Content

PornDial-143

Type
Program
SubType
PornDialer
Discovery Date
01/20/2003
Minimum DAT
4246 (02/05/2003)
Updated DAT
4271 (06/11/2003)
Minimum Engine
5.1.00
Description Added
01/20/2003
Description Modified
01/29/2003 10:36 AM (PT)

Tab Navigation

Characteristics

This is a porn dialer application that installs itself to run at system startup. A porn dialer is simply a program that is used to dial into a pornographic "service". Some porn dialers do not advertise that extremely high phone bills may result from using their service.
/PROGRAM detection is being added for this "potentially unwanted application". The current command-line scanner makes use of such detections, as does VirusScan 7.

The "msite18.exe" (102.932 bytes) is a 32 bit executable file, it's packed internally with UPX. When run, the program copies itself silently into the %windows\%system directory, example on win2000: copied itself to "c:\winnt\system32\msite18.exe"

PornDial-143 doesn't show it's presence visible but it gets loaded at system start. It makes entries to the registry such as:

-HKEY_CLASSES\ROOT\MS-Connect.Scriptfile\shell\open\command
"c:\winnt\system32\msite18.exe" %1

-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\
MS-Connect "c:\winnt\system32\msite18.exe"

In the windows taskmanager, the process msite18.exe is visble and can be killed manually. (Note that Virusscan is able to kill the process automatically.)

Aliases

Aliases

    N/A