Content

W32/Almanahe.sys

Type
Trojan
SubType
Win32
Discovery Date
04/16/2007
Length
Varies
Minimum DAT
5010 (04/16/2007)
Updated DAT
5168 (11/21/2007)
Minimum Engine
5.1.00
Description Added
04/16/2007
Description Modified
04/17/2007 4:52 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Symptoms

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Method of Infection

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Removal

VirusScan Users

Use the latest engine and DAT files for detection.

Due to the nature in which this virus operates once a machine is successfully infected, read-access to the DLL and SYS components of the virus may be denied.

VirusScan 11.x and VirusScan Enterprise 8.5 or newer can detect and remove these rootkit-protected components directly.

Older versions of VirusScan will not be able to detect these files in this case. Because of this, if a machine is suspected to be infected, users can follow the procedure below:

  1. Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
  2. Run a system scan using the specified engine/DATs.
  3. Clean files flagged as infected
  4. Restart machine in default mode.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

 

Variants

Variants

    N/A

All Information

Overview -

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Aliases

  • troj/ntrootk-bn (Sophos)
  • troj_corelink.a (TrendMicro)

Characteristics

Characteristics -

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Symptoms

Symptoms -

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Method of Infection

Method of Infection -

W32/Almanahe.sys is the rootkit component of W32/Almanahe.a. More details of this virus at:

Removal -

Removal -

VirusScan Users

Use the latest engine and DAT files for detection.

Due to the nature in which this virus operates once a machine is successfully infected, read-access to the DLL and SYS components of the virus may be denied.

VirusScan 11.x and VirusScan Enterprise 8.5 or newer can detect and remove these rootkit-protected components directly.

Older versions of VirusScan will not be able to detect these files in this case. Because of this, if a machine is suspected to be infected, users can follow the procedure below:

  1. Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
  2. Run a system scan using the specified engine/DATs.
  3. Clean files flagged as infected
  4. Restart machine in default mode.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

 

Variants

Variants -

    N/A