Trojan

Trojan.Dialer.AH (file analysis)

Malware Removal

The Trojan.Dialer.AH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Dialer.AH virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Trojan.Dialer.AH?


File Info:

crc32: 31225CCC
md5: e1e6ccdc1870fa8e4906739808a8673b
name: 14-0-42-106.exe
sha1: 71a86ca5e91ac138c2d00580bfa1217648c84b53
sha256: 97e7f3d31069575427e9b78e98092ce82d73e5131196fe94d9f3fb1481653583
sha512: f71c5541fc069442d880356626c8ae8512251b2d111287dbf7e2614bc99f293f77db9b495339e2d2b6314230637f5be50d4c21873012c667766ed7d327f780a0
ssdeep: 768:DSJDpxAB6HzS5inaBJk/bCzqX3fNNOXOs91jkbl/DVEc2S0Z/GI751Bxwt:2JDpKB6T7aBJk/bCWX3fNZs91wb5DiM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Dialer.AH also known as:

MicroWorld-eScanTrojan.Dialer.AH
FireEyeTrojan.Dialer.AH
CAT-QuickHealTrojan.MauvaiseRI.S5256558
Qihoo-360Win32/Trojan.971
ALYacTrojan.Dialer.AH
ZillyaDialer.WebDialer.Win32.52
SangforMalware
K7AntiVirusDialer ( 00046bb31 )
BitDefenderTrojan.Dialer.AH
K7GWDialer ( 00046bb31 )
Cybereasonmalicious.c1870f
TrendMicroDIAL_RAS.HT
BitDefenderThetaGen:NN.ZexaF.34090.cmGfaKEvTHE
CyrenW32/Dialer.CGCF-0034
SymantecDialer.Generic
TotalDefenseWin32/Dialer.WebDialer!generic
APEXMalicious
AvastWin32:Dh-A [Heur]
ClamAVWin.Trojan.Dialer-83
GDataTrojan.Dialer.AH
KasperskyTrojan.Win32.Scar.omgz
AlibabaTrojan:Win32/Dialer.7b60a508
NANO-AntivirusTrojan.Win32.Webdial.bblnih
AegisLabTrojan.Win32.Scar.4!c
TencentWin32.Trojan.Scar.Akyo
Ad-AwareTrojan.Dialer.AH
SophosDial/WebDial-A
ComodoTrojWare.Win32.Dialer.~DRE@8zplm
F-SecureDialer.DIAL/000025
DrWebDialer.Webdial
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
McAfee-GW-EditionBehavesLike.Win32.Dialer.pc
CMCPorn-Dialer.Win32.Small!O
EmsisoftTrojan.Dialer.AH (B)
IkarusDialer
F-ProtW32/Dialer.P
JiangminPorn-Dialer.WebDialer.u
AviraDIAL/000025
Antiy-AVLGrayWare[Porn-Dialer]/Win32.WebDialer
Endgamemalicious (moderate confidence)
ArcabitTrojan.Dialer.AH
ZoneAlarmTrojan.Win32.Scar.omgz
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Unwanted/Win32.Dialer.R101528
Acronissuspicious
McAfeeArtemis!E1E6CCDC1870
MAXmalware (ai score=82)
VBA32Porn-Dialer.WebDialer
PandaDialer.Gen
ESET-NOD32a variant of Win32/Dialer.WebDial
TrendMicro-HouseCallDIAL_RAS.HT
RisingWorm.Tedeos!8.5B48 (CLOUD)
YandexDialer.Webdialer.Gen
SentinelOneDFI – Suspicious PE
FortinetW32/Webdialer.7ACD!tr
AVGWin32:Dh-A [Heur]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Dialer.AH?

Trojan.Dialer.AH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment