LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: InFESTeD on May 23, 2006, 05:45:27 PM

Title: Win32:Dialer-520
Post by: InFESTeD on May 23, 2006, 05:45:27 PM
Everytime I log-on I avast detecects this virus:Win32:Dialer-520

Im using:
Windows 98 SE
Avast!4.7 Home Edition
BitDefender 8 Free Edition
Ad-Aware 6 SE
Spybot: S & D
A-Squared anti Malware
Zone Alarm Firewall(expired today)

When I start the computer I get this error:
SHLDDRV.VXD is missing

When I start Avast! I get this error:
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fimg329.imageshack.us%2Fimg329%2F3171%2Favasteror4dr.png&hash=1bda764afccd1c920de2e44bdfe792ee569d96d3)This is the error message I get after the memory check finishes.

(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fimg103.imageshack.us%2Fimg103%2F5993%2Favasteror26ei.png&hash=6cc73fef4d85789586f7ba0e7859c0ca62769f2e)
This is the error message I get after the first one.

And when I scan with BitDefender 8 Free Edition i finds winnyjy32.dll but doesn't remove or quarantine it.

Please help.

Title: Re: Win32:Dialer-520
Post by: GR@PH;<'S on May 23, 2006, 05:53:56 PM
InFESTeD,
I recommend that you try at least two if not more of these  On-line scans
Panda (http://www.pandasoftware.com/activescan/com/activescan_principal.htm)
Symantec (http://security.symantec.com/ssc/home.asp?j=1&langid=us&venid=sym&plfid=23&pkj=AUVCCVGZBZTVOGXFSTZ)
McAfee (http://us.mcafee.com/root/mfs/default.asp)
TrendMicro (http://housecall.trendmicro.com/housecall/start_corp.asp)
Bit Defender (http://www.bitdefender.com/scan/licence.php)
RAV (http://www.ravantivirus.com/scan/)
Kaspersky (http://www.kaspersky.com/scanforvirus.html)
CommandonDemand (http://www.commandondemand.com/eval/index.cfm)
Computer Associates (http://www3.ca.com/threatinfo/virusinfo/)
CyberTechHelp (http://www.cybertechhelp.com/html/misc/av.php)
PC Pitstop (http://www.pcpitstop.com/antivirus/default.asp)
Stinger (http://vil.nai.com/vil/stinger/)
a2 (http://www.emsisoft.com/en/software/free/)
or download and try
TrojanHunter (http://www.misec.net/) (Note Trojan Scanner 30 day Trial)
Then once you have done clear out your cache folder again ie: Run
CCleaner (http://www.ccleaner.com/)
(Note in CCleaner: go to >options > advanced > Uncheck "Only delete files in Windows Temp folders older than 48 hours"). but see CCleaner Set up (http://www.bbusa.net/ghost1/ccleanersetup.html)

then rescan with Ad-aware SE Build 106 (http://lavasoft.element5.com/support/download)
after using  the WebUpDate
to get the latest Definition file
SE1R109 22.05.2006 by doing a  "Full Scan"  and post your logfile here by using the "Add-reply" feature
If needed here's how to post your Ad-aware  Logfile ;)

Here's how to copy your Ad-aware log
click my computer
click local C Drive
then Click Program Files
then Click Lavasoft
then click Ad-aware SE
and then Logs,
find the latest one that you have
(by date & time)
and open it right Click select all
copy and then paste the contents of it here.
(Make sure that all of your Logfile has been posted, sometimes it will require two post's to get it all)
I recommend that you use the WebUpDate just before you scan that way you will always be up to date.
GR@PH;<'S    :breakkie:
Title: Re: Win32:Dialer-520
Post by: InFESTeD on May 23, 2006, 06:22:03 PM
The link you gave me doesnt work but i stil ldownloaded it fro mthe site.How do I add it to Ad-Aware SE? and i downloaded the programs youadvised me of.Thanks!
Title: Re: Win32:Dialer-520
Post by: GR@PH;<'S on May 23, 2006, 08:53:15 PM
InFESTeD,
Hmmmm yes you are right there site must be down,
as long as you got Ad-aware SE Build 106 (http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10399602.html?tag=pop) once installed use the WebUpDate
to get the latest Definition file
SE1R109 22.05.2006
To do this Open Ad-aware
Click the WebUpDate
button at the top right hand side of the Ad-aware screen (The world globe).
Click "Connect"
Ad-aware will then download the latest  Definition file for you.
To make sure it is updated , look at the main
Ad-aware screen, and look under "Initialization Status"
It should say the Latest Definition file.
then scan  doing a  "Full Scan" (http://www.lavasofthelp.com/howto/scan_se/) and then post your logfile here by using the Add-Reply Feature
But do the on-line scans first then clear your cache folder IE: run CCleaner (http://www.ccleaner.com/)

GR@PH;<'S   :breakkie:
Title: Re: Win32:Dialer-520
Post by: SpiritWind on May 24, 2006, 06:17:53 AM
 :hammy:  Hi InFESTed :

  I see you took my advise on the Avast Antivirus forums to come here for help .
  The following info which you posted on that forum may help those here help you :
  "Everytime i start my pc it says that SHLDDR.OCX or soemthing like that is missing(in MS-DOS mode). and then it tells you to press any key to continue. "

  P.S. Before you run an Ad-Aware "Full System Scan", it is advisable to UNcheck the
        "Search for negligible risk entries" setting AND check the "Search for low-risk
         threats" setting .

Title: Re: Win32:Dialer-520
Post by: SpiritWind on May 24, 2006, 06:23:29 AM
 :hammy:  GR@PH;<'S :

  I see on this forum you have NOT removed the reference to "RAV" that I told you
  about some time ago on another forum, that it has been discontinued ( you followed
  my advise about this on the "other" forum ) .
Title: Re: Win32:Dialer-520
Post by: InFESTeD on May 24, 2006, 05:26:47 PM
Who me?
Whats a 'RAV'?

I think the virus is gone now.Thanks for yuor help guys!
Title: Re: Win32:Dialer-520
Post by: GR@PH;<'S on May 24, 2006, 06:49:20 PM
InFESTeD,
the Rav info from SpiritWind was directed to me.(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fsmilies.sofrayt.com%2Ffsc%2Fwink2.gif&hash=026d7c7f666300aa5560f32f726a9d4a87a10844)

QuoteI think the virus is gone now
To be sure can you post the your Ad-aware SE logfile If needed here's how to post your Ad-aware  Logfile ;)

Here's how to copy your Ad-aware log
click my computer
click local C Drive
then Click Program Files
then Click Lavasoft
then click Ad-aware SE
and then Logs,
find the latest one that you have
(by date & time)
and open it right Click select all
copy and then paste the contents of it here.
(Make sure that all of your Logfile has been posted, sometimes it will require two post's to get it all)

GR@PH;<'S   :breakkie:
Title: Re: Win32:Dialer-520
Post by: GR@PH;<'S on May 24, 2006, 06:50:30 PM
SpiritWind,
ok thanks  (https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fsmilies.sofrayt.com%2Ffsc%2Fthumbs-up.gif&hash=c1e3dd78f2962d425885915fa02daf0bba965636)

GR@PH;<'S   :breakkie: