Win32.Ganda.A@mm( W32/Ganda@MM (McAfee), Ganda (F-Secure) )
SYMPTOMS: - Presence of the following registry keys:[HKEY_LOCAL_MACHINE\Software\SS] [HKEY_LOCAL_MACHINE\Software\SS\Sent] [HKEY_LOCAL_MACHINE\Software\SS\Sent2] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\ CurrentVersion\Run\"ScanDisk"="C:\WINDOWS\SCANDISK.exe"] - File "SCANDISK.exe" in Windows folder, 45,056 bytes in size - a randomly named file in Windows folder, 45,056 bytes in size (ex: "xjvhtbxt.EXE") TECHNICAL DESCRIPTION: Once run, it creates two copies of itself in Windows folder: SCANDISK.EXE and another randomly named file (ex: "xjvhtbxt.EXE").Creates a mutex "SWEDENSUX" in order to allow only one copy of itself in memory. It attempts to shut down processes with names as "virus","firewall","f-secure","symantec","mcafee","pc-cillin","trend micro","kaspersky","sophos","norton". It infects executable files by searching for *.exe, *.scr and *.lnk files in %windir%\DESKTOP\ and %windir%\START MENU\ If a .lnk file is found, it retrieves the executable path and name contained within the .lnk file, then opens the file (if it founds a .exe or a .scr file, it opens them directly) and adds a stub to the end of the executable file, then hijacks one of the functions ExitProcess, GetProcAddress, GetModuleHandleA, LoadLibraryA to point to the stub. The stub loads and executes the file with random name in Windows folder (ex: "xjvhtbxt.EXE"). It creates registry key [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\ CurrentVersion\Run\"ScanDisk"="C:\WINDOWS\SCANDISK.exe"] It looks in [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] and [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices] and attempts to modify the files pointed by the keys, and render them unusable. It harvests e-mails searching for files matching "*.eml","*.htm*","*.dbx" and Windows Address Book. It also contains the next hardcoded e-mails: This mass-mailer uses IFRAME exploit (infected e-mails opened in Outlook will execute automatically) and features it's own SMTP engine and attempts to connect to a mailserver in Sweden. The subject and body of the e-mails may vary, but the attachment is a file ??.scr where ? is any random letter (ex: xx.scr). Subject/body are in english or swedish, the mass-mailer gets the default language using GetSystemDefaultLangID function. The body is always in html. The subjects and bodies of an infected e-mail may be: Subject: Screensaver advice Body: Do you think this screensaver could be considered illegal? Would appreciate if you or any one of your friends could check it out and answer as soon as humanly possible. Thanx ! ------------------- Subject: Spy pics. Body: Here's the screensaver i told you about. It contains pictures taken by one of the US spy satellites during one of it's missions over iraq. If you want more of these pic's you know where you can find me. Bye! ------------------- Subject: GO USA !!!! Body: This screensaver animates the star spangled banner. Please support the US administration in their fight against terror. Thanx a lot! ------------------- Subject: G.W Bush animation. Body: Here's the animation that the FBI wants to stop. Seems like the feds are trying to put an end to peoples right to say what they think of the US administration. Have fun! ------------------- Subject: Is USA a UFO? Body: Have a look at this screensaver, and then tell me that George.W Bush is not an alien. ;-) ------------------- Subject: Is USA always number one? Body: Some misguided people actually believe that an american life has a greater value than those of other nationalities. Just have a look at this pathetic screensaver and then you'll know what i'm talking about. All the best. ------------------- Subject: LINUX. Body: Are you a windows user who is curious about the linux environment? This screensaver gives you a preview of the KDE and GNOME desktops. What's more, LINUX is a free system, meaning anyone can download it. ------------------- Subject: Nazi