Malware

PornDialer.WebDialer (file analysis)

Malware Removal

The PornDialer.WebDialer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PornDialer.WebDialer virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine PornDialer.WebDialer?


File Info:

crc32: FA3E8227
md5: 4571ef526b1adea234eadc13bbf57bc5
name: 5-2-46-151.exe
sha1: 5a9e89cd3df7d545ccd15f8da67d0fadf28bfa71
sha256: 965c174334c1c1522af8a2c8f711cfe9c47edf197a3f0f65baa999dd5c8068fe
sha512: 4742d411c0af9934fc80ac5460a26aa7272bc598d37666f7850574a39299c0c8ea1935f01f7fc781571cf02cb8c3838fd48bd347a444754f7997b1107bb26ec1
ssdeep: 1536:ix/0fXKXAkU49OV+SGEYBocUaAuCSXebCM4TzeLUP485E3:ix/0f7dwBoKUSubGTCLk48S
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2001-2002 keen+partner gmbh
InternalName: webdialer
FileVersion: 3, 0, 0, 53
CompanyName: keen+partner gmbh
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: webdialer
SpecialBuild:
ProductVersion: 4, 0, 0, 2
FileDescription:
OriginalFilename:
Translation: 0x0407 0x04b0

PornDialer.WebDialer also known as:

MicroWorld-eScanApplication.Dialer.Q
FireEyeApplication.Dialer.Q
CAT-QuickHealTrojan.GenericRI.S7513510
McAfeeDialer-Generic.b
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
SangforMalware
K7AntiVirusDialer ( 0055e3fa1 )
BitDefenderApplication.Dialer.Q
K7GWDialer ( 0055e3fa1 )
Cybereasonmalicious.26b1ad
TrendMicroDIAL_RAS.HT
BitDefenderThetaGen:NN.ZexaF.34090.dmKfaCzep5F
F-ProtW32/Dialer.S.gen!Eldorado
TotalDefenseWin32/Dialer.Webdialer
TrendMicro-HouseCallDIAL_RAS.HT
AvastWin32:Dh-A [Heur]
ClamAVWin.Trojan.Dialer-83
GDataApplication.Dialer.Q
KasperskyTrojan.Win32.Scar.ogkx
AlibabaTrojan:Win32/Dialer.a6039f2f
NANO-AntivirusRiskware.Win32.WebDialer.bnzio
AegisLabRiskware.Win32.Small.l2hr
RisingWorm.Tedeos!8.5B48 (CLOUD)
Endgamemalicious (moderate confidence)
SophosDial/WebDial-A
ComodoApplicUnwnt.Win32.PornDialer.Webdialer.DA@4n4flj
F-SecureDialer.DIAL/000153
DrWebDialer.Webdial
ZillyaDialer.WebDialer.Win32.96
Invinceaheuristic
McAfee-GW-EditionDialer-Generic.b
SentinelOneDFI – Suspicious PE
CMCPorn-Dialer.Win32.Small!O
EmsisoftApplication.Dialer.Q (B)
APEXMalicious
CyrenW32/Dialer.S.gen!Eldorado
JiangminPorn-Dialer.WebDialer.k
AviraDIAL/000153
Antiy-AVLGrayWare[Porn-Dialer]/Win32.WebDialer
MicrosoftDialer:Win32/PornDialer
ArcabitApplication.Dialer.Q
SUPERAntiSpywareTrojan.Agent/Gen-Dialer
ZoneAlarmTrojan.Win32.Scar.ogkx
AhnLab-V3Unwanted/Win32.Dialer.R101528
VBA32PornDialer.WebDialer
ALYacApplication.Dialer.Q
MAXmalware (ai score=73)
Ad-AwareApplication.Dialer.Q
PandaDialer.Gen
ESET-NOD32a variant of Win32/Dialer.WebDial
TencentMalware.Win32.Gencirc.10b70573
YandexDialer.Webdialer.Gen
IkarusDialer
FortinetW32/Dialer.DIAL!tr
WebrootW32.Dialer.Gen
AVGWin32:Dh-A [Heur]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove PornDialer.WebDialer?

PornDialer.WebDialer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment