Sophos

Sophos blogs

Troj/Dialer-FI

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 12 June 2008 02:22:37 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Dialer-FI is a Trojan for the Windows platform.

When run Troj/Dialer-FI creates the files:
<Program Files>\altcmd\altcmd.inf - can be safely removed
<Program Files>\altcmd\altcmd.dll - detected as Troj/Dialer-FI
<Program Files>\altcmd\uninstall.bat - can be safely removed

The following registry entries are set:

HKCR\CLSID\{32131238-5434-4234-4234-432432423432}\InprocServer32
(default)
<Program Files>\altcmd\altcmd.dll

HKCR\CLSID\{32131238-5434-4234-4234-432432423432}\InprocServer32
ThreadingModel
Apartment

Registry entries are created under:

HKCR\CLSID\{32131238-5434-4234-4234-432432423432}\
HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\
HKCR\MsVCL1.BhoApp.1\
HKCR\MsVCL1.BhoApp\
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\altcompare\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer