Home Malware Programs Worms Rahack.b

Rahack.b

Posted: March 28, 2006

Rahack.b is a worm that scans the network for PCs running Radmin remote administration tool and attempts to spread to them using a list of known weak passwords. The spyware may give the attacker full unauthorized access to a compromised PC. Rahack.b automatically runs on every Windows startup and every time an executable file is run.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 server.dll
    2 syshid.exe
    3 system.vbs

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERexefileShellOpenCommand(default)=syshid.exe"%1"%*HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsysser
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}3040DD03-9C5A-4563-AC2E-0026188C25A9

Related Posts

Loading...