Home > Support > Global Security Advisor 

Virus Detail

Win32.Gema.D

Date Published:
22 Oct 2004

Last Updated:
26 Oct 2004

Threat Assessment

Overall Risk:   Very Low
Wild:  Medium
Destructiveness:  Low
Pervasiveness:  None

Characteristics

Type : Trojan

Category : Win32

Also known as:  TROJ_CRYPT.A (Trend) , W32/Crypter.B@dl (F-Secure), Troj/Cryptldr-A (Sophos), PWS-Datei (McAfee), Win32/Gema.14336.Trojan, TrojanDownloader.Win32.Crypt (Kaspersky)

Immediate Protection Info

 
SignatureProductRemoval Instructions
23.66.79
eTrust Antivirus v7/8* (InoculateIT Engine)
11.x/8643
eTrust Antivirus v7/8* (Vet Engine)
6.1x/5785
eTrust EZ Antivirus 6.1x
6.2x/8643
eTrust EZ Antivirus 6.2x
10.5x/5785
Vet Anti-Virus 10.5x
10.6x/8643
Vet Anti-Virus 10.6x
 
 
 

Description

Win32.Gema.D is a trojan that downloads and executes arbitrary files. It has been distributed as a 14,336-byte, PECompact compressed, Win32 executable.

Back to top

Method of Infection

Each time Gema.D is executed, it changes its filename and associated registry entries.


It copies itself to the %System% directory using one of the following names:


advmon32.exe
audiocntl.exe
cddrv32.exe
cmt101.exe
cmx32.exe
de32gen.exe
dlldmt.exe
dmtdll.exe
dvraudio.exe
dvrvideo.exe
flpycntl.exe
idecntl.exe
keybdcntl.exe
mainviewex.exe
mdmdll32.exe
modeminf.exe
mousecntl.exe
mousecntl32.exe
msmon.exe
mswavedll.exe
scopedll.exe
sysdpt.exe
sysflg32.exe
sysint16.exe
unldr16.exe
unldrexe.exe
videocntl.exe


Gema.D modifies the registry to ensure that regardless of its chosen filename, it is executed each time Windows is started:


HKLM\Software\Microsoft\Windows\Currentversion\Run\<generated name> = "%System%\<generated filename>.exe"
HKCU\Software\Microsoft\Windows\Currentversion\Run\<generated name> = "%System%\<generated filename>.exe"
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run\ <generated name> = "%System%\<generated filename>.exe"


Back to top

Payload

Downloads and Executes Arbitrary Files

The trojan attempts to periodically contact the IP address: 216.130.216.229, to receive information regarding the locations of files to be downloaded. At the time of publishing this address was inactive. Additional evidence suggests that the files downloaded were porn dialers, specially designed for various locations to match that of the affected machine.


Note: CA has received several reports of different Gema variants from the wild. IP addresses associated with other Gema variants are as follows: 


203.166.19.23
216.130.216.229
216.130.216.225     
216.130.216.242
213.252.5.46


Analysis by Matthew McCormack


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools