Content
W32/RAHack!7d0ba3dd2d8c
- Type
- Virus
- SubType
- -
- Discovery Date
- 08/21/2009
- Length
- 67584
- Minimum DAT
- 5716 (08/21/2009)
- Updated DAT
- 5716 (08/21/2009)
- Minimum Engine
- 5300.2777
- Description Added
- 08/21/2009
- Description Modified
- 08/21/2009 11:22 AM (PT)
Tab Navigation
Characteristics
| File Property | Property Value |
|---|---|
| FileName | Unavailable |
| McAfee Artemis | Artemis!7d0ba3dd2d8c |
| McAfee Detection | W32/RAHack |
| Length | 67,584 bytes |
| CRC | 63A26820 |
| MD5 | 7D0BA3DD2D8CBD6E392BE9A3A849D827 |
| SHA1 | F4A83E5557C99666366D89508E3FFBE963B6715B |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| avast | Win32:Allaple [Wrm] |
| AVG (GriSoft) | Worm/Allaple.E |
| Avira | W32/Virut.N.DR |
| BitDefender | Win32.Worm.Allaple.Gen |
| clamav | Worm.Allaple-2 |
| Dr.Web | Trojan.Starman.102 |
| Eset | Win32/Kryptik.MY trojan (variant) |
| FortiNet | W32/Virut.fam |
| F-Prot | W32/RAHack.A.gen!Eldorado |
| Kaspersky | Net-Worm.Win32.Allaple.b |
| microsoft | worm:win32/allaple.a |
| norman | allaple.gen3 |
| panda | W32/Rahack.gen.worm |
| rising | Worm.Win32.Allaple.a |
| Sophos | W32/Allaple-F |
| Symantec | W32.Rahack.W |
| Trend Micro | WORM_ALLAPLE.IK |
| vba32 | OScope.Malware-Cryptor.Win32.Allaple |
| V-Buster | Worm.Allaple.Gen (mutant) |
| Vet (Computer Associates) | Win32/Mallar |
Other detections that have been observed.
| FileName | McAfee Supported |
|---|---|
| %COMMONPROGRAMFILES%\microsoft shared\stationery\brvrjrke.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\czjevcet.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\njbsvtll.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\qjllsjhl.exe | W32/RAHack |
| %WINDIR%\system32\urdvxc.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\vkjljzrn.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\elwtjnbj.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\bhrhnkht.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\nsqjttkv.exe | W32/RAHack |
| %USERPROFILE%\local settings\temporary internet files\content.ie5 \zxbyvrni\senntbzs.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\system\ado\tsektjkj.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\tlcwjrwt.exe | W32/RAHack |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
The following files have been added to the system:
The following registry elements have been created:
- (default) = jnjltqrecxctntqe
- (default) = c:\program files\common files\microsoft shared\stationery
\czjevcet.exe
- (default) = lzqswtrnessbqnbj
- (default) = c:\program files\common files\microsoft shared\stationery
\qjllsjhl.exe
- (default) = blxtsszserttnlne
- (default) = c:\program files\common files\system\ado\tsektjkj.exe
- (default) = vllvtvqnhlrlkjlt
- (default) = c:\program files\common files\microsoft shared\stationery
\bhrhnkht.exe
- (default) = svlhnrxhbhrwbkhe
- (default) = chsjctesvvlehrsr
- (default) = c:\program files\common files\microsoft shared\stationery
\tlcwjrwt.exe
- (default) = qhhztrtrrnhtssje
- (default) = c:\program files\common files\microsoft shared\stationery
\nsqjttkv.exe
- (default) = xkesehkrjlesztte
- (default) = c:\program files\common files\microsoft shared\stationery
\elwtjnbj.exe
- (default) = hsbnjhxsnsksqsjl
- (default) = c:\program files\common files\microsoft shared\stationery
\vkjljzrn.exe
- (default) = exrezwzrxhwqttjn
- (default) = nlhjnqseszjenlhn
- (default) = seevtvnsclrntknt
- (default) = wlchqkksbbkjkkve
- (default) = zhhrbsbhklecxzbn
- (default) = c:\windows\system32\urdvxc.exe
- (default) = sknrbbhscthjeejh
- (default) = c:\program files\common files\microsoft shared\stationery
\njbsvtll.exe
- (default) = hhskxtttnnjnexrb
- (default) = c:\program files\common files\microsoft shared\stationery
\brvrjrke.exe
- (default) = tnwwszesrnltnetk
The following registry elements have been changed:
- (default) = 14
- (default) = 15
- activeservice = mswindows
- failureactions = [binary data]
- failurecommand = c:\windows\system32\urdvxc.exe
Symptoms
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then further propagate the virus. Although many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
| File Property | Property Value |
|---|---|
| FileName | Unavailable |
| McAfee Artemis | Artemis!7d0ba3dd2d8c |
| McAfee Detection | W32/RAHack |
| Length | 67,584 bytes |
| CRC | 63A26820 |
| MD5 | 7D0BA3DD2D8CBD6E392BE9A3A849D827 |
| SHA1 | F4A83E5557C99666366D89508E3FFBE963B6715B |
Other Common Detection Aliases
| Company Name | Detection Name |
|---|---|
| avast | Win32:Allaple [Wrm] |
| AVG (GriSoft) | Worm/Allaple.E |
| Avira | W32/Virut.N.DR |
| BitDefender | Win32.Worm.Allaple.Gen |
| clamav | Worm.Allaple-2 |
| Dr.Web | Trojan.Starman.102 |
| Eset | Win32/Kryptik.MY trojan (variant) |
| FortiNet | W32/Virut.fam |
| F-Prot | W32/RAHack.A.gen!Eldorado |
| Kaspersky | Net-Worm.Win32.Allaple.b |
| microsoft | worm:win32/allaple.a |
| norman | allaple.gen3 |
| panda | W32/Rahack.gen.worm |
| rising | Worm.Win32.Allaple.a |
| Sophos | W32/Allaple-F |
| Symantec | W32.Rahack.W |
| Trend Micro | WORM_ALLAPLE.IK |
| vba32 | OScope.Malware-Cryptor.Win32.Allaple |
| V-Buster | Worm.Allaple.Gen (mutant) |
| Vet (Computer Associates) | Win32/Mallar |
Other detections that have been observed.
| FileName | McAfee Supported |
|---|---|
| %COMMONPROGRAMFILES%\microsoft shared\stationery\brvrjrke.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\czjevcet.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\njbsvtll.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\qjllsjhl.exe | W32/RAHack |
| %WINDIR%\system32\urdvxc.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\vkjljzrn.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\elwtjnbj.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\bhrhnkht.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\nsqjttkv.exe | W32/RAHack |
| %USERPROFILE%\local settings\temporary internet files\content.ie5 \zxbyvrni\senntbzs.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\system\ado\tsektjkj.exe | W32/RAHack |
| %COMMONPROGRAMFILES%\microsoft shared\stationery\tlcwjrwt.exe | W32/RAHack |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
The following files have been added to the system:
The following registry elements have been created:
- (default) = jnjltqrecxctntqe
- (default) = c:\program files\common files\microsoft shared\stationery
\czjevcet.exe
- (default) = lzqswtrnessbqnbj
- (default) = c:\program files\common files\microsoft shared\stationery
\qjllsjhl.exe
- (default) = blxtsszserttnlne
- (default) = c:\program files\common files\system\ado\tsektjkj.exe
- (default) = vllvtvqnhlrlkjlt
- (default) = c:\program files\common files\microsoft shared\stationery
\bhrhnkht.exe
- (default) = svlhnrxhbhrwbkhe
- (default) = chsjctesvvlehrsr
- (default) = c:\program files\common files\microsoft shared\stationery
\tlcwjrwt.exe
- (default) = qhhztrtrrnhtssje
- (default) = c:\program files\common files\microsoft shared\stationery
\nsqjttkv.exe
- (default) = xkesehkrjlesztte
- (default) = c:\program files\common files\microsoft shared\stationery
\elwtjnbj.exe
- (default) = hsbnjhxsnsksqsjl
- (default) = c:\program files\common files\microsoft shared\stationery
\vkjljzrn.exe
- (default) = exrezwzrxhwqttjn
- (default) = nlhjnqseszjenlhn
- (default) = seevtvnsclrntknt
- (default) = wlchqkksbbkjkkve
- (default) = zhhrbsbhklecxzbn
- (default) = c:\windows\system32\urdvxc.exe
- (default) = sknrbbhscthjeejh
- (default) = c:\program files\common files\microsoft shared\stationery
\njbsvtll.exe
- (default) = hhskxtttnnjnexrb
- (default) = c:\program files\common files\microsoft shared\stationery
\brvrjrke.exe
- (default) = tnwwszesrnltnetk
The following registry elements have been changed:
- (default) = 14
- (default) = 15
- activeservice = mswindows
- failureactions = [binary data]
- failurecommand = c:\windows\system32\urdvxc.exe
Symptoms
Symptoms -
This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Method of Infection
Method of Infection -
Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A