Threat Database Dialers Trojan.Dialer.GA

Trojan.Dialer.GA

By CagedTech in Dialers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 9
First Seen: May 23, 2023
Last Seen: March 10, 2026
OS(es) Affected: Windows

The detection of Trojan.Dialer.GA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially cause harm to your personal data and online activities. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Dialer.GA?

Trojan.Dialer.GA is a type of malware that falls under the category of Trojans, which are malicious programs that disguise themselves as legitimate software. The ".Dialer" part of the name suggests that this malware may be related to dialer programs, which can be used to connect to premium rate phone numbers or perform other unauthorized actions. However, without more specific information, it's difficult to determine the exact nature and capabilities of this particular threat.

How Trojan.Dialer.GA Operates

Trojan.Dialer.GA, like other Trojans, is likely designed to operate stealthily, avoiding detection by security software and system administrators. It may use various techniques to infect a system, such as exploiting vulnerabilities, disguising itself as a legitimate program, or being downloaded and installed by unsuspecting users. Once installed, the malware can perform a range of malicious activities, including data theft, unauthorized access to system resources, and communication with command and control servers.

Symptoms of Infection

Identifying the symptoms of a Trojan infection can be challenging, as the malware is designed to remain hidden. However, some common signs of infection include unusual system behavior, such as slow performance, frequent crashes, or unexpected pop-ups and alerts. You may also notice unauthorized changes to your system settings, unfamiliar programs or icons, or suspicious network activity. If you suspect that your system is infected with Trojan.Dialer.GA, it's essential to take immediate action to contain and remove the threat.

How to Remove Trojan.Dialer.GA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Dialer.GA from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable security software, you can help to ensure the removal of this malware and prevent future infections. It's also essential to maintain good security practices, such as regularly updating your operating system and software, using strong passwords, and being cautious when downloading and installing programs from the internet. By taking these precautions, you can help to protect your system and personal data from the threats posed by Trojan.Dialer.GA and other types of malware.

Analysis Report

General information

Family Name: Trojan.Dialer.GA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 34f80e4c95022ca5405055bbd789b606
SHA1: 345c0812ce0f80e2ca19c1b423022bcc7c85a797
SHA256: 3574C7CA75F71481EEED44BE9B373D7CE76F917C2F835AF84A6E62A58EA3CB77
File Size: 94.18 KB, 94176 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name A Lifestyle GmbH
File Description aconti NetService
File Version 2.24
Legal Copyright (c) 2000,01 A Lifestyle
Original Filename aconti.exe
Product Name aconti NetService
Product Version 2.24

File Traits

  • packed
  • x86

Block Information

Total Blocks: 407
Potentially Malicious Blocks: 158
Whitelisted Blocks: 238
Unknown Blocks: 11

Visual Map

x x x x x x x x x x 0 x x x x 0 0 0 x 0 x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x ? x x x x x x x x x x x x 0 x x 0 x x x x 0 x x ? 0 x x x 0 x x x x x x x ? x x 0 x x x 0 0 x x x x x x x x x x x x ? x x x x x x x x x ? 0 x x x x x x x x x x x x x x x x x x x 0 x x x x ? x x x x x x x x x 0 x 0 x x x x x x 0 x x x ? 1 ? 0 0 ? x x ? x x x ? x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\aconti.log Generic Write,Read Attributes
c:\windows\aconti.dat Generic Write,Read Attributes
c:\windows\aconti.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\aconti.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\aconti.sdb Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 d� xy�ރ��^��z*Vs} kP~ ��1>��e���1�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::aconti C:\WINDOWS\aconti.exe -auto RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\aconti::displayname aconti RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\aconti::uninstallstring C:\WINDOWS\aconti.exe -uninstall RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute

Shell Command Execution

(NULL) C:\WINDOWS\aconti.exe -firstrun

Related Posts

Trending

Most Viewed

Loading...