Virus Characteristics
| File Property | Property Value |
| FileName | file(1).exe |
| McAfee Artemis | Artemis!bb89081b1531
|
| McAfee Detection | W32/Almanahe.c |
| Length | 50,688 bytes |
| CRC | 5D41822B |
| MD5 | BB89081B15318274C49FF3DAEED4D7C2
|
| SHA1 | 3091818496F1886898B832A046A47E537E1236FC
|
Other Common Detection Aliases
| Company Name | Detection Name |
| avast | Win32:Alman |
| AVG (GriSoft) | Win32/Alman |
| Avira | W32/Almanahe.b |
| BitDefender | Win32.Almanahe.D |
| clamav | W32.Alman-2 |
| Dr.Web | Win32.Alman.1 |
| FortiNet | W32/Alman.DB |
| F-Prot | w32/alman.c |
| Kaspersky | Virus.Win32.Alman.b |
| microsoft | virus:win32/almanahe.b
|
| norman | w32/alman.b |
| panda | W32/Almanahe.c |
| rising | Worm.Magistr.g |
| Sophos | W32/Alman-C |
| Symantec | W32.Almanahe.B!inf |
| Trend Micro | PE_CORELINK.C-1 |
| vba32 | Virus.Win32.Alman.ab
|
| V-Buster | Win32.Alman.B (mutant)
|
Vet (Computer Associates)
| Win32/Almanahe.F!x386
|
Avert® Labs has observed the following system activities:
| Activity | Risk Level |
Enumerates running processes
| Medium |
Writes executable in the system folder
| Low |
Writes executable in the windows folder
| Low |
Performs a shell execute of downloaded or existing files
| Informational |
Other detections that have been observed.
| FileName | McAfee Supported |
%WINDIR%\system32\drivers\nvmini.sys
| W32/Almanahe.sys |
%WINDIR%\linkinfo.dll
| W32/Almanahe.dll |
This sample can be identified by the following symptoms.
System Changes
These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following files were analyzed:
%USERPROFILE%\local settings\temp\file(1).exe
The following files have been added to the system:
%WINDIR%\linkinfo.dll%WINDIR%\system\svchost.exe%WINDIR%\system32\drivers\nvmini.sys
The applications created the following network connection(s):
http