems in this area, email me and I'll give 'ya a hand "cleaning up those nasty pests...  It would consume too much space explaining it all here, I'll just send you the apps I use :).

My system's been *clean* for over 6mos solid

~Shadow

 

by: tato374Posted on 2003-03-10 at 07:03:01ID: 8103291

thanx Shadow_Hawk - no probs right now - but good to have a contact in case of emergencies - perhaps u could send me your email -

tato@blueyonder.co.uk

 

by: Shadow_HawkPosted on 2003-03-10 at 11:45:28ID: 8105410

Tato374, please check your mail :).

 

by: chezdimPosted on 2003-03-19 at 13:13:42ID: 8169703

You should consider buying tds-3 its probbaly the best anti-trojan software out there.Cost is around 40$ or so.
Check out the reviews.
http://www.diamondcs.com.au

 

by: tomdfxPosted on 2003-04-10 at 22:00:03ID: 8311529

If you still have a copy of the trojan program, you might want to examine it for any URLs embedded in it or things like that.  There is a possibility it could be a legitimate adult content dialer thats been altered or binded with a separate malicious piece of software to make it auto-dial without notifying you.

If it does turn out to be a real dialer program that's been hacked or altered, I can bet that the company would be much more grateful to be contacted by you than the FCC.  

Or, you could go directly to the FCC, as auto-dialing mechanisms, especially if they are dialing domestic toll calls, are easy cases to solve for them.

 

by: akbossPosted on 2004-03-03 at 16:13:33ID: 10509968


============================
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is:
PAQ/Refund Points
Please leave any comments here within the next four days.
 
PLEASE DO NOT ACCEPT THIS COMMENT AS
AN ANSWER!
 
akboss
EE Cleanup Volunteer
============================

 

by: CetusMODPosted on 2004-03-07 at 15:30:45ID: 10536973

PAQed, with points refunded (100)

CetusMOD
Community Support Moderator

 

by: fcislerPosted on 2004-03-29 at 06:12:13ID: 10704136

this question has been finished, but heres my 0.02

when i come across a "rouge" program or the like heres my steps for dealing with it.

1) if it's an app then i look in task manager and try to kill it.
2) if i can kill the app i delete it from registry HKEY_L_M\microsoft\windows\currentversion\run
3) if for some reason app keeps adding itself back to run (or can't delete it) then simply use permissions (YES regedit does have key security) and set permissions to deny for all
4) reboot. Attempt to delete file. Reset permissions on run key. Delete Key.
5) If you STILL can't delete the EXE, use NTFS permissions to set deny to everyone (if no one can access it, it can't run!)
6) reboot. Reset permissions. Delete

If those steps dont get the EXE out then good luck!

If it's a dll my approach is slightly different.

1) regsvr32 /u c:\path\to\the.dll (NOTE: if it's in program files please change to regsvr32 /u "c:\program files\common\etc"...you need the " " for paths with spaces in them)
2) regedit, find > dllname.dll
3) heres the tricky part for DLL's...you have to know what to delete and what traces back to where...so without some common knowledge here i suggest you simply set permissions on the .dll to everyone deny full access. Reboot your pc, if things still work then feel free to delete it. If you get errors trace them back. At this point, it's much better to just say get spybot or ad-aware.

Again, just my $0.02. My EXE removal works over 90% of the time.

 

by: NicoLaanPosted on 2004-03-29 at 23:38:24ID: 10711405

Addtional note:

I also tried deleting some virus the hard way, because Windows used it, only then my system crashed.
The virusfiles (some DLL's) where linked to Explorer.exe.

So as extra advise I strongly recommand to first try hard to find out what this program is and find specific removal instructions for this dialer / virus or whatever on the internet.

And as we all know, MAKE BACKUPS! (I do since I had some crashes and nasty virusses)

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...