Trojan.win32.dialer.ht

D

DARRE Eric

Hello

How to get rid off this trojan (win32.dialer.ht) from Dialer platform
limited which open a internet windows as soon as my computer is on and
connect to this site 63.218.226.78 ?
Thanks
 
S

Steve Wechsler [MVP]

DARRE said:
Hello

How to get rid off this trojan (win32.dialer.ht) from Dialer platform
limited which open a internet windows as soon as my computer is on and
connect to this site 63.218.226.78 ?
Thanks

a² - Free Edition can remove it :
http://www.emsisoft.com/en/software/free/


Steve Wechsler (akaMowGreen)
MS-MVP 2004-2005

===============
*-343-* FDNY
Never Forgotten
===============
 
J

JohnF.

Okay friend, you will have to get Ron Kinner in to help you. Here is the
info for that:

*** For assistance in battling infestations***
- Get HijackThis.exe from:
http://tomcoyote.org/hjt/hjt199//HijackThis.exe
- Save it to C:\hjt (new folder)
- Open it and select "Scan and Save Log"
- Note where you saved the log
- Send it to Ron Kinner as an attachment
- Ron's email address is (e-mail address removed)
- Put Hijack in the subject so he knows it's not spam
- He will tell you what to do next
 
D

DARRE Eric

Thank you John for your kind help.

ERIC

JohnF. said:
Okay friend, you will have to get Ron Kinner in to help you. Here is the
info for that:

*** For assistance in battling infestations***
- Get HijackThis.exe from:
http://tomcoyote.org/hjt/hjt199//HijackThis.exe
- Save it to C:\hjt (new folder)
- Open it and select "Scan and Save Log"
- Note where you saved the log
- Send it to Ron Kinner as an attachment
- Ron's email address is (e-mail address removed)
- Put Hijack in the subject so he knows it's not spam
- He will tell you what to do next
 
S

Steve Wechsler [MVP]

Eric,

If you're running XP Home suggest you log on as Administrator in Safe
Mode and run a² from there after first checking for an update.
The trojan you cite is listed in their definition files and *should* be
able to be removed from the system by scanning with a² in SM as an Admin.

Steve Wechsler (akaMowGreen)
MS-MVP 2004-2005

===============
*-343-* FDNY
Never Forgotten
===============
 
D

DARRE Eric

Thank you Steeve

I've done what you said but a² doesn't find anything about 63.218.226.78 and
when I connect to Internet, my browser still try to go to this site.
In the browser, I put this site in the forbidden sites (tools/internet
options) and it still write itself in authorized sites.
I have used Regseeker and erased all 63.218.226.78 entries and I will see
what happen.
Thank you for your help.
Eric
 
Joined
Feb 12, 2006
Messages
1
Reaction score
0
wlan1934.sys

Okay, it's been a while but I've had the same problem recently.
Occasionally my computer additionally tried to connect to 205.177.124.72
Here's what it's all about:
The trouble is caused by the file
c:\windows\system32\drivers\wlan1934.sys,
a trojan.
Delete it, and everything's fine.
Here's what you gotta do if the file is in use:

- Log on as administrator
- Download and run Process Explorer from www.sysinternals.com
- Press Ctrl-F and enter "wlan1934"
- A handle named c:\windows\system32\drivers\wlan1934.sys in process "System" should be found: double-click it
- In the lower pane, right-click wlan1934.sys, select "close handle" and confirm
- now delete c:\windows\system32\drivers\wlan1934.sys (or just rename it, if you're not sure)
- reboot
- done

Optional: clean your registry:
- Run regedit.exe
- Navigate to the top of the tree
- Press Ctrl-F and enter "wlan1934". Make sure to mark "Keys" and to unmark "Match whole string only"
- In the tree view, delete each occurrence found. To do this, right-click it and set the proper permissions, then press "del" and confirm
- Continue searching with F3 and repeat the step above until no more "wlan1934" is found.
 
Last edited:

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top