Submission Summary:

What's been foundSeverity Level
A network-aware worm that uses known exploit(s) in order to replicate across vulnerable networks.
MS04-012: DCOM RPC Overflow exploit - replication across TCP 135/139/445/593 (common for Blaster, Welchia, Spybot, Randex, other IRC Bots).
Contains characteristics of an identified security risk.

 

Technical Details:

 

Possible Security Risk

Threat CategoryDescription
A network-aware worm that attempts to replicate across the existing network(s)

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 [pathname with a string SHARE]\bcwvzwbh.exe 86,528 bytes MD5: 0xE5080D7D5BF1E35C156BD3C268E7C35F
SHA-1: 0xE7F20C88A16EA58EBAE5E671FD59A3F5570E2E3A
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
2 [pathname with a string SHARE]\bhrhnkht.exe 86,528 bytes MD5: 0xD034B3FA3F00D60757AC160FAE827C10
SHA-1: 0x8425E06DDA5F1AC7EB08A092F34A33722C524A99
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
3 [pathname with a string SHARE]\bnbtzwxt.exe 86,528 bytes MD5: 0xBB919AC44BD08FF9DF3F18FEC40E8D59
SHA-1: 0xCDBD9685DB9E453EFA9BCDB7BF38155793B669FE
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
4 [pathname with a string SHARE]\brvrjrke.exe 86,528 bytes MD5: 0x8250EAF800864C46AC6ABD541FA45530
SHA-1: 0xAE668AEC1E6EE30FFBF7DDDDA35F32BC55B774E7
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
5 [pathname with a string SHARE]\bzqlkhrh.exe 86,528 bytes MD5: 0x891E7F98652420498CAFCC46CA7D6087
SHA-1: 0x2AED6BC70B60C80E2A953404A4097501D1209428
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
6 [pathname with a string SHARE]\czjevcet.exe 86,528 bytes MD5: 0xEC1DF5EA22A7332324C5A59A400C063E
SHA-1: 0x75D5DBFC70838CEEF827157D730D276B818430F5
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
7 [pathname with a string SHARE]\ehbebsrn.exe 86,528 bytes MD5: 0x9CBC9484572F1CF59DFE642B6160E980
SHA-1: 0x4DD945881102B6EA3E881229638BA7D33B42EDAA
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
8 [pathname with a string SHARE]\elwtjnbj.exe 86,528 bytes MD5: 0x0DD020678E0B345289B04F312615116D
SHA-1: 0x52A0672C6A36CCB0B5FBB83AEA665EF2F7C9BF9C
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
9 [pathname with a string SHARE]\njbsvtll.exe 86,528 bytes MD5: 0x435D1BA29792A9C9C7A254141261BC30
SHA-1: 0x86353B8DD2B020CB8B1E012A355CE601F0BF5FA5
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
10 [pathname with a string SHARE]\nsqjttkv.exe 86,528 bytes MD5: 0xEF273D931FC828EEB356386BD768BC6D
SHA-1: 0xB2F0A5595029B5CE0F55621E0067BEEFF54EDF06
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
11 [pathname with a string SHARE]\qjllsjhl.exe 86,528 bytes MD5: 0xCFB2AF281BBCA4C5CBCEDA6B54E0AC0B
SHA-1: 0x477B17D838FB0F0D76FE2605FAD29CC94DB53BBA
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
12 [pathname with a string SHARE]\tlcwjrwt.exe 86,528 bytes MD5: 0x0F224F04AE4A9A4B3705A2452EF27661
SHA-1: 0xBB046E00F0FFA503575506F0AE9ABB092405B942
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
13 [pathname with a string SHARE]\vkjljzrn.exe 86,528 bytes MD5: 0x12520F8292BBC72A3268BB11CDD3FDB2
SHA-1: 0x5D52A72909D49CBC59E45F01A5122F2770E755CD
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
14 [pathname with a string SHARE]\xrljqjzn.exe 86,528 bytes MD5: 0xD09F0683C084A73A6D9A962F97EC7A64
SHA-1: 0xB62AD8ADB8CE53FA880267F713AF35ED4C850B37
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
15 %ProgramFiles%\Common Files\System\ado\tsektjkj.exe 86,528 bytes MD5: 0xC87868865EA8D3A88783A6950787F9F1
SHA-1: 0xBCB066DF8C0C49BC61E2630AC3B16776A2F346D4
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
16 %ProgramFiles%\NetMeeting\rsewzjqn.exe 86,528 bytes MD5: 0xA99DC45EA5FAB26A90502C823DDDB71A
SHA-1: 0x1B379B7157B99148FDF06AABE8349B0138441084
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
17 c:\tvsknrse.exe 86,528 bytes MD5: 0x4BB960304F289B96052CD1538CCFAC26
SHA-1: 0xED251530B435FCCFE6272E0A087137A8EC0006EA
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
18 %Windir%\pchealth\helpctr\System\CompatCtr\hrtbebze.exe 86,528 bytes MD5: 0x6CA89C252874B3B2DECE7AF0F85B2DFE
SHA-1: 0xC242BE3AC610808544491F3C74111E6C0E24D629
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
19 %Windir%\pchealth\helpctr\System\CompatCtr\jbnxjtkn.exe 86,528 bytes MD5: 0x2F856751FB642C28C26A343015E196B4
SHA-1: 0x81BC80E74EF817A5FB58D1BFC25B9B79784B7C5E
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
20 %Windir%\pchealth\helpctr\System\CompatCtr\tnslrrhk.exe 86,528 bytes MD5: 0x048A16DDD4BDBB273D33A11A25A9236D
SHA-1: 0x400F59E9267C28BB81CC5097E6B9D73980D5B4EA
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
21 %Windir%\pchealth\helpctr\System\CompatCtr\zlhqrlbx.exe 86,528 bytes MD5: 0xB9BFA95C331321AF58A926D4593A93FD
SHA-1: 0xADE9B7198A62590FE42FB8B2B933B5740D0822F5
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
22 %Windir%\pchealth\helpctr\System\DVDUpgrd\shrrtjet.exe 86,528 bytes MD5: 0x000DACDF7EF5CAA57536E9925949B1C3
SHA-1: 0xA21C4AC86CD0351C88C33F39858C78B346E3E44F
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
23 %Windir%\pchealth\helpctr\System\ErrMsg\vlvxqrek.exe 86,528 bytes MD5: 0xC292741CCEC001F9EC492859151893A6
SHA-1: 0x969E2274F658C05EB887D25C844B4E82D3C76405
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
24 %Windir%\pchealth\helpctr\System\errors\jcjjlqnq.exe 86,528 bytes MD5: 0x6EB5F8AD3100C1400F1728CCDD195668
SHA-1: 0xF564E183B3536979B6CD4A64297C5C4D3EE3F42A
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
25 %Windir%\pchealth\helpctr\System\NetDiag\hsjqschn.exe 86,528 bytes MD5: 0xD905CC129588F1E5842A30A9E49D61A6
SHA-1: 0x268F81499D214B622F03022F093197F003A318AA
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
26 %Windir%\pchealth\helpctr\System\NetDiag\xrvxszvs.exe 86,528 bytes MD5: 0x68244EA7294662639FCB4505F14C524F
SHA-1: 0xEC80F7BD0D20973B0E04C46DBF2204A157E639B1
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
27 %Windir%\pchealth\helpctr\System\panels\nntlskwn.exe 86,528 bytes MD5: 0x387B472672DB43551F2C9C69F7EA5515
SHA-1: 0x5A8F66C71777FB0A6B0892DB18B03019FE4F26BE
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
28 %Windir%\pchealth\helpctr\System\panels\sncncweb.exe 86,528 bytes MD5: 0x4C192B97C9BF4278D36AC9125950F576
SHA-1: 0xB2E45C3DE112DE880B3C07BC2F8781DF57845879
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
29 %Windir%\pchealth\helpctr\System\rc\qbrblthb.exe 86,528 bytes MD5: 0xE394697FF0DC9B099278B5CE68077242
SHA-1: 0xE4EE778C1BFD2B21CF4E10EBC8C5D5AF7A088D47
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
30 %Windir%\pchealth\helpctr\System\Remote Assistance\Common\hxrshqsj.exe 86,528 bytes MD5: 0x4DEBE0C4AAC23B713819850587CC18E7
SHA-1: 0x55CE12D5F84DF0E892A2F86F74258FF1C1B515F4
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
31 %Windir%\pchealth\helpctr\System\Remote Assistance\Common\rwcjrqhw.exe 86,528 bytes MD5: 0xCCE96710931648D4FC1106CBE334BC52
SHA-1: 0x59620F0F5994F936E51DF714269B611EA6D66557
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
32 %Windir%\pchealth\helpctr\System\Remote Assistance\Common\seshhtth.exe 86,528 bytes MD5: 0x4207BF769ED31CC58F16BE764A5144A5
SHA-1: 0x014B35CCE9CD16AB7EE288254699762F85D08D2A
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
33 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\ekjvhbcn.exe 86,528 bytes MD5: 0x61DDC42E760A9689B350E5586AE265B8
SHA-1: 0x2F9B84BF33AF879B9667991E3C43AE8D0E8FFB75
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
34 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\jjennetl.exe 86,528 bytes MD5: 0xCF479566371CE2A168F8020447196F2F
SHA-1: 0xB73E4A169D395CCE4F2A129774A22E3241DB35A4
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
35 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\knenvxlj.exe 86,528 bytes MD5: 0xE2B55D7602AD2E4CB219E02E9400EBA1
SHA-1: 0x6369A5BE9FC9D6E7149A7FC971B975D6944A432D
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
36 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\ttzvrbzr.exe 86,528 bytes MD5: 0xF07A4BACFD9D54304744FE04D4C5F310
SHA-1: 0x2DB3E59961B689192BF19A47947ADD1D770CAD4D
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
37 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\wbjbjelb.exe 86,528 bytes MD5: 0xD46087E98AB990BF6A19FEAECDE282AB
SHA-1: 0x231067EACEA3F3E69D5EC36CFBA9325BBDC494D2
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
38 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\zqwkjbbt.exe 86,528 bytes MD5: 0xAC1DFD481F378A4DC6A6608795A2B6AF
SHA-1: 0x05ECA0A080B40129AE4D3B7CB725ED82E7BD9892
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
39 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\bbsbrlee.exe 86,528 bytes MD5: 0x39CB13D4D5023A508E78E33818F5CB94
SHA-1: 0x6B66A18FD83EA7BD6C23D05C226A1AB3D95CD991
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
40 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\kbzzlwlr.exe 86,528 bytes MD5: 0x9505CBBDC27841A7B65AA68AA6BA9662
SHA-1: 0x1A153BC274F6CFD54AAC89B771BDDC5B5072A2FC
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
41 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\rbntkevt.exe 86,528 bytes MD5: 0x8AE652275305E903A5DEEA1BAE9E9BB1
SHA-1: 0xC3D68C446B15E4C6CA9871DDED1A5A4CE11563C0
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
42 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\shnkjjbh.exe 86,528 bytes MD5: 0x56DF10391A39E2CF4D51807A8506B7E6
SHA-1: 0x8DEFC66807B04A1DA70C80CEFE48449C7E53E30D
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
43 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ccthwjlr.exe 86,528 bytes MD5: 0x3330F72230E4A618F62223471618BB1F
SHA-1: 0x9655231798DD108593A2C9AF7A6509FA150180D4
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
44 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ctjxljxh.exe 86,528 bytes MD5: 0x68DCD1C10F49A0FC9106430620123E4B
SHA-1: 0xFE8B6F7A27E5585D7AE5F334C79FDE742C926682
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
45 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ezslqrbz.exe 86,528 bytes MD5: 0xBE2C6C616B483D507094AB7773F9BA3D
SHA-1: 0x409E0F91AD2B128A20B4F5912B2EFDBF988CEEF1
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
46 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\neqvzkeh.exe 86,528 bytes MD5: 0x0D837FD694BF8F77D920C76AAA02D905
SHA-1: 0xF08A894BC3677750B9E3B95E943BE9B57555A156
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
47 %Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\shrnxshq.exe 86,528 bytes MD5: 0x4896EBEE2AF0C1FB454BD175C3AC41DB
SHA-1: 0x6CCD92C7877D260DD3117DFCD41781914CD7F5A5
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
48 %Windir%\pchealth\helpctr\System\Remote Assistance\rqxjhbsl.exe 86,528 bytes MD5: 0x0288A2D359276CA00F7A0DA2FD90D57E
SHA-1: 0xBD111CCE4019F8CA2B40B587A313B25C446C3212
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
49 %Windir%\pchealth\helpctr\System\Remote Assistance\rzqstbqq.exe 86,528 bytes MD5: 0x721DCFD5B83243F550903E706A0E52E8
SHA-1: 0xFC0B2BDF96A961B727CB5B511F4CEB9663506103
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
50 %Windir%\pchealth\helpctr\System\Remote Assistance\wesnhzec.exe 86,528 bytes MD5: 0x8FE3C39D19535CCAD4B27E11185958A7
SHA-1: 0x186F548D97B0245F1954B46FFBB02555BC10B7B8
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
51 %Windir%\pchealth\helpctr\System\sysinfo\bjlkjrls.exe 86,528 bytes MD5: 0x8F9C8EB5CCD6B9486FAED8D2CE9DCB50
SHA-1: 0x931E80DE79C5546CC4E5F63F73B65814DC08B3E0
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
52 %Windir%\pchealth\helpctr\System\sysinfo\cntbrbzr.exe 86,528 bytes MD5: 0x0A892B8D7DAB2835AE5512E26660190D
SHA-1: 0xC10921EE7FD8B9B93570ED7FA215F6DD3EE92008
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
53 %Windir%\pchealth\helpctr\System\sysinfo\jbrhbztz.exe 86,528 bytes MD5: 0xD844A9C63F5F0DB8B56E6D3075370586
SHA-1: 0x0B66BE8947EEAC798594B170C8A8DA18E5AD2AC8
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
54 %Windir%\pchealth\helpctr\System\sysinfo\jrtqcssx.exe 86,528 bytes MD5: 0x5BCED829991C5D45D166B36AC3A2F157
SHA-1: 0xCC7D7CA4E13AD52F17712BE0C8572EA0D0EC87EC
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
55 %Windir%\pchealth\helpctr\System\sysinfo\rbcjjwqr.exe 86,528 bytes MD5: 0xA021CFBCE580F19A35EAD45582D7B3FD
SHA-1: 0x62E9742DF70AE956309B2ABC30CC3325D650C484
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
56 %Windir%\pchealth\helpctr\System\sysinfo\rercrnhh.exe 86,528 bytes MD5: 0x4148966BC7C3AA28023DF9CF2FD120DF
SHA-1: 0x17C1932A97A5013E0C9FCEBB8217B0C9A51B6845
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
57 %Windir%\pchealth\helpctr\System\sysinfo\rnbrkrlv.exe 86,528 bytes MD5: 0x6A95F26EA9A590BDBD5FA9F8336FCB32
SHA-1: 0x41D0A3901DDA8977F4381AD3EC4FB21D41F87EE5
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
58 %Windir%\pchealth\helpctr\System\sysinfo\vkchbbxh.exe 86,528 bytes MD5: 0xB3D0E136460A710F7CCBBC9B44C84189
SHA-1: 0xB4A81D3E8206F1E07099FCEC067FDA9482A26B9E
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
59 %Windir%\pchealth\helpctr\System\UpdateCtr\lwklbvze.exe 86,528 bytes MD5: 0x4A5559BD72D86D63662135AA716164F5
SHA-1: 0xD927367A78AFDB9DF2B0D66390C580C1681A1D7D
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
60 %Windir%\pchealth\helpctr\System\UpdateCtr\qxshkkqn.exe 86,528 bytes MD5: 0x67D0F54E4390F9BFE68B4ED2046A1519
SHA-1: 0x1EF9C1A5049200760C534414712577BA20929109
W32.Rahack.W [Symantec]
Net-Worm.Win32.Allaple.b [Kaspersky Lab]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
61 %Windir%\pchealth\helpctr\System\UpdateCtr\rrbvcsbb.exe 86,528 bytes MD5: 0xC6D2CC301365E2117F6758F242C3DABB
SHA-1: 0x41CE5E4A5F74D174A9ACBA94A554149A84F794CD
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
62 %Windir%\pchealth\helpctr\System\UpdateCtr\snqesjrk.exe 86,528 bytes MD5: 0xC6669BCD8B8EA3AA8D2772846D5E6208
SHA-1: 0x402D3EF9F5409E03C434F7CC6BD3C7F0F1D1DC2A
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
63 %Windir%\pchealth\helpctr\System\UpdateCtr\trkhkjxz.exe 86,528 bytes MD5: 0xEFF8A76C17970F70449D896725FEB5FD
SHA-1: 0x5B8B25A6E832A2CDF97F6C2246FFD478C7C05F9E
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
64 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\erwskeqr.exe 86,528 bytes MD5: 0xA241A49C1D61ED564346E5448347DA4A
SHA-1: 0xA4818E2B39045E12895ADFE5181D33E1A469301C
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
65 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\kkrtrbns.exe 86,528 bytes MD5: 0x3A146B2DD353FF35FCD082D819968FD9
SHA-1: 0x1A7BF5B8E14E11D910588B7251E5312FFCC43822
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
66 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\vxwqhwzs.exe 86,528 bytes MD5: 0xE93B2DB7CC9F49690FE82BB197986209
SHA-1: 0x9123AD7B12CE4D8607A6B76A24FC7FE3133A7972
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
67 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\vxwqhwzs.exe 86,528 bytes MD5: 0x39D515FF74881DC91BA66EC2C7185FF8
SHA-1: 0x2013BE434841A7772BE89EF70E0B28DEEF5B7261
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
68 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\vxwqhwzs.exe 86,528 bytes MD5: 0x51F0B06AC498512C0488883A954741FA
SHA-1: 0x3E9F3C276B399DC63B4100AF89668B1A8882FF73
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
69 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\vxwqhwzs.exe 86,528 bytes MD5: 0x8C66455EAF9A4C00E2BC304EAFE56329
SHA-1: 0x52D4037B871E5E3310624476B49CAF650B4B7025
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
70 %Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\vsekkehe.exe 86,528 bytes MD5: 0x6372B52DA64657D0FF5BA70CC0C7E11F
SHA-1: 0xB1C1949835E6584C5DF2C863B27F45F8B2BFF31C
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
71 [file and pathname of the sample #1] 86,528 bytes MD5: 0x7441A79E4F6726CD2543D34C37F4F793
SHA-1: 0xCC446A42D3ECBFC2E677F848940564D57235EB41
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]
72 %System%\urdvxc.exe 86,528 bytes MD5: 0x99D6658E3D54F5A0C023A183D5E93DCA
SHA-1: 0x51B38089049EEEFE18044C91665BA85BEC1906F1
W32.Rahack.W [Symantec]
W32/RAHack [McAfee]
WORM_ALLAPLE.IK [Trend Micro]
W32/Allaple-F [Sophos]
Worm:Win32/Allaple.A [Microsoft]
Net-Worm.Win32.Allaple [Ikarus]
Win-Trojan/Starman.Gen [AhnLab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]159,744 bytes

Service NameDisplay NameStatusService Filename
MSWindowsNetwork Windows Service"Stopped""%System%\urdvxc.exe" /service

 

Registry Modifications

 

Other details

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.