WINCE_TERDIAL.A
October 08, 2012
ALIASES:
Microsoft : Dialer:WinCE/Terdial.A ; Sophos : Troj/Terdial-A
PLATFORM:
Windows CE
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:

Threat Type: Dialer
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This dialer dials premium-rate numbers. The charges are billed to the computer owner unknowingly.
TECHNICAL DETAILS
File Size: 4/26/2010 bytes
File Type: PE
Memory Resident: Yes
Initial Samples Received Date: 26 Apr 2010
Dialer Routine
This dialer dials premium-rate numbers. The charges are billed to the computer owner unknowingly.
Other Details
This dialer does the following:
- Arives on a system as %Windows%\smart32.exe. It arrives as a component of other malicious applications. It is designed to run in Windows CE environment used in mobile devices.
- Attempts to dial the following numbers:
- +8823460777
- +17675033611
- +88213213214
- +25240221601
- +2392283261
- +881842011123
(Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
SOLUTION
Minimum Scan Engine: 8.900
VSAPI OPR PATTERN File: 7.129.00
VSAPI OPR PATTERN Date: 26 Apr 2010
Scan your computer with your Trend Micro product to delete files detected as WINCE_TERDIAL.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.