Content

Dialer-212

Type
Program
SubType
Dialer
Discovery Date
11/17/2004
Minimum DAT
4388 (08/25/2004)
Updated DAT
4539 (07/20/2005)
Minimum Engine
5.1.00
Description Added
08/25/2004
Description Modified
12/01/2004 6:18 AM (PT)

Tab Navigation

Characteristics

This is not a virus or trojan.  User usually agree to have these types of applications installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

Installation

Upon execution, the application installs itself into the %SysDir% directory as "MMFR32.exe".

(Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM)

For example:

C:\WINDOWS\System32\MMGR32.exe

The following Registry key(s) is/are added to hook system startup:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "OpenMstart" = "%SysDir%\MMGR32.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Switch "DisplayName" = "Switch"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Switch "UninstallString" = "%SysDir%\MMGR32.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\MStart2Page "Id" = "466EDBF27F368DACAF3E788351939350"
  • HKEY_LOCAL_MACHINE\SOFTWARE\MStart2Page "installed" = "1"
  • HKEY_LOCAL_MACHINE\SOFTWARE\MStart2Page "version" = "51"
  • HKEY_LOCAL_MACHINE\SOFTWARE\SwitchDialer "Id" = "466EDBF27F368DACAF3E788351939350"
  • HKEY_LOCAL_MACHINE\SOFTWARE\SwitchDialer "version"  "51"
  • "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN "iexplore.exe" = "00, 00, 00, 00"
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow "*.ffx23wl.nl" = ""
  • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\User Trusted External Applications  C:\WINDOWS\System32\MMGR32.exe" = "Yes"
  • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers "application/x-callswitch" = "%SysDir%\MMGR32.exe"
  • HKEY_CURRENT_USER\Software\Netscape\Netscape Navigator\Viewers "TYPE35" = "application/x-callswitch"

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Aliases

Aliases

    N/A