Malware

Dial/WebDial-A (file analysis)

Malware Removal

The Dial/WebDial-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dial/WebDial-A virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Dial/WebDial-A?


File Info:

crc32: 46D8D30F
md5: 7e94f69efea6376e5114edf591706ce3
name: 5-2-46-286.exe
sha1: 67f525c1d842d4ea508ed0c714d4bbe1c0e64974
sha256: 2fa1982e8cda7659ce1e2704b8132c337a414817ac6f7d4f341274ba8a3f9a95
sha512: a8c29daafe290baf2ba28931ee0d9c3a4e61e0ebf925f9db78b88e88fa2a006936e75ff1741cbe0176d18d1a44f307a4362e397cb9337594728dda2e1c1dcfc0
ssdeep: 1536:Bx/0fXKXAkU49OV+SGEYBocUaAuCSXebCM4TzeDP3b85E3:Bx/0f7dwBoKUSubGTCzr8S
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2001-2002 keen+partner gmbh
InternalName: webdialer
FileVersion: 3, 0, 0, 53
CompanyName: keen+partner gmbh
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: webdialer
SpecialBuild:
ProductVersion: 4, 0, 0, 2
FileDescription:
OriginalFilename:
Translation: 0x0407 0x04b0

Dial/WebDial-A also known as:

MicroWorld-eScanApplication.Dialer.Q
FireEyeApplication.Dialer.Q
CAT-QuickHealTrojan.GenericRI.S7513510
Qihoo-360HEUR/QVM11.1.514B.Malware.Gen
McAfeeDialer-Generic.b
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
AegisLabRiskware.Win32.Small.l2hr
SangforMalware
K7AntiVirusDialer ( 0055e3fa1 )
BitDefenderApplication.Dialer.Q
K7GWDialer ( 0055e3fa1 )
Cybereasonmalicious.efea63
TrendMicroDIAL_RAS.HT
BitDefenderThetaGen:NN.ZexaF.34090.dmKfaSGiKJr
CyrenW32/Dialer.S.gen!Eldorado
SymantecDialer.Generic
TotalDefenseWin32/Dialer.Webdialer
TrendMicro-HouseCallDIAL_RAS.HT
ClamAVWin.Trojan.Dialer-83
GDataApplication.Dialer.Q
KasperskyTrojan.Win32.Scar.ogkx
NANO-AntivirusRiskware.Win32.WebDialer.bnzio
TencentMalware.Win32.Gencirc.10b70573
Ad-AwareApplication.Dialer.Q
SophosDial/WebDial-A
ComodoApplicUnwnt.Win32.PornDialer.Webdialer.DA@4n4flj
F-SecureDialer.DIAL/000153
DrWebDialer.Webdial
ZillyaDialer.WebDialer.Win32.96
Invinceaheuristic
McAfee-GW-EditionDialer-Generic.b
SentinelOneDFI – Suspicious PE
CMCPorn-Dialer.Win32.Small!O
EmsisoftApplication.Dialer.Q (B)
APEXMalicious
F-ProtW32/Dialer.S.gen!Eldorado
JiangminPorn-Dialer.WebDialer.k
WebrootW32.Dialer.Gen
AviraDIAL/000153
Antiy-AVLGrayWare[Porn-Dialer]/Win32.WebDialer
Endgamemalicious (moderate confidence)
ArcabitApplication.Dialer.Q
SUPERAntiSpywareTrojan.Agent/Gen-Dialer
ZoneAlarmTrojan.Win32.Scar.ogkx
MicrosoftDialer:Win32/PornDialer
AhnLab-V3Unwanted/Win32.Dialer.R101528
VBA32PornDialer.WebDialer
ALYacApplication.Dialer.Q
MAXmalware (ai score=74)
PandaDialer.Gen
ESET-NOD32a variant of Win32/Dialer.WebDial
RisingWorm.Tedeos!8.5B48 (RDMK:cmRtazqvv1FPJBfxHmXX+HjGc2AX)
YandexDialer.Webdialer.Gen
IkarusDialer
FortinetW32/Dialer.DIAL!tr
AVGWin32:Dh-A [Heur]
AvastWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Dial/WebDial-A?

Dial/WebDial-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment