United Kingdom
  • UK Support
  • My Account
  • Renewal Centre

Bitdefender®

  • Home
  • Home Users
  • Small Business
  • Corporate Business
  • ISPs
  • News
  • About Us
  • Partners
  • Home
  • Defense Center
  • Virus Information for - Win32.Gattman.A
BitDefender Products
  • Home Products
  • BitDefender for your Business
About BitDefender
  • About Us
  • Company Overview

Win32.Gattman.A

Spreading: very low
Damage: very low
Size: 16384 bytes
Discovered: 2006 Jul 13

SYMPTOMS:

Unusually big IDC files (more than 800KB).

TECHNICAL DESCRIPTION:

This is a concept virus, it infects only IDC files (Interactive DisAssembler scripts). It infects one IDC file at a time, and the IDC file grows in size with about 800 KB. The virus enumerates files from the current directory, and checks the SHA1 sum of the extension for a match.

The IDC file once ran, drops a 16384-byte executable file which has only one letter as name and exe extension (for instance G.EXE), and executes it. That is the very same executable that infects IDC files.

To check that a IDC file has already been infected, the virus checks if the size is bigger than 0x66666 bytes (about 400 KB).

The infected script is very much polymorphic and that is done by adding lots of comments with garbage (for instance: /*-%VomsL_Ku*/). The comments can contain non-printable characters. A variable with random name is added in one function already present in the script, and an exe file is created then written using the script functions: writelong, writeshort, writestr or putchar.

As this is a concept virus, it doesn't do any other malware action instead of infecting one IDC file in the current directory.

The infected IDC files are detected by BitDefender as Win32.Gattman.IDC.

Removal instructions:

Please let BitDefender delete/disinfect your files.

ANALYZED BY:

Mihai Neagu ,virus researcher

© 2010 BitDefender

  • Site Map
  • Legal Terms
  • Site Feedback
  • Global Sites
  • Privacy Policy

For Home Users

  • BitDefender® Total Security 2011
  • BitDefender® Internet Security 2011
  • BitDefender® Antivirus Pro 2011
  • BitDefender 2011 Product Comparison

For Small Business

  • For Small Business
  • BitDefender® Small Business Security for Desktops and File Servers
  • BitDefender® Small Business Security for Desktops, File Servers, and Exchange

News

  • BitDefender Finds IT Security Employees Likely to Disclose Sensitive Information on Social Networks
  • BitDefender Internet Security 2010 Receives Esteemed AV-Test Certification
  • BitDefender launches Total Security 2011 today to offer consumers a simplified and enhanced way to safeguard their online world

Tools & Resources

  • Free Online Virus Scanner
  • Renew Product Licence
  • Download Trial Versions
  • Download Datasheets