Rabu, 11 Desember 2013

Posted by Ardiant Utomo
No comments | 18.28

Virus Profile:W32/Almanahe.b

  
Risk Assessment:Home Low | Corporate Low
Date Discovered:4/1/2013
Date Added:7/12/2013
Origin:Unknown
Length:48640
Type:Virus
Subtype:Win32
DAT Required:7031

  
 This is a Virus
File PropertiesProperty Values
Amzkomp DetectionW32/Almanahe.b
Length48640 bytes
MD5215f9064eb731688713a2111ff9a27bd
SHA162b34e208db7bea62a5be5e5927eaa9abd8d0039

Other Common Detection Aliases
Company NamesDetection Names
ahnlabWin32/Alman
avastWin32:Alman
AVG (GriSoft)Win32/Alman
aviraW32/Almanahe.a
KasperskyVirus.Win32.Alman.a
BitDefenderGeneric.IRCBot.87E052BB
clamavW32.Alman.cd-1
Dr.WebWin32.Alman.2
F-ProtW32/Alman.D
FortiNetW32/Alman.DB
Microsofttrojan:win32/almanahe.a.dll
SymantecW32.Spybot.Worm
EsetWin32/Alman.A virus
normanAgent.VEHZ
pandaW32/Almanahe.b
risingWin32.Almanahe.C
SophosW32/Alman-B
Trend MicroPE_ALMANAHE.A
vba32Virus.Alman.a
V-BusterWin32.Agent.HAC
Vet (Computer Associates)Win32/Almanahe.C
Other brands and names may be claimed as the property of others.

ActivitiesRisk Levels
Enumerates many system files and directories.Low
Adds or modifies a COM object.Low
Adds or modifies Internet Explorer cookiesLow
No digital signature is presentInformational

Amzkomp ScansScan Detections
Amzkomp Security EssentialsW32/Almanahe.b

System Changes
Some path values have been replaced with environment variables as the exact location may vary with different configurations.
e.g.
%WINDIR% = \WINDOWS (Windows 9x/ME/XP/Vista/7), \WINNT (Windows NT/2000)
%PROGRAMFILES% = \Program Files

The following files were analyzed:
62B34E208DB7BEA62A5BE5E5927EAA9ABD8D0039
The following files have been added to the system:
  • %WINDIR%\AppPatch\deamon.dll
  • %WINDIR%\img4851.zip
  • %WINDIR%\c_095.nls
  • %WINDIR%\winnt.exe
The following files were temporarily written to disk then later removed:
  • C:\a.bat
The following registry elements have been created:
  • HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{C111980D-B372-44B4-8095-1B6060E8C647}\
  • HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{C111980D-B372-44B4-8095-1B6060E8C647}\INPROCSERVER32\
The following registry elements have been changed:
  • HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{C111980D-B372-44B4-8095-1B6060E8C647}\INPROCSERVER32\THREADINGMODEL = Apartment
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\AUDIO DEVICE MANAGER = WinNT.exe

0 komentar:

Posting Komentar

Blogroll

About