Updated: February 13, 2007 11:36:21 AM
Type: Dialer
Risk Impact: High
File Names:
Varies
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
When Dialer.SwitchDialer is executed, it performs the following actions:
- Copies itself to the %System% folder using the same name as the file that was originally run on the computer.
Note: %System% is a variable. The dialer locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
- Adds some of the following folders:
- %ProgramFiles%\Make125
- %ProgramFiles%\Make125\Portal
- %ProgramFiles%\Plus18Point
- %ProgramFiles%\Plus18Point\Portal
- %ProgramFiles%\FirstEnter
- %ProgramFiles%\FirstEnter\Portal
- %ProgramFiles%\QuickPage
- %ProgramFiles%\QuickPage\Portal
- Adds some of the following subkeys:
HKEY_CLASSES_ROOT\.cxq
HKEY_CLASSES_ROOT\.mxq
HKEY_CLASSES_ROOT\cxqfile
HKEY_LOCAL_MACHINE\SOFTWARE\Startportal
HKEY_LOCAL_MACHINE\SOFTWARE\SwitchDialer
HKEY_LOCAL_MACHINE\SOFTWARE\Make125
HKEY_LOCAL_MACHINE\SOFTWARE\Plus18Point
HKEY_LOCAL_MACHINE\SOFTWARE\FirstEnter
HKEY_LOCAL_MACHINE\SOFTWARE\QuickPage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5CBF8C22-E9A6-11D7-90FE-000AE4012DB4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-callswitch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Switch
- Adds one of the following values:
"Diskstart" = "%System%\<filename>"
"sVideo2" = "%System%\<filename>"
"Quicktlme" = "%System%\<filename>"
"Classes" = "%System%\<filename>"
"CLSID" = "%System%\<filename>"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the dialer runs when you start Windows.
- Adds the value:
"{5CBF8C22-E9A6-11D7-90FE-000AE4012DB4}" = "{5CBF8C22-E9A6-11D7-90FE-000AE4012DB4}!1,0,0,2"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\ClsidFeature
- Adds the value:
"*.ffx23wl.nl" = ""
to the registry subkey:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow
- Adds the values:
"TYPE34" = "application/x-callswitch"
"application/x-callswitch" = "%System%\<filename>"
to the registry subkey:
HKEY_CURRENT_USER\SOFTWARE\Netscape\Netscape Navigator\Viewers
- Adds the value:
"%System%\<filename>" = "Yes"
to the registry subkey:
HKEY_CURRENT_USER\SOFTWARE\Netscape\Netscape Navigator\User Trusted External Applications
- Adds the value:
"" = "%System%\<filename>" "%1"
to the registry subkey:
HKEY_LOCAL_MACHINE\Software\Classes\Classes\shell\open\command
- Adds the value:
"" = "%System%\<filename>" "%1"
to the registry subkey:
HKEY_LOCAL_MACHINE\Software\Javascrlpt\Classes\shell\open\command