trojan.win32.dialer.hc

AOL Spyware

Still cannot remove all the remnants of AOL Spyware. Have use the ad/remove programs feature of Winxp and it says AOl spyware is gone but I still get the spysweeper notification occassionally and AOL says its spyware is partially active.

Any help removing AOL spyware would be appreciated as I cannot find the active file anywhere on my system.
 
LonnyRJones said:
Hi
Is it possible to contact AOL support and get more info ?



I have tried and they maintain that no duplicate installation is possible and simply using the programs unistall feature will do the trick. I suspect I may have to do a complete unistall of AOL and then a reinstall.

Its really weird, I cannot find any folders or executatables for AOL spyware yet AOL maintains in its dialup box that I have partial coverage. Today I got a message saying that AOL had quarantined Atomic2 1.1 and com.com whatever they are.
 
I did a bit of research on this when Artic Wolf originally posted and mentioned the Beta version of the AOL Spyware Protection. Unfortunately, it appears that AOL dumped the original program that was being written for them when it had too many issues and switched to including a re-branded existing program (Pest Patrol?, I believe Lonny mentioned) in its place.

The problem is that those who had installed the original Beta probably simply installed the new program over the old, leaving remnants of the Beta on the PC. Since the two programs were probably totally different, it's likely the old program remained at least to some extent as you discovered. Probably the Beta should have been uninstalled before installing the final released version.

Since the original program never went past Beta stage, most of AOL support is probably unaware that it even existed. Even if they are, they may not acknowledge it's existence since it was never officially released or supported.

This means those who tried it may be left in exactly your situation. Other then removing the old program remnants by hand, which would be extremely difficult without original installation info, a complete PC reformat and re-install is probably the only way to truly clean it out. I could find nothing on the Web describing the original Beta other then that it existed, though it's possible there may be information on the AOL web sites that only members can access.

In either case, only AOL users are likely to have this info since virtually no one else would have ever had access to the orignal Beta. Since most AOL users are non-technical, it's not likely anyone ever analyzed the Beta, so only AOL itself could probably provide it. This is why Beta software has warnings, since exactly such situations can occur, though they're pretty rare these days.

I didn't pipe up before because I thought you'd gone to talk to AOL and would get an answer there, but since that hasn't worked I thought I'd mention it now. I don't remember where I found this info, but I believe it was some sort of article about the Beta.

This is interesting, I just found it while trying to find the original article.
http://www.spywaredata.com/spyware/spyware-adware-about.php

What's most interesting about it is this paragraph from a different article on another site.
AOL on Tuesday introduced its own version of anti-spyware protection from Aluria Software. The new feature for AOL's nearly 25 million subscribers will be available when the Dulles, Va.-based online giant debuts AOL 9.0 in the "next few weeks."
http://www.internetnews.com/xSP/article.php/3296851

Since it appears the same person developed both products, they were probably close, but not quite the same. Unless the Aluria product was the original Beta and AOL later replaced it with Pest Patrol, which I thought was the basis of the current version myself.

Either way, your issue is the same. Without information or an unistaller for the earlier version a complete re-install of the OS after format is probably the only way to completely remove it.
 
I'm also seeing Win32.Trojan.Dialer.hc come up with Zone alarm anti-spyware.
I'ts deleting a registry entry.
Upon installing Spybot, I have no error.....When I update Spybot, is when it comes in.

Are you sure it's a false positive?
I have always used the two together with no problem before.
 
md usa spybot fan said:
miadlor:

What is the actual detection you are getting and what is the registry entry that is being deleted?
I'm checking now...........small experiment.............
 
Ok........

It's coming from the update: Detection Rules dated 2006(3-19)

Registry value:

HKEY_CURRNET_USERS\Software\Miicrosoft\Windows\CurrentVersion\InternetSetting\ZoneMap\Domains\archiviosex.net

is being deleted.
 
During immunization Spybot adds the following registry entry to place archiviosex.net into Internet Explorer's restricted sites zone.

Code:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\archiviosex.net]
*=dword:00000004
If you go into Spybot > Immunize you will probably get a warning that you are missing an item.
 
No warning message of missing item.

Question?.......the deleted registry entry ended at .......... archivio.net
what's the extra

Are you sure of this or speculating? (no offense)
 
The "*=dword:00000004" is the code to place something into Internet Explorer's restricted sites zone.

Reference:

Internet Explorer 4.0 and later
Internet Explorer security zones settings are stored under the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
These registry keys contain the following keys:
• TemplatePolicies
• ZoneMap
• Zones

....


ZoneMap
The ZoneMap key contains the following keys: • Domains
• ProtocolDefaults
• Ranges

....


Zones
The Zones key contains keys that represent each security zone that is defined for the computer. By default, the following five zones are defined (numbered zero through four): Value Setting
------------------------------
0 My Computer
1 Local Intranet Zone
2 Trusted sites Zone
3 Internet Zone
4 Restricted Sites Zone
No BS nor speculation.

Try the following:
Go into Spybot > Immunize > click the "Check again" button and see if you get a warning.

Even if not click the "Immunize" button (big green plus sign) at the top of the right pane to immunize again. Then run another ZoneAlarm Anit-Spyware scan and see if the Win32.Trojan.Dialer.hc detection returns.

Added with edit:
ps: I see that you already tried to re-immunize while I was typing.
 
miadlor:

Prove it to yourself:

Go into Internet Explorer > Tools > Internet options... > "Security" tab > click the "Restricted sites" button > then the "Sites" button > the Web sites listings will show what sites are in the restricted zone.

Look for the following both before and after immunizing with Spybot and removing the entry with ZoneAlarm (note the entries are in alphabetical order by the second and third nodes of the name):
  • *.archiviosex.net
 
Exactly what you said!

So Zone Alarm is in error.....because it's not coming up with all the others as infections.
 
Back
Top