Adultoweb.Desire Dialer Profile
Adultoweb.Desire was first discovered on October 14 of 2003. It is distributed by Creanet S.A., a known developer of Porn Dialers, and is typically transmitted from websites promoting pornography, though it can be transmitted from nearly anywhere else. It is of French origin.
Adultoweb.Desire, just like most Dialers, is stealthily installed on your computer by an ActiveX drive-by download. It has also been seen to be manually installed in some cases.
Adultoweb.Desire attacks by hijacking your computer’s dial-up modem. It starts with a browser window showing a 900 number to call for “Hot Babes in your box, new pictures every day. Just $50 a call, adults over 21 only.” It then exploits your modem to call a “900” phone number instead of your usual Internet service. This will result in enormous phone bills that you will have to haggle against. Creanet shares in the spoils with the phone number’s server.
Adultoweb.Desire also comes bundled with other Dialer programs, Trojan Backdoors, Downloaders, and possibly some Worms.
If you discover that you are infected with Adultoweb.Desire, you should remove it immediately with ZookaWare PC Cleaner.
Also Known As:
Dialer.Desire (Symantec)
Desire Dialer
Spyware Type:
Dialer
Associated Files:
%ProgramFiles\dialers\dialers
%ProgramFiles\dialers\dialers\desire
%ProgramFiles\dialers\dialers\subcriptions
• %ProgramFiles%\dialers\desire\desire.exe
• %System%\Desire-uninstall.exe
%ProgramFiles%\dialers\subcriptions\SubsDone.html
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “Desire”=”%ProgramFiles%\dialers\desire\desire.exe /<option>”
HKEY_CURRENT_USER\Software\SiteIcons
HKEY_CURRENT_USER\Software\SiteIcons\Dialers
HKEY_CURRENT_USER\Software\SiteIcons\Dialers\Desire
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\Desire
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-DESIRE
HKEY_CLASSES_ROOT\.DESIRE
HKEY_CLASSES_ROOT\DESIRE File
HKEY_CLASSES_ROOT\DESIRE File\shell
HKEY_CLASSES_ROOT\DESIRE File\shell\open
HKEY_CLASSES_ROOT\DESIRE File\shell\open\command
HKEY_CLASSES_ROOT\DESIRE File\shell\open\command “Default” = “%ProgramFiles%\dialers\desire\desire.exe %1”
HKEY_USERS\.DEFAULT\Software\Netscape\Netscape Navigator\Viewers “application/x-DESIRE” = “%ProgramFiles%\dialers\desire\desire.exe %1”
Just a quick word to say thanks. After trying unsuccessfully to remove Adultoweb.Desire with various other tools, SpyZooka has done the trick!
Nice work!
I came across this tool recently and tried it on one of my infected computers.
All the threats were cleaned. I am impressed with the effectiveness and the simplicity of the complete experience.
Great job SpyZooka!