Malware

Dialer:Win32/PornDialer!pz removal tips

Malware Removal

The Dialer:Win32/PornDialer!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dialer:Win32/PornDialer!pz virus can do?

  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dialer:Win32/PornDialer!pz?


File Info:

name: 9A8355C4E3203F603C8B.mlw
path: /opt/CAPEv2/storage/binaries/dd68ed46d9d0f7a9d8ae036f6525b0d708dd156158688b52ad028260de06fb80
crc32: F49A6BD3
md5: 9a8355c4e3203f603c8b25c6fa33705e
sha1: df42b54a39ce57605c0a3e4b9755838207bdcbc1
sha256: dd68ed46d9d0f7a9d8ae036f6525b0d708dd156158688b52ad028260de06fb80
sha512: 4c215f8eccbba212c3dbf5bc0036db4aa8affaefb44d55ce5c9845b4531fd481208a0882815146dc8d82ff632aa885b3f06be8624817ecf9114a5bbc7539f821
ssdeep: 1536:pvwIMUkn5lRjATpx6GWT4T/ajHXECdcsEMLlYNQwQIfvGcwedOYH4UPiZ:9JknVKucT/uUCdcshlkQHIvjvxYUk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1931298705C3B94F659AF30220F87007BF650A19B5C3B7CA4FE347EDE921626C4AA75
sha3_384: ac4863187377ee2a49da3b4686d4c7e82970ce8d04af5a7bc280743ac7ac380989a36539ca5e30455d79b9f655085fb6
ep_bytes: 60be005041008dbe00c0feff5783cdff
timestamp: 2002-08-28 13:27:06

Version Info:

0: [No Data]

Dialer:Win32/PornDialer!pz also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.l0jn
Elasticmalicious (high confidence)
DrWebDialer.Online.2
MicroWorld-eScanGen:Variant.Razy.43087
FireEyeGeneric.mg.9a8355c4e3203f60
CAT-QuickHealPUA.WebdialerRI.S26707506
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXAA-AA!9A8355C4E320
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Scar.Win32.72351
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Dialer.0612926f
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Razy.DA84F
BitDefenderThetaGen:NN.ZexaF.36744.fmGfamEsjjq
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Dialer.0190-Dialers
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Dialer-202
KasperskyTrojan.Win32.Scar.fmke
BitDefenderGen:Variant.Razy.43087
NANO-AntivirusTrojan.Win32.Scar.exuuur
SUPERAntiSpywareTrojan.Agent/Gen-Webdialer
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b3a5a4
EmsisoftGen:Variant.Razy.43087 (B)
F-SecureDialer.DIAL/000293
VIPREGen:Variant.Razy.43087
TrendMicroDIAL_RAS.HE
SophosDial/190-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bfcl
VaristW32/Webdialer.gen!GSA
AviraDIAL/000293
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Scar
Kingsoftmalware.kb.b.994
XcitiumApplicUnsaf.Win32.Dialer.Generic@jux8x
MicrosoftDialer:Win32/PornDialer!pz
ViRobotTrojan.Win32.A.Scar.62513[UPX]
ZoneAlarmTrojan.Win32.Scar.fmke
GDataGen:Variant.Razy.43087
GoogleDetected
AhnLab-V3Adware/Win32.Dialer.R21773
VBA32Dialer.Online
ALYacGen:Variant.Razy.43087
Cylanceunsafe
PandaDialer.Gen
TrendMicro-HouseCallDIAL_RAS.HE
RisingHackTool.PornDialer!1.6613 (CLOUD)
YandexDialer.eConnect.Gen
IkarusDialer
MaxSecureTrojan.Malware.4018820.susgen
FortinetRiskware/190
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Dialer:Win32/PornDialer!pz?

Dialer:Win32/PornDialer!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment