SEARCH :

Custom Search

Thursday, October 28, 2010

Virus:W32/Alman.A

Name : Virus:W32/Alman.A
Detection names : Virus.Win32.Alman.a
Category : Malware
Type : Virus
Type : Net-Worm
Platform : W32


Details

Registry Modifications :
Creates these keys: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RioDrvs
DisplayName = "RioDrvs Usb Driver"
ImagePath = "system32\Drivers\RioDrvs.sys"

Virus:W32/Alman.A infects all executable files in the system. The virus propagates over a network. It also has rootkit capabilities and is capable of contacting a remote server to forward information about the infected system.

A later variant of this virus, Virus:W32/Alman.B is also in the wild.

Variants of this family may be detected by the Generic Detection, Virus:W32/Alman.gen!A.


Infection


Alman.A infects all .EXE files in the affected system. It appends its code to the target file and sets this as an additional code section. It searches for files to infect in all fixed, shared, and removable drives.

It skips infecting files located in the following directories:

Local Settings\Temp
Windows
WinNT

Execution

Upon execution, this network-propagating virus drops the following files:

[Windows Directory]\linkinfo.dll - infector component
[Windows System Directory]\drivers\DKIS6.sys - rootkit component
[Windows System Directory]\drivers\RioDrvs.sys - rootkit component

The dropped file RioDrvs.sys is registered as a service. The file linkinfo.dll is injected into explorer.exe and is hidden by the rootkit components.

This virus terminates processes with names that match the following strings:
c0nime.exe,cmdbcs.exe, ctmontv.exe,explorer.exe,fuckjacks.exe, iexpl0re.exe,iexplore.exe,internat.exe,logo_1.exe,logo1_.exe, lsass.exe,lying.exe,msdccrt.exe,msvce32.exe,ncscv32.exe,nvscv32.exe, realschd.exe,rpcs.exe,run1132.exe,rundl132.exe,smss.exe,spo0lsv.exe, spoclsv.exe,ssopure.exe,svch0st.exe,svhost32.exe,sxs.exe,sysbmw.exe, sysload3.exe,tempicon.exe,upxdnd.exe,wdfmgr32.exe, wsvbs.exe.

However, the path of the files associated with the above mentioned processes should not contain the following strings:

\com\
\program files\
\system\
\windows\
\winnt\

Once the process is terminated, the corresponding file is also deleted.

You Can Download Win32/Alman here : (Download the following two files)
Alman Removal.exe
Alman Removal.nt

You can also specify the disks (or partitions) to heal as a command parameters, e.g.: "rmalman C: D:". If the command is used without parameters, it heals all disks (partitions) on computer.

Note:
Successful running of the remover requires administrator rights. For proper functionality of the remover it is necessary to save the rmalman.nt into the same folder as rmalman.exe. After the healing process please run the AVG Complete Test to make sure your computer is virus-free.

No comments: