Malware

Dialer:Win32/WebDialler removal

Malware Removal

The Dialer:Win32/WebDialler is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dialer:Win32/WebDialler virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Dialer:Win32/WebDialler?


File Info:

name: 0C09C93946822A591244.mlw
path: /opt/CAPEv2/storage/binaries/57aa5485e1da0f965053d684acd35fb6ae4269ee3345135f5f338621f39867fe
crc32: 65615C27
md5: 0c09c93946822a5912445e8e2a0bd69f
sha1: 07257f167748ed607eff50c5216f05abc115f92f
sha256: 57aa5485e1da0f965053d684acd35fb6ae4269ee3345135f5f338621f39867fe
sha512: f70e33627d99d1386217f0826725fd0373531c5416032d51866d5b5909b1a5ff28a3ada843ab6071023548c691466f3ed61f3096ce12053a7369d0aa29460585
ssdeep: 384:Ev9cmRi9jIewGcnWx3cdPn/rj3qmdyJBGj+x:1n9jIeXc+3Qn/GT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D822C03EA984456D4F26B3090BBD622DD34FEB15475ED1B63A0820A1EB13D36BB971F
sha3_384: 1788bd9046554f1d30a1886edd46779d9942846af5cf1c6060cdd1e3d5c7d98a4a2a7fd26568095acb5e8794e39a5b94
ep_bytes: 8d0dc71240008d0563114000505a2bc8
timestamp: 2005-07-07 03:28:50

Version Info:

0: [No Data]

Dialer:Win32/WebDialler also known as:

LionicTrojan.Win32.Dialer.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Dialer.Premium
FireEyeGeneric.mg.0c09c93946822a59
ALYacTrojan.Dialer.Premium
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
BaiduWin32.Trojan.Dialer.f
VirITTrojan.Win32.Dialer.EG
CyrenW32/Dialer.TCS3_DET!Eldorado
SymantecDialer.Generic
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Dialer
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Dialer-5680
KasperskyTrojan.Win32.Dialer.kq
BitDefenderTrojan.Dialer.Premium
NANO-AntivirusTrojan.Win32.Eaccess.dxgqsr
AvastWin32:Dialer-gen13 [Trj]
TencentWin32.Trojan.Dialer.Eon
Ad-AwareTrojan.Dialer.Premium
TACHYONTrojan/W32.Dialer.18080
EmsisoftTrojan.Dialer.Premium (B)
ComodoSuspicious@#3hl6cvhpb0ayh
F-SecureTrojan.TR/Dialer.KQ.1
DrWebDialer.Eaccess
ZillyaTrojan.Dialer.Win32.1509
TrendMicroDIAL_RAS.HX
McAfee-GW-EditionDialer-263
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Mal/Behav-061
IkarusTrojan.Win32.Dialer
GDataTrojan.Dialer.Premium
JiangminTrojan/Dialer.kgn
AviraTR/Dialer.KQ.1
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Dialer.Premium
ZoneAlarmTrojan.Win32.Dialer.kq
MicrosoftDialer:Win32/WebDialler
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Premium.R7602
Acronissuspicious
McAfeeDialer-263
MAXmalware (ai score=82)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesMalware.AI.1059105180
TrendMicro-HouseCallDIAL_RAS.HX
RisingTrojan.Dialer.kq (CLASSIC)
YandexTrojan.Dialer!sEvDve40R/c
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/263
BitDefenderThetaGen:NN.ZexaF.34742.biX@auObB8oi
AVGWin32:Dialer-gen13 [Trj]
Cybereasonmalicious.946822
PandaTrj/Genetic.gen

How to remove Dialer:Win32/WebDialler?

Dialer:Win32/WebDialler removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment