View Full Version : Dialer in system32?
aigle
May 31st, 2006, 04:27 PM
Ewido 4 beta finds the following dialer in my system 32-- seems to be false positive as it is present even in my basic RollbackRx snapshot.
Anybody has an idea?
Seems to be some programme preinstalled by toshiba( it,s toshiba satellite M70 laptop. Clicking the icon does try to dial a dial up connection but I don,t know it is really a malware or not?
aigle
May 31st, 2006, 04:33 PM
Jotti,s scan and VirusTotal scan results of first file.
aigle
May 31st, 2006, 04:38 PM
Jotti,s scan and VirusTotal scan results of 2nd file.
btman
June 1st, 2006, 01:22 AM
Could you send it in to BitDefender? www.bitdefender.com has live support and they should give you an email of where to send the file in a compressed file. I was getting mixed results about a certain file and some of jotti's scanners detected it while others didnt, Bit Defender told me it was a gaming protection file and not malware and so I contacted the other places and it was declared f/p. Also could you try a squared free 1.6.5 run update, scan and post results if you don't like bit defender or something lol...
aigle
June 1st, 2006, 02:12 AM
Ok thanks. I will try. to me seems false positive. It is sure a dialer but might be an ad put by toshiba and it does not dial on its own.
karl.ewido
June 1st, 2006, 08:32 AM
Please send us a copy of this file (use this website: http://www.ewido.net/en/malware/), so if it is a false positive, we can also fix it.
websnail
June 5th, 2006, 05:33 AM
The dialler it's picked up is one I've had some dealings with following some hassles with a clients machine.
It's a legitimate application in so much as BTinternet (BT Yahoo now) install it from their ISP installation disk along with something called BT Modem Lock. The dialler and modem lock, work to stop any other diallers (including other ISP settings in WinXP) from dialling out.
It's a neat feature but it is being seen as malware by some anti-spyware vendors including Ewido...
aigle
June 5th, 2006, 07:57 AM
You are right as i got it preinstalled from toshiba.
aigle
June 5th, 2006, 07:58 AM
{QUOTE-> Please send us a copy of this file (use this website: http://www.ewido.net/en/malware/), so if it is a false positive, we can also fix it. <-QUOTE}
As websnail said it is false positive. I wil send u a copy.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums