Threat Database Dialers Trojan.Dialer.GA

Trojan.Dialer.GA

By CagedTech in Dialers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 10
First Seen: May 23, 2023
Last Seen: August 18, 2026
OS(es) Affected: Windows

The detection of Trojan.Dialer.GA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially cause harm to your personal data and online activities. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Dialer.GA?

Trojan.Dialer.GA is a type of malware that falls under the category of Trojans, which are malicious programs that disguise themselves as legitimate software. The ".Dialer" part of the name suggests that this malware may be related to dialer programs, which can be used to connect to premium rate phone numbers or perform other unauthorized actions. However, without more specific information, it's difficult to determine the exact nature and capabilities of this particular threat.

How Trojan.Dialer.GA Operates

Trojan.Dialer.GA, like other Trojans, is likely designed to operate stealthily, avoiding detection by security software and system administrators. It may use various techniques to infect a system, such as exploiting vulnerabilities, disguising itself as a legitimate program, or being downloaded and installed by unsuspecting users. Once installed, the malware can perform a range of malicious activities, including data theft, unauthorized access to system resources, and communication with command and control servers.

Symptoms of Infection

Identifying the symptoms of a Trojan infection can be challenging, as the malware is designed to remain hidden. However, some common signs of infection include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups and alerts. You may also notice unauthorized changes to your system settings, unfamiliar programs or icons, or suspicious network activity. If you suspect that your system is infected with Trojan.Dialer.GA, it's essential to take immediate action to contain and remove the threat.

How to Remove Trojan.Dialer.GA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Dialer.GA from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable security software, you can help to ensure the removal of this malware and prevent future infections. It's also essential to maintain good security practices, such as regularly updating your operating system and software, using strong passwords, and being cautious when downloading and installing programs from the internet. By taking these precautions, you can help to protect your system and personal data from the threats posed by Trojan.Dialer.GA and other types of malware.

Analysis Report

General information

Family Name: Trojan.Dialer.GA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 34f80e4c95022ca5405055bbd789b606
SHA1: 345c0812ce0f80e2ca19c1b423022bcc7c85a797
SHA256: 3574C7CA75F71481EEED44BE9B373D7CE76F917C2F835AF84A6E62A58EA3CB77
File Size: 94.18 KB, 94176 bytes
MD5: d02d78ad1afc906d57a8d866319953b3
SHA1: 00de377e641677de3ab58f0e4ca140616f98c3c3
SHA256: 1A2EB967356B21ACFD651D99DC9366BC19309A22790986685B3F7003EC0F33F5
File Size: 108.61 KB, 108606 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments A Lifestyle GmbH Wilmskamp 15 41069 Mönchengladbach Deutschland +492161966060 InternetAddress: www.aconti.net
Company Name A Lifestyle GmbH
Development Date 17.05.2003
File Description aconti NetService
File Version
  • 2.915
  • 2.24
Legal Copyright
  • (c) 2000,01 A Lifestyle
  • (c) 2000-03 A Lifestyle
Original Filename aconti.exe
Product Name aconti NetService
Product Version
  • 2.915
  • 2.24

File Traits

  • packed
  • x86

Block Information

Total Blocks: 461
Potentially Malicious Blocks: 278
Whitelisted Blocks: 183
Unknown Blocks: 0

Visual Map

x x 0 x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x 0 x x x 0 0 0 x x x x x 0 x 0 0 x x x x x x x x x 0 0 1 x x x x x 0 0 x x 0 x x x 0 0 x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x 0 x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x 0 x x x x 0 x x x 0 x x x 0 x x x 0 0 0 0 x x x x x 0 x x x x x x 0 x 0 x x 0 x x x 0 x x x x 0 x x x 0 x x x x x 0 0 0 x 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Dialer.GA

Files Modified

File Attributes
c:\aconti.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\aconti.log Generic Write,Read Attributes
c:\windows\aconti.dat Generic Write,Read Attributes
c:\windows\aconti.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\aconti.exe Synchronize,Write Attributes
c:\windows\aconti.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\aconti.sdb Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 d� xy�ރ��^��z*Vs} kP~ ��1>��e���1�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::aconti C:\WINDOWS\aconti.exe -auto RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\aconti::displayname aconti RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\aconti::uninstallstring C:\WINDOWS\aconti.exe -uninstall RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 M�  xy* �/��Y�d�kP~� ��ރ�p ��^�o�3Vs}kP~��1"��7 ���ﺃee�� ��1��fe��h�n�i�e�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\aconti::displayicon C:\WINDOWS\aconti.exe RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute

Shell Command Execution

(NULL) C:\WINDOWS\aconti.exe -firstrun