Content
W32/RAHack!0a7e35347508
- Type
- Virus
- SubType
- -
- Discovery Date
- 08/20/2009
- Length
- 57344
- Minimum DAT
- 5715 (08/20/2009)
- Updated DAT
- 5715 (08/20/2009)
- Minimum Engine
- 5300.2777
- Description Added
- 08/20/2009
- Description Modified
- 08/20/2009 3:47 PM (PT)
Tab Navigation
Characteristics
| File Property | Property Value |
|---|---|
| FileName | 4b665e6bcdb2684179a2ad9204a22f8920bc3319.exe |
| McAfee Artemis | Artemis!0a7e35347508 |
| McAfee Detection | W32/RAHack |
| Length | 57,344 bytes |
| CRC | 35314594 |
| MD5 | 0A7E35347508B16F23EA68734DF75939 |
| SHA1 | 4B665E6BCDB2684179A2AD9204A22F8920BC3319 |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| avast | Win32:Allaple [Wrm] |
| AVG (GriSoft) | Worm/Allaple.D |
| Avira | WORM/Allaple.Gen |
| BitDefender | Win32.Worm.Allaple.Gen |
| clamav | Worm.Allaple-83 |
| Dr.Web | Trojan.Starman |
| Eset | Win32/Allaple.D worm (variant) |
| F-Prot | W32/Allaple.A.gen!Eldorado |
| Kaspersky | Net-Worm.Win32.Allaple.e |
| microsoft | worm:win32/allaple.a |
| norman | allaple.gen1 |
| panda | W32/Rahack.gen.worm |
| rising | Worm.Win32.Allaple.a |
| Sophos | W32/Allaple-F |
| Symantec | W32.Rahack.H |
| Trend Micro | WORM_ALLAPLE.IK |
| vba32 | OScope.Malware-Cryptor.Win32.Allaple |
| V-Buster | Worm.Allaple.Gen (mutant) |
| Vet (Computer Associates) | Win32/Mallar |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Registers DLLs | Informational |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
The following registry elements have been created:
- (default) = nxtwrvlnhrlbskxe
Symptoms
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then further propagate the virus. Although many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
| File Property | Property Value |
|---|---|
| FileName | 4b665e6bcdb2684179a2ad9204a22f8920bc3319.exe |
| McAfee Artemis | Artemis!0a7e35347508 |
| McAfee Detection | W32/RAHack |
| Length | 57,344 bytes |
| CRC | 35314594 |
| MD5 | 0A7E35347508B16F23EA68734DF75939 |
| SHA1 | 4B665E6BCDB2684179A2AD9204A22F8920BC3319 |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| avast | Win32:Allaple [Wrm] |
| AVG (GriSoft) | Worm/Allaple.D |
| Avira | WORM/Allaple.Gen |
| BitDefender | Win32.Worm.Allaple.Gen |
| clamav | Worm.Allaple-83 |
| Dr.Web | Trojan.Starman |
| Eset | Win32/Allaple.D worm (variant) |
| F-Prot | W32/Allaple.A.gen!Eldorado |
| Kaspersky | Net-Worm.Win32.Allaple.e |
| microsoft | worm:win32/allaple.a |
| norman | allaple.gen1 |
| panda | W32/Rahack.gen.worm |
| rising | Worm.Win32.Allaple.a |
| Sophos | W32/Allaple-F |
| Symantec | W32.Rahack.H |
| Trend Micro | WORM_ALLAPLE.IK |
| vba32 | OScope.Malware-Cryptor.Win32.Allaple |
| V-Buster | Worm.Allaple.Gen (mutant) |
| Vet (Computer Associates) | Win32/Mallar |
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
|---|---|
| Registers DLLs | Informational |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
The following registry elements have been created:
- (default) = nxtwrvlnhrlbskxe
Symptoms
Symptoms -
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Method of Infection -
Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A