win32:dialer-524[Trj]

i have been having this win32:dialer-524[Trj] poping up for the past 2 days and avast cannot find it to move it to chest,this also is poping up at the same time hxxp://www.impotato.com/a412/shed1.php?m=1&b=779&c=1[UPX] which is part of the dialer as above,can anyone please help me get this out of my system. thanks in advance.


Welcome to the forums, hornet1. :slight_smile:

Using the Search button at the top of the page, I found this thread which may help you. Be sure to read all of the posts as there is very good info in all of them. In particular, read the one by Polonus.

http://forum.avast.com/index.php?topic=20164.0

It is also a good idea to tell what your computer OS is as well as other security programs you may have. This info will help others provide better help for you.


  1. Please done post active links to suspect or known malware, you can edit your link like this http: // www dot impotato.com/a412/shed1.php?m=1&b=779&c=1[UPX] this avoids accidental clicking but the curious, etc.

  2. A forum search for impotato.com shows this has been covered before and there is a downloader on your system trying to download from this site. See the thread that CharleyO gave a link for.

  3. as a temporary measure you can add impotato.com to the URL Blocking section in the Web Shield provider.

  4. avast won’t find it on the HDD as the Web Shield is what is detecting it whilst it is being downloaded and gives only one option Abort Connection. This stops that download in its tracks and it doesn’t get to your HDD.

Thx for your help guys,I did a boot scan and avast found and removed the dialer.Cheers.

Did you run a-squared and ewido to be fully cleaned?

yeap i ran both those programs and they found 15 win32 dialers,its well cleaned now. thx.

Love the avatar Hornet, however, we try to keep them around 100 X 100 for those with low resolution monitors.

You can use this one if you like, welcome to the forums.

Cheers m8 thx for the avatar.