Home Malware Programs Trojans MSIL/Terdial.D

MSIL/Terdial.D

Posted: June 29, 2011

MSIL/Terdial.D is a Trojan that attacks mobile phones that use certain Windows operating systems. Most victims of a MSIL/Terdial.D attack acquire the MSIL/Terdial.D infection by downloading a game that contains MSIL/Terdial.D hidden inside its installation routine. MSIL/Terdial.D's payload consists of dialing high-cost numbers at semi-random intervals, with the resulting charges appearing on your cell phone bill. If you value your money or your mobile phone's security, delete MSIL/Terdial.D as soon as you can with appropriate anti-virus software.

MSIL/Terdial.D: A Trojan Just for Your Cell Phone

Unlike the majority of Trojans that target PCs, MSIL/Terdial.D is designed explicitly to attack mobile phones, specifically ones that run Windows Mobile 6.5. Updating your phone to a more recent operating system may help to protect your phone from a MSIL/Terdial.D attack.

MSIL/Terdial.D distributes itself by being packaged with a gaming application called '3D Anti-Terrorist action.' Although this game is a legitimate application, the MSIL/Terdial.D infection that's bundled with it is wholly malicious. The infected file bundle may be named after the game or it may be named like a codec or other movie update: example installation files include 'antiterrorist3d.cab' and 'codecpack.cab.'

Although MSIL/Terdial.D emerged as a threat in 2010, it has seen limited distribution and your chances of becoming infected by it are relatively small. In addition, as a mere five kilobyte-sized file, MSIL/Terdial.D has a negligible file size and may not seem like a threat due to this. However, an infection by MSIL/Terdial.D is still dangerous, if primarily to your bank account.

The MSIL/Terdial.D Payload That Hits Your Wallet

MSIL/Terdial.D's payload is to dial a variety of international and high-charge phone numbers at semi-random periods. The time between MSIL/Terdial.D's dialing attacks may be as long as three days or as short as under twenty-four hours. This can result in sky-rocketing phone bill expenses if you don't notice MSIL/Terdial.D and figure out how to delete MSIL/Terdial.D before it can make too many calls.

MSIL/Terdial.D is also detected by other slight variations of its name, including Trojan:WinCE/Terdial, MSIL/Terdial.A, Trojan.Terred, MSIL/Terdial.C and MSIL/Terdial.B. The exact variant name that MSIL/Terdial.D uses doesn't change the recommended solution for removing MSIL/Terdial.D: use a good anti-virus program to sweep MSIL/Terdial.D out of your phone, before the phone bill ratchets up to painful levels.

At the time of this writing, MSIL/Terdial.D isn't able to cause this attack on normal PCs, but the presence of a MSIL/Terdial.D infection on your computer should still be considered a security weakness to be eradicated with all due haste. In this case, standard anti-virus strategies apply, and you can delete MSIL/Terdial.D by using the same software that you would use to delete any other Trojan.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %appdata%\microsoft\internet explorer\quick launch\MSIL/Terdial.D.lnk
    2 %commonprograms%\MSIL/Terdial.D\about.lnk
    3 %commonprograms%\MSIL/Terdial.D\activate.lnk
    4 %commonprograms%\MSIL/Terdial.D\buy.lnk
    5 %commonprograms%\MSIL/Terdial.D\MSIL/Terdial.D support.lnk
    6 %commonprograms%\MSIL/Terdial.D\MSIL/Terdial.D.lnk
    7 %commonprograms%\MSIL/Terdial.D\scan.lnk
    8 %commonprograms%\MSIL/Terdial.D\settings.lnk
    9 %commonprograms%\MSIL/Terdial.D\update.lnk
    10 %desktop%\MSIL/Terdial.D support.lnk
    11 %desktop%\MSIL/Terdial.D.lnk
    12 %programfiles\MSIL/Terdial.D\about.ico
    13 %programfiles\MSIL/Terdial.D\activate.ico
    14 %programfiles\MSIL/Terdial.D\buy.ico
    15 %programfiles\MSIL/Terdial.D\def.db
    16 %programfiles\MSIL/Terdial.D\defcnt.exe
    17 %programfiles\MSIL/Terdial.D\defext.dll
    18 %programfiles\MSIL/Terdial.D\defhook.dll
    19 %programfiles\MSIL/Terdial.D\help.ico
    20 %programfiles\MSIL/Terdial.D\scan.ico
    21 %programfiles\MSIL/Terdial.D\settings.ico
    22 %programfiles\MSIL/Terdial.D\splash.mp3
    23 %programfiles\MSIL/Terdial.D\uninstall.exe
    24 %programfiles\MSIL/Terdial.D\update.ico
    25 %programfiles\MSIL/Terdial.D\virus.mp3

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}hkcu\Software\Microsoft\Windows\CurrentVersion\Run "MSIL/Terdial.D"hklm\SOFTWARE\MSIL/Terdial.DHKEY..\..\..\..{RegistryKeys}hkcr\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}MSIL/Terdial.D
Loading...