Ganda Removal Tool
August 10, 2010
All time downloads
Description of Ganda Removal Tool
Find and delete Ganda virus from your PC
Ganda Removal Tool is a small but effective application that targets the Win32.Ganda.A@mm malware.Once run, it creates two copies of itself in Windows folder: SCANDISK.EXE and another randomly named file (ex: "xjvhtbxt.EXE"). Creates a mutex "SWEDENSUX" in order to allow only one copy of itself in memory. It attempts to shut down processes with names as "virus", "firewall", "f-secure", "symantec", "mcafee", "pc-cillin", "trend micro", "kaspersky", "sophos", "norton".
It infects executable files by searching for *.exe, *.scr and *.lnk files in %windir%DESKTOP and %windir%START MENU If a .lnk file is found, it retrieves the executable path and name contained within the .lnk file, then opens the file (if it founds a .exe or a .scr file, it opens them directly) and adds a stub to the end of the executable file, then hijacks one of the functions ExitProcess, GetProcAddress, GetModuleHandleA, LoadLibraryA to point to the stub.
It harvests e-mails searching for files matching "*.eml","*.htm*","*.dbx" and Windows Address Book. It also contains some hardcoded e-mails.a
Add your review
Top popularity in Antivirus