propaganda? Body: This screensaver has been banned in Germany. It contains a number of animated symbols that can be related to the nazi culture. What do you think, is it a legitimate ban or not? Please answer asap. Thanx! ------------------- Subject: Catlover. Body: If you like cats you'll love this screensaver. It's four animated kittens running around on the screen. Contact me for more clipart. Have fun! ;-) ------------------- Subject: Disgusting propaganda. Body: Hello! My 12 year old doughter received this screensaver on a CDROM that was sent to her through advertising. I find it disturbing that children are now being targets of nazi organizations. I would appreciate to hear from you on this matter, as soon as possible. Thank you. ------------------- Subject: Olaglig_sk„rmsl„ckare? Body: Hej! Min son visade mig denna sk„rmsl„ckare som jag misst„nker kan bryta mot lagen om hets mot folkgrupp. Eftersom du „r verksam som jurist, s† vore jag tacksam f”r en fackmans syn p† saken. Tack p† f”rhand. ------------------- Subject: Rashets eller inte? Body: Hejsan! Min datal„rare gjorde mig uppm„rksam p† att denna sk„rmsl„ckare m”jligen kan t„nkas vara ett verk av rasister. Nu vet jag varken ut eller in, eftersom jag hade t„nkt anv„nda den p† min skoldator. B”r jag att forts„tta att anv„nda den? Svara helst snarast. Tack p† f”rhand. ------------------- Subject: Hakkors. Body: Hej! Min klassf”rest†ndare gick i taket n„r hon fick se sk„rmsl„ckaren som jag har anv„nt under tv† terminer. Hon anklagade mig f”r antisemitism eftersom den ibland visar ett hakkors. Tycker du att jag b”r acceptera detta fr†n henne? Vore tacksam f”r ett utl†tande fr†n dig. Svara helst s† snart det g†r. ------------------- Subject: Suspekta semaforer. Body: Hejsan ! I skolan hittade jag en CD skiva som inneh”ll bl.a denna sk„rmsl„ckare. En l„rare som r†kade kasta ett ”ga p† den avf„rdade dess inneh†ll som ren rasistisk propaganda. Sj„lv tycker jag inte att det „r n†got att orda om. Vore tacksam f”r din uppfattning. Tack p† f”rhand. ------------------- Subject: Avskyv„rd_reklam.? Body: Hej! Min minder†rige son fick denna sk„rmsl„ckare p† en CD skiva via ett massutskick av reklam. Jag uppr”rs ”ver det s„tt p† vilket rasistiska och nazistiska propagandister till†ts f”rmedla sin avskyv„rda ideologi till barn. Jag ”verv„ger nu att polisanm„la detta tilltag s† snart du, i egenskap av juridisk fackman, delgett mig din †sikt. Tack p† f”rhand. ------------------- Subject: ™verviktiga_f”rnedras.? Body: Hejsan ! Jag ”verv„ger att polisanm„la denna sk„rmsl„ckare. Jag anser att den har en nedl†tande attityd gentemot ”verviktiga personer. Jag skulle bli ytterst tacksam om du kunde bidra med din syn p† saken. Tack p† f”rhand. ------------------- Subject: Go ack ack ack.... Body: Hej igen! Den h„r sk„rmsl„ckaren verkar vara en amerikansk parodi p† n†got som svenskarna g”r p† midsommar. Skratta inte ihj„l dig bara. :-) ------------------- Subject: Žr_USA_ett_UFO=3F? Body: Hej igen! H„r „r sk„rmsl„ckare nummer 4. Kolla in den och tala sedan om f”r mig att George W Bush INTE „r en rymdvarelse. ;-) ------------------- Subject: Korkad president. Body: Hej igen! H„r „r sk„rmsl„ckaren som jag snackade om. George W Bush verkar inte vara allf”r bright om man ska tro brittiska komiker. ------------------- Subject: Katt, hund, kanin. Body: Hej igen! Om du gillar djur s† m†ste denna sk„rmsl„ckare vara n†\'t f”r dig. Mjau, Voff, Arf Arf.... ;-) ------------------- Subject: DISKRIMINERAD !!!! Body: ... (the body is too long to be listed here) The mass-mailer contains two encrypted strings: "I support animal-liberators worldwide." and "[WORM.SWEDENSUX] Coded by Uncle Roger in HSrnösand, Sweden, 03.03. I am being discriminated by the swedish schoolsystem. This is a response to eight long years of discrimination." Removal instructions: - automatic removal: let BitDefender delete/disinfect files found infected.- use the free removal tool from BitDefender ANALYZED BY: Patrik Vicol BitDefender Virus Researcher |