Sophos

Troj/RaHack-A

Aliases
  • Backdoor.Win32.Agent.go
  • W32/RAHack
  • virus
  • BKDR_RASBA.B
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 17 February 2005 13:31:39 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/RaHack-A will copy itself into %windows%\system32 folder under the name mscolsrv.exe and svchsot.exe. It will also drop the following files:

%Start Menu%\Programs\Startup\system.vbs
%windows%\system32\server.dll
%windows%\system32\syshid.exe (detected as Troj/Agent-BQ)

It will attempt to autostart itself by setting the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sysser
HKCR\exefile\Shell\open\command\
@ = syshid.exe \"%1\" %*\"

And create a service in the name "MSCoolServ".

System.vbs is responsible for start the COM serers for "ComDll.1", for which registry entries could be found in:

HKCR\ComDll.1\
HKCR\ComDll.1\CLSID\(default) = %clsid%
HKCR\CLSID\%clsid%\
HKCR\CLSID\%clsid%\TypeLib\(default) = %typelibid%
HKCR\CLSID\%typelibid%\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer