Results 1 to 2 of 2

Thread: [dialer] qhsnXX

  1. #1
    Junior Member
    Join Date
    Aug 2006

    Default [dialer] qhsnXX

    I've a problem with a dialer.
    I don't know how, but a malware creates a file in Windows\Temp directory. This file's name is "qhsnXX.exe", where XX is a number that automatically changes itself. After the windows session is started, suddenly at any time, the "qhsnXX.exe" file is loaded in memory and it works like [or it IS] a dialer: it disconnects my current connection and tries to make a new connection [a phone call to the usual very expensive telephone number].
    Spybot can't solve the problem, neither my antivirus software can.
    I obviously denied internet access to the file qhsnXX.exe [using Spybot]. However it can still make the phone call. My antidialer software is useless and doesn't stop the dialer.
    I delete the qhsnXX.exe file, but it re-creates itself with a different name, so it becomes a useless operation [i.e. if I delete qhsn08.exe, in short time the malware creates qhsn09.exe, loads it in memory and makes the phone call].
    If I could add qhsnXX.exe file to the black list in Tea-Timer, probably I would solve the problem for a bit of time. But, as I already wrote, the dialer/malware creates a copy of itself with a different numeration, and I can't do anything to stop its activity.

    Is there a solution to my problem?
    Thanks for the attention.


  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005



    Please follow the instructions in this sticky topic to get a HJT log:
    "BEFORE you POST" -Preliminary Steps

    Then start your own thread here:
    Malware Removal Forum

    A helper will advise you as soon as available, hang in there,
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts