Content
W32/Virut.a!9BFCFE19
- Type
- Virus
- SubType
- -
- Discovery Date
- 06/30/2008
- Length
- 46197
- Minimum DAT
- 5327 (06/27/2008)
- Updated DAT
- 5327 (06/27/2008)
- Minimum Engine
- 5.2.00
- Description Added
- 06/30/2008
- Description Modified
- 06/30/2008 5:41 AM (PT)
Tab Navigation
Characteristics
| File Property | Property Value |
|---|---|
| File Name | vil_139473_virut.a_ggwppfkv.exe |
| McAfee Detection | W32/Virut.a |
| Length | 46,197 bytes |
| CRC32 | 9BFCFE19 |
| MD5 | e0a73d7f4ccfcae9b28bcd799eca2bd1 |
| SHA1 | 2642FE89D9A338E06858B4B8143CA5FF6D7CF170 |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| AVG (GriSoft) | win32/virut.a |
| Microsoft | virus:win32/virut.a |
| Norman | w32/virut.a |
| Panda | W32/Virutas.B |
| Sophos | W32/Virut-T |
| Symantec | Trojan.Tooso.R |
| Trend Micro | PE_VIRUT.A |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Modifies Memory of Other Processes | High |
| Enumerates running Processes | Medium |
| Sends e-mails using SMTP | Medium |
| Creates Registry Keys and Data values persistent on OS Reboot | Low |
| Writes Executable in the Windows Folder | Low |
| Program often suspends itself | Informational |
Other detections that have been observed.
| File Name | McAfee Supported |
|---|---|
| c:\documents and settings\administrator\application data\hidn\hidn2.exe | W32/Virut.a |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files have been added to the system:
The following registry elements have been created:
- firstrun = 1
The following registry elements have been changed:
- programcount = 2
- drv_st_key = c:\documents and settings\administrator\application data
\hidn\hidn2.exe
- start = 4
The applications created the following network connection(s):
- \Device\RasAcd:knickimbit.de
- hxxp://5050clothing.com /********
- hxxp://axelero.hu /********
- hxxp://calamarco.com /********
- hxxp://ceramax.co.kr /********
- hxxp://charlesspaans.com /********
- hxxp://chatsk.wz.cz /********
- hxxp://checkalertusa.com /********
- hxxp://cibernegocios.com.ar /********
- hxxp://cof666.shockonline.net /********
- hxxp://comaxtechnologies.net /********
- hxxp://concellodesandias.com /********
- hxxp://dev.jintek.com /********
- hxxp://dogoodesign.ch /********
- hxxp://donchef.com /********
- hxxp://erich-kaestner-schule-donaueschingen.de /********
- hxxp://foxvcoin.com /********
- hxxp://grupdogus.de /********
- hxxp://hotchillishop.de /********
- hxxp://ilikesimple.com /********
- hxxp://innovation.ojom.net /********
- hxxp://kisalfold.com /********
- hxxp://knickimbit.de /********
- hxxp://kremz.ru /********
- hxxp://massgroup.de /********
- hxxp://poliklinika-vajnorska.sk /********
- hxxp://prime.gushi.org /********
- NICK zvcpsbyo USER k020501 . . :_
- NICK zvcpsbyo USER k020501 . . :_ JOIN &virtu
- hxxp://svatba.viskot.cz /********
- hxxp://systemforex.de /********
- hxxp://uwua132.org /********
- hxxp://vanvakfi.com /********
- hxxp://vega-sps.com /********
- hxxp://vidus.ru /********
- hxxp://viralstrategies.com /********
- hxxp://vivamodelhobby.com /********
- hxxp://vkinfotech.com /********
- hxxp://vproinc.com /********
- hxxp://v-v-kopretiny.ic.cz /********
- hxxp://vytukas.com /********
- hxxp://waisenhaus-kenya.ch /********
- hxxp://watsrisuphan.org /********
- hxxp://wbecanada.com /********
- hxxp://web-comp.hu /********
- hxxp://webfull.com /********
- hxxp://welvo.com /********
- hxxp://wvpilots.org /********
- hxxp://www.ag.ohio-state.edu /********
- hxxp://www.chapisteriadaniel.com /********
- hxxp://www.chittychat.com /********
- hxxp://www.cort.ru /********
- hxxp://www.crfj.com /********
- hxxp://www.kersten.de /********
- hxxp://www.kljbwadersloh.de /********
- hxxp://www.voov.de /********
- hxxp://www.walsch.de /********
- hxxp://www.wchat.cz /********
- hxxp://www.wg-aufbau-bautzen.de /********
- hxxp://www.wzhuate.com /********
- hxxp://xotravel.ru /********
- hxxp://yeniguntugla.com /********
- hxxp://zebrachina.net /********
- hxxp://zsnabreznaknm.sk /********
E-mails Sent:
Server: (Varies, the following has been observed)
From: (Varies, the following has been observed)
To: (Varies, the following has been observed)
Sender Name: (Varies, the following has been observed)
Subject: (Varies, the following has been observed)
Symptoms
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then further propagate the virus. Although many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
| File Property | Property Value |
|---|---|
| File Name | vil_139473_virut.a_ggwppfkv.exe |
| McAfee Detection | W32/Virut.a |
| Length | 46,197 bytes |
| CRC32 | 9BFCFE19 |
| MD5 | e0a73d7f4ccfcae9b28bcd799eca2bd1 |
| SHA1 | 2642FE89D9A338E06858B4B8143CA5FF6D7CF170 |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| AVG (GriSoft) | win32/virut.a |
| Microsoft | virus:win32/virut.a |
| Norman | w32/virut.a |
| Panda | W32/Virutas.B |
| Sophos | W32/Virut-T |
| Symantec | Trojan.Tooso.R |
| Trend Micro | PE_VIRUT.A |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Modifies Memory of Other Processes | High |
| Enumerates running Processes | Medium |
| Sends e-mails using SMTP | Medium |
| Creates Registry Keys and Data values persistent on OS Reboot | Low |
| Writes Executable in the Windows Folder | Low |
| Program often suspends itself | Informational |
Other detections that have been observed.
| File Name | McAfee Supported |
|---|---|
| c:\documents and settings\administrator\application data\hidn\hidn2.exe | W32/Virut.a |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files have been added to the system:
The following registry elements have been created:
- firstrun = 1
The following registry elements have been changed:
- programcount = 2
- drv_st_key = c:\documents and settings\administrator\application data
\hidn\hidn2.exe
- start = 4
The applications created the following network connection(s):
- \Device\RasAcd:knickimbit.de
- hxxp://5050clothing.com /********
- hxxp://axelero.hu /********
- hxxp://calamarco.com /********
- hxxp://ceramax.co.kr /********
- hxxp://charlesspaans.com /********
- hxxp://chatsk.wz.cz /********
- hxxp://checkalertusa.com /********
- hxxp://cibernegocios.com.ar /********
- hxxp://cof666.shockonline.net /********
- hxxp://comaxtechnologies.net /********
- hxxp://concellodesandias.com /********
- hxxp://dev.jintek.com /********
- hxxp://dogoodesign.ch /********
- hxxp://donchef.com /********
- hxxp://erich-kaestner-schule-donaueschingen.de /********
- hxxp://foxvcoin.com /********
- hxxp://grupdogus.de /********
- hxxp://hotchillishop.de /********
- hxxp://ilikesimple.com /********
- hxxp://innovation.ojom.net /********
- hxxp://kisalfold.com /********
- hxxp://knickimbit.de /********
- hxxp://kremz.ru /********
- hxxp://massgroup.de /********
- hxxp://poliklinika-vajnorska.sk /********
- hxxp://prime.gushi.org /********
- NICK zvcpsbyo USER k020501 . . :_
- NICK zvcpsbyo USER k020501 . . :_ JOIN &virtu
- hxxp://svatba.viskot.cz /********
- hxxp://systemforex.de /********
- hxxp://uwua132.org /********
- hxxp://vanvakfi.com /********
- hxxp://vega-sps.com /********
- hxxp://vidus.ru /********
- hxxp://viralstrategies.com /********
- hxxp://vivamodelhobby.com /********
- hxxp://vkinfotech.com /********
- hxxp://vproinc.com /********
- hxxp://v-v-kopretiny.ic.cz /********
- hxxp://vytukas.com /********
- hxxp://waisenhaus-kenya.ch /********
- hxxp://watsrisuphan.org /********
- hxxp://wbecanada.com /********
- hxxp://web-comp.hu /********
- hxxp://webfull.com /********
- hxxp://welvo.com /********
- hxxp://wvpilots.org /********
- hxxp://www.ag.ohio-state.edu /********
- hxxp://www.chapisteriadaniel.com /********
- hxxp://www.chittychat.com /********
- hxxp://www.cort.ru /********
- hxxp://www.crfj.com /********
- hxxp://www.kersten.de /********
- hxxp://www.kljbwadersloh.de /********
- hxxp://www.voov.de /********
- hxxp://www.walsch.de /********
- hxxp://www.wchat.cz /********
- hxxp://www.wg-aufbau-bautzen.de /********
- hxxp://www.wzhuate.com /********
- hxxp://xotravel.ru /********
- hxxp://yeniguntugla.com /********
- hxxp://zebrachina.net /********
- hxxp://zsnabreznaknm.sk /********
E-mails Sent:
Server: (Varies, the following has been observed)
From: (Varies, the following has been observed)
To: (Varies, the following has been observed)
Sender Name: (Varies, the following has been observed)
Subject: (Varies, the following has been observed)
Symptoms
Symptoms -
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Method of Infection -
Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A