1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Dialer:SymbOS/Pornidal.A

Name : Dialer:SymbOS/Pornidal.A
Detection Names : Porn-Dialer:SymbOS/Pornidal.A
Category:Riskware
Type:Dialer
Platform:SymbOS

Summary

A program that connects the computer to the Internet via a telephone line and modem. Malicious dialers will secretly connect the computer to premium-rate lines.

Additional Details

This dialer program is known as PornPlayer. Its main purpose is to give the client access to the porn site youth6.net and to dial remote numbers from the client's mobile phone.

The program's End User License Agreement (EULA) is contained in the c:\tmp\MKS0\terms0.txt file and explicitly states the following features of the program:

  • It will view and download sexually explicit material
  •  It will makes calls to international destinations



The user must agree to the EULA before the program is installed to the system.


Installation

On executing the dialer program for the first time, the following screens are displayed:







If the user agrees to install the program, it will drop the following files into the system:

  • c:\system\apps\SexyVideo\SexyVideo.app
  • c:\system\apps\SexyVideo\SexyVideo.rsc
  • c:\system\apps\programs\FullLengthViewer.exe
  • c:\tmp\MKS0\terms0.txt
  • c:\system\recogs\EZRECOG.MDL

The file c:\system\recogs\EZRECOG.MDL will automatically launch c:\system\apps\programs\FullLengthViewer.exe when the phone boots up.


Activity


The following are the numbers dialled by the program:

  • +43820911995
  • +43810522237
  • +239980254
  • +3598815400096
  • +22650500089
  • +6744449333
  • +423662690232
  • +227171020
  • +41773111701
  • +2284260203