Trojan

About “Trojan.Dialer.AF” infection

Malware Removal

The Trojan.Dialer.AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dialer.AF virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Dialer.AF?


File Info:

crc32: 16583807
md5: bcd4cd3666bb400413d4d0b0d2037fda
name: 5-6-100-103_dk.exe
sha1: 5742c0c4d3046fb680ca1056a27d2d0a616437bf
sha256: 11e48f1a712aa78aa4bea78d15927ce5d3f0541ada501f5c1f8c22a23d33efcc
sha512: da76fdcef727abe35136d587c781fe66624b1b5da36c9280addd0b44c00436a09bff990355939a7402f7a95f330ac138835ad69545c2bcb566249087967386d6
ssdeep: 768:ojtCpMIpNTmP0dRHlhD3w42Yb+VdHbaQ/hjGWOMUK+tGDoIwnbPmeiJyXDtqsoM:ojUB3D3PlOdHbauj2bmenHf
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2001-2002
InternalName: webdialer
FileVersion: 3, 0, 0, 53
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: webdialer
SpecialBuild:
ProductVersion: 4, 0, 0, 2
FileDescription:
OriginalFilename:
Translation: 0x0407 0x04b0

Trojan.Dialer.AF also known as:

MicroWorld-eScanTrojan.Dialer.AF
FireEyeTrojan.Dialer.AF
Qihoo-360HEUR/QVM11.1.Malware.Gen
McAfeeDialer-Generic.b
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
AegisLabRiskware.Win32.WebDialer.lBGH
SangforMalware
K7AntiVirusDialer ( 0055e3fa1 )
BitDefenderTrojan.Dialer.AF
K7GWDialer ( 0055e3fa1 )
Cybereasonmalicious.666bb4
TrendMicroDIAL_PORNH.104
BitDefenderThetaGen:NN.ZexaF.34090.dmKfaaQv8Os
CyrenW32/Dialer.S.gen!Eldorado
SymantecDialer.Generic
TotalDefenseWin32/Dialer.Webdialer
TrendMicro-HouseCallDIAL_PORNH.104
ClamAVWin.Trojan.Dialer-83
GDataTrojan.Dialer.AF
Kasperskynot-a-virus:Porn-Dialer.Win32.WebDialer
NANO-AntivirusTrojan.Win32.Webdial.bdxvzj
TencentMalware.Win32.Gencirc.10b6a2fe
Ad-AwareTrojan.Dialer.AF
SophosDial/WebDial-A
ComodoApplicUnwnt.Win32.PornDialer.WebDialer.~SAE@2poru
F-SecureDialer.DIAL/100002
DrWebDialer.Webdial
ZillyaDialer.WebDialer.Win32.13
Invinceaheuristic
McAfee-GW-EditionDialer-Generic.b
SentinelOneDFI – Suspicious PE
CMCPorn-Dialer.Win32.Small!O
EmsisoftTrojan.Dialer.AF (B)
APEXMalicious
F-ProtW32/Dialer.S.gen!Eldorado
JiangminPorn-Dialer.WebDialer.a
WebrootW32.Dialer.Gen
AviraDIAL/100002
Antiy-AVLGrayWare[Porn-Dialer]/Win32.WebDialer
Endgamemalicious (moderate confidence)
ArcabitTrojan.Dialer.AF
SUPERAntiSpywareTrojan.Agent/Gen-Dialer
ZoneAlarmnot-a-virus:Porn-Dialer.Win32.WebDialer
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Unwanted/Win32.Dialer.R101119
Acronissuspicious
VBA32Porn-Dialer.WebDialer
ALYacTrojan.Dialer.AF
MAXmalware (ai score=84)
PandaDialer.Gen
ESET-NOD32a variant of Win32/Dialer.WebDial
RisingWorm.Tedeos!8.5B48 (TFE:dGZlOgUzZpGf+T4boA)
YandexDialer.Webdialer.Gen
IkarusDialer
FortinetRiskware/WebDialer
AVGWin32:Dialer-gen9 [Trj]
AvastWin32:Dialer-gen9 [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Dialer.AF?

Trojan.Dialer.AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment