Trojan

Should I remove “Trojan:Win32/Porndial”?

Malware Removal

The Trojan:Win32/Porndial is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Porndial virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Porndial?


File Info:

crc32: 2EFD266D
md5: bf48a3a6c3b1f160dbe6c7407c6e011a
name: 12-110-1-8.exe
sha1: 7538a96a5211fcaa49a5d8c133c6046973e0b32f
sha256: de6a1f53e3ffe71bddbc52737203ffeaf630639804d05ac60db9ab9bec05b289
sha512: 0adf0af3a7440f37f7fa4bb72b9ed05e602d7ee8c01da62b4fa17074e47363fe605f70459df1786757bf7bb4a077e71037e1793c9b9d677edc1c8dbcf45a2e81
ssdeep: 768:ZjtCpMIpNTMZGGkEaNxCXTJctA+T/0bXM0v4LZRRFlbF6reSEv8ZTaMRbykgJDX:ZjUdGkEaHATcA+T/yfWjvv8ZwPxim2J
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 2001-2002
InternalName: webdialer
FileVersion: 3, 0, 0, 53
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: webdialer
SpecialBuild:
ProductVersion: 4, 0, 0, 2
FileDescription:
OriginalFilename:
Translation: 0x0407 0x04b0

Trojan:Win32/Porndial also known as:

DrWebDialer.Webdial
MicroWorld-eScanTrojan.Porndial.Damaged.F
FireEyeGeneric.mg.bf48a3a6c3b1f160
Qihoo-360Win32/Trojan.323
ALYacTrojan.Porndial.Damaged.F
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.wsc (mx-v)
SangforMalware
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderTrojan.Porndial.Damaged.F
K7GWDialer ( 004888d21 )
K7AntiVirusDialer ( 004888d21 )
TrendMicroTROJ_RAS.HT
BitDefenderThetaGen:NN.ZexaF.34104.dmKfaK7tyrs
F-ProtW32/Dialer.S.gen!Eldorado
SymantecDialer.Generic
TotalDefenseWin32/Dialer.Webdialer
APEXMalicious
AvastWin32:Dialer-gen8 [Trj]
ClamAVWin.Trojan.Dialer-83
GDataTrojan.Porndial.Damaged.F
Kasperskynot-a-virus:Porn-Dialer.Win32.WebDialer
NANO-AntivirusTrojan.Win32.Webdial.bblxsy
AegisLabRiskware.Win32.WebDialer.l5yW
TencentMalware.Win32.Gencirc.10b658c6
Ad-AwareTrojan.Porndial.Damaged.F
SophosDial/WebDial-A
ComodoApplication.Win32.Dialer.WebDial.B@2mw3
F-SecureDialer.DIAL/100001
ZillyaDialer.WebDialer.Win32.22
Invinceaheuristic
McAfee-GW-EditionDialer-RAS.c.gen
CMCPorn-Dialer.Win32.Small!O
EmsisoftTrojan.Porndial.Damaged.F (B)
IkarusDialer
CyrenW32/Dialer.S.gen!Eldorado
JiangminPorn-Dialer.WebDialer.a
WebrootW32.Dialer.Gen
AviraDIAL/100001
MAXmalware (ai score=100)
Antiy-AVLGrayWare[Porn-Dialer]/Win32.WebDialer
Endgamemalicious (moderate confidence)
ArcabitTrojan.Porndial.Damaged.F
SUPERAntiSpywareTrojan.Agent/Gen-Dialer
ZoneAlarmnot-a-virus:Porn-Dialer.Win32.WebDialer
MicrosoftTrojan:Win32/Porndial
AhnLab-V3Unwanted/Win32.Dialer.R101119
Acronissuspicious
McAfeeArtemis!BF48A3A6C3B1
VBA32Porn-Dialer.WebDialer
PandaDialer.Gen
ESET-NOD32Win32/Dialer.WebDial.B
TrendMicro-HouseCallTROJ_RAS.HT
RisingWorm.Tedeos!8.5B48 (TFE:dGZlOgUzZpGf+T4boA)
YandexDialer.Webdialer.Gen
SentinelOneDFI – Suspicious PE
FortinetRiskware/WebDialer
AVGWin32:Dialer-gen8 [Trj]
Cybereasonmalicious.6c3b1f
Paloaltogeneric.ml
MaxSecureTrojan.Malware.7072.susgen

How to remove Trojan:Win32/Porndial?

Trojan:Win32/Porndial removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment