Home Malware Programs Worms Rahack

Rahack

Posted: March 28, 2006

Rahack is a dangerous worm that scans the network for vulnerable PCs running Radmin remote administration tool and infects them. The worm may give the remote attacker full unauthorized access to compromised computers. It also infects all found HTML files.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mscolsrv.exe
    2 server.dll
    3 srvsxc.exe
    4 svchsot.exe
    5 syshid.exe
    6 system.vbs

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTCLSID[randomname]HKEY_CLASSES_ROOTexefileshellopencommand(Default)=syshid.exe%1%*HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsysserHKEY_LOCAL_MACHINESOFTWARERAdminHKEY_LOCAL_MACHINESYSTEMControlSet001ServicesMSCoolServHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesMSCoolServHKEY_LOCAL_MACHINESYSTEMRAdmin

Related Posts

Loading...