Virus Profile: W32/Almanahe.c!bb89081b1531

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 6/28/2009
Date Added: 6/28/2009
Origin: Unknown
Length: 50688
Type: Virus
Subtype: -
DAT Required: 5659
Removal Instructions
   
 
 
   

Description

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then further propagate the virus. Although many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Indication of Infection

This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

Methods of Infection

Viruses are self-replicating. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. Viruses may also spread by infecting files on a network file system or a file system that is shared by another computer.

   

Virus Characteristics

File PropertyProperty Value
FileNamefile(1).exe
McAfee ArtemisArtemis!bb89081b1531
McAfee DetectionW32/Almanahe.c
Length50,688 bytes
CRC5D41822B
MD5BB89081B15318274C49FF3DAEED4D7C2
SHA13091818496F1886898B832A046A47E537E1236FC

Other Common Detection Aliases

Company NameDetection Name
avastWin32:Alman
AVG (GriSoft)Win32/Alman
AviraW32/Almanahe.b
BitDefenderWin32.Almanahe.D
clamavW32.Alman-2
Dr.WebWin32.Alman.1
FortiNetW32/Alman.DB
F-Protw32/alman.c
KasperskyVirus.Win32.Alman.b
microsoftvirus:win32/almanahe.b
normanw32/alman.b
pandaW32/Almanahe.c
risingWorm.Magistr.g
SophosW32/Alman-C
SymantecW32.Almanahe.B!inf
Trend MicroPE_CORELINK.C-1
vba32Virus.Win32.Alman.ab
V-BusterWin32.Alman.B (mutant)
Vet (Computer Associates)
Win32/Almanahe.F!x386

Avert® Labs has observed the following system activities:

ActivityRisk Level
Enumerates running processes
Medium
Writes executable in the system folder
Low
Writes executable in the windows folder
Low
Performs a shell execute of downloaded or existing files
Informational

Other detections that have been observed.

FileNameMcAfee Supported
%WINDIR%\system32\drivers\nvmini.sys
W32/Almanahe.sys
%WINDIR%\linkinfo.dll
W32/Almanahe.dll

This sample can be identified by the following symptoms.

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following files were analyzed:

  • %USERPROFILE%\local settings\temp\file(1).exe
  • The following files have been added to the system:

  • %WINDIR%\linkinfo.dll
  • %WINDIR%\system\svchost.exe
  • %WINDIR%\system32\drivers\nvmini.sys
  • The applications created the following network connection(s):

  • http
    • hxxp://*************
  •    
    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations