Sophos

Sophos blogs

Dial/Scom-D

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 10 May 2005 13:10:19 (GMT)
Last updated 23 September 2005 05:29:52 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing dialers.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

and remove any reference to any file you deleted.

Close the registry editor.

More Information

Dial/Scom-D is a premium rate dialler application.

Dial/Scom-D will create the folder C:\<Program Files>/pinfo/dialers/lisa
and copy itself to this folder with the filename lisa.exe.

The following registry entry will be created to start the dialler application
when a user logs on to Windows:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Lisa
<Program Files>\PInfo\Dialers\Lisa\Lisa.exe /dontdial


Dial/Scom-D will also create a clean Microsoft DLL in the Windows folder named rnaph.dll. This file may be deleted if the user wishes.

Dial/Scom-D may attempt to download and execute other files from the internet and sent system information to a pre-defined website.

Dial/Scom-D will also place shortcuts to itself on the computers Desktop, the strt menu and the start menu's Programs folder.

The following registry entry will also be created:


HKCU\Software\Netscape\Netscape Navigator\Suffixes\application
x-htnw
htnw

HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications
<Program Files>\PInfo\\Dialers\\Lisa\\Lisa.exe
yes

HKCU\Software\Netscape\Netscape Navigator\Viewers\application
x-htnw
<Program Files>\PInfo\\Dialers\\Lisa\\Lisa.exe %1

HKCU\Software\Netscape\Netscape Navigator\Viewers
TYPE35
application/x-htn

HKCU\Software\Pinfo\Dialers\Lisa
AC
dword:00000001

HKCU\Software\Pinfo\Dialers\Lisa
RLC
dword:00000000

HKCU\Software\Pinfo\Dialers\Lisa
MIMETYPE_DESCRIPTION
.htnw

HKCU\Software\Pinfo\Dialers\Lisa
SDNO
dword:00000001

HKCU\Software\Pinfo\Dialers\Lisa
CRR_ID
dword:000001f4

HKCU\Software\Pinfo\Dialers\Lisa
Modem_Found
dword:00000000

HKCR\.htnw
(default)
htnw File

HKCR\.htnw
Content Type
application/x-htnw

HKCR\MIME\Database\Content Type\application/x-htnw
Extension
.htnw

HKCR\htnw File
(default)
htnw Data

HKCR\htnw File
EditFlags
hex:00,00,01,00


HKCR\htnw File
shell\(default)
open

HKCR\htnw File\shell\open\command
(default)
<Program Files>\PInfo\\Dialers\\Lisa\\Lisa.exe %1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Lisa
<Program Files>\PInfo\\Dialers\\Lisa\\Lisa.exe /dontdial


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lisa
UninstallString
<Program Files>\PInfo\\Dialers\\Lisa\\Lisa.exe /uninstall

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lisa
DisplayName
Lisa

HKLM\SOFTWARE\Pinfo\Dialers\Lisa
SDNO
dword:00000001

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer