Sophos

Dial/DialCar-M

Aliases
  • Trojan.Win32.Diamin.i
  • Dialer-267
  • Dialer-573
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 29 November 2005 14:03:40 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Dial/DialCar-M is a dialer application.

Dial/DialCar-M includes functionality to access the internet and communicate with a remote server via HTTP.

When run, Dial/DialCar-M displays the following message:

Scegliere "Si" per ricaricare i propri crediti, scegliere "No" per accedere direttamente.

If the user clicks "Si" to the message box and agrees to install the content from the following security warning then the dialer will be run, switching the internet connection to a predetermined number. If the user clicks "No", the application automatically connects to a predetermined website.

If the user agrees to install the program, the dialer copies itself to the Windows folder as Passe-partout.exe and creates a link to this file on the Desktop.

The following registry entry is created to run Passe-partout.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
NETVISIONPasse-partout
<windows>\Passe-partout.exe -A

The following registry entry is also created:
HKCU\Software\NETVISION
Passe-partout
[RandomValue]

The application may also change internet security settings.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer