Home Malware Programs Worms Malware.Valla

Malware.Valla

Posted: January 31, 2011

Threat Metric

Ranking: 2,779
Threat Level: 9/10
Infected PCs: 53,910
First Seen: July 24, 2009
Last Seen: October 15, 2023
OS(es) Affected: Windows

Malware.Valla is a network-aware computer worm that uses known system exploits to spread across networks. Malware.Valla can attack single computers but it favours spreading across whole networks, as found in business environments. The worm comes from the Randex family of worms, which are notoriously dangerous for this type of infection. Malware.Valla follows instructions from hackers who link the worm to a remote IRC server which also helps the parasite to produce outbound traffic. System executable files will also modified to hide the pressence of the worm on the system thereby making it difficult to remove.

Network worms like Malware.Valla are designed to steal personal or business information stored on vulnerable networks. The stolen data will be used by hackers for malicious purposes. To make sure your computer network is secure experts recommend using security software with a good track record. Do not give Malware.Valla a chance to spread. Terminate the threat immediately once it has been detected.

Aliases

Trj/Passtealer.FZ [Panda]Worm/Delf.GOD [AVG]W32/AutoRun.LW!worm [Fortinet]Win-Trojan/Autorun.59392.B [AhnLab-V3]W32/SillyFDC-BP [Sophos]TR/Agent.AGBR [AntiVir]Win32.HLLW.Autoruner.1773 [DrWeb]Worm.Win32.AutoRun.EY [Comodo]Trojan.Agent.AGBR [BitDefender]Worm.Win32.AutoRun.lw [Kaspersky]Trojan.Autorun-220 [ClamAV]Win32:AutoRun-QM [Wrm] [Avast]W32/Worm.AXFI [F-Prot]Win32/AutoRun.EY [NOD32]W32/Autorun.worm.r [McAfee]
More aliases (2804)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\documents\database.mdb File name: database.mdb
Size: 8.43 KB (8432 bytes)
MD5: 0a456ffff1d3fd522457c187ebcf41e4
Detection count: 6,277
Mime Type: unknown/mdb
Path: %SYSTEMDRIVE%\Users\<username>\documents
Group: Malware file
Last Updated: October 8, 2023
naked.exe File name: naked.exe
Size: 73.73 KB (73732 bytes)
MD5: da4371bc7347d3633c0eea308c9cb444
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ALLUSERSPROFILE%\Adobe .scr File name: Adobe .scr
Size: 200.7 KB (200704 bytes)
MD5: 4798cecc36d9952ba73633c54f3468b6
Detection count: 77
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 190.46 KB (190464 bytes)
MD5: e1de5e4408e7db707f4a366137f40510
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
%ALLUSERSPROFILE%\Application Data .scr File name: Application Data .scr
Size: 1.23 MB (1232896 bytes)
MD5: 3c59bd20783744e16f749127055b52de
Detection count: 74
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
gip3.exe File name: gip3.exe
Size: 82.84 KB (82848 bytes)
MD5: 644814aa418a3ae1716daa7fb484a539
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
gip1.exe File name: gip1.exe
Size: 45.05 KB (45056 bytes)
MD5: dbea1cc228c9353851e06599788a5a5e
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 203.26 KB (203264 bytes)
MD5: ef0d84b6c1066a09a657e4043070730d
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 210.88 KB (210887 bytes)
MD5: 607970f9d752fc6bb5715be35704936d
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
K:\kop .scr File name: kop .scr
Size: 40.96 KB (40960 bytes)
MD5: 7a0b5674ec20b6455559ca1d70dc2c55
Detection count: 44
Mime Type: unknown/scr
Path: K:
Group: Malware file
Last Updated: October 5, 2017
E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34 File name: VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Size: 40.96 KB (40960 bytes)
MD5: 15c2f7ece2c6647c5e45608e39b08e34
Detection count: 41
Path: E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Group: Malware file
Last Updated: January 10, 2022
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 132.6 KB (132608 bytes)
MD5: 081dd2267978379f9a1864192402837e
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
paukor.exe File name: paukor.exe
Size: 416.25 KB (416256 bytes)
MD5: 7e20359dfc0b2291487f1a45c4471988
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
fintas.exe File name: fintas.exe
Size: 36.86 KB (36864 bytes)
MD5: 42b1eb959ce76f9013e8e9922305ca29
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe File name: Prolin.exe
Size: 36.86 KB (36864 bytes)
MD5: 65eeb8a0fce412d7f236f8348357d1c0
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe
Group: Malware file
Last Updated: October 3, 2023
C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE File name: NAKEDWIF.EXE
Size: 73.72 KB (73728 bytes)
MD5: da9dba70de70dc43d6535f2975cec68d
Detection count: 16
File type: Executable File
Mime Type: unknown/EXE
Path: C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE
Group: Malware file
Last Updated: July 11, 2023
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 226.05 KB (226051 bytes)
MD5: 5176a58244391519e1adb48221377b58
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
e:\ \musallat.exe File name: musallat.exe
Size: 244.6 KB (244606 bytes)
MD5: 6af25dee63ba49ddd86058eb253352cd
Detection count: 15
File type: Executable File
Mime Type: unknown/exe
Path: e:\ 
Group: Malware file
Last Updated: July 10, 2019
toil.exe File name: toil.exe
Size: 8.19 KB (8192 bytes)
MD5: ec8a1659c7d67a3859d515130bae3c4c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 11, 2020
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\musallat.exe File name: musallat.exe
Size: 189.44 KB (189440 bytes)
MD5: bba1a6d47a23806963911a46129fd920
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: July 10, 2019
E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408 File name: VirusShare_2ca27551e11bf054f7c5cb98eac11408
Size: 36.86 KB (36864 bytes)
MD5: 2ca27551e11bf054f7c5cb98eac11408
Detection count: 5
Path: E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408
Group: Malware file
Last Updated: January 20, 2022
magistr.exe File name: magistr.exe
Size: 77.82 KB (77824 bytes)
MD5: a8cfcfa06303168b5f94e0696882a3c8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 24, 2021
E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748 File name: VirusShare_0eb3cca824da735aa040caa012450748
Size: 76.8 KB (76800 bytes)
MD5: 0eb3cca824da735aa040caa012450748
Detection count: 5
Path: E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748
Group: Malware file
Last Updated: January 20, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

File name without path! My Picutre.SCR!new.scrimages.scrNew Folder.exeThumbs .dbwindows vista setup .scrRegexp file mask%ALLUSERSPROFILE%\Adobe .scr%APPDATA%\Microsoft\winlog.exe%APPDATA%\MusaLLaT.exe%APPDATA%\readere_lm.com%SystemRoot%\System32\XP-[RANDOM CHARACTERS].exe%WINDIR%\dc.exe

Additional Information

The following directories were created:
%PROGRAMFILES%\windows common files%PROGRAMFILES(x86)%\windows common files%TEMP%\E_4%TEMP%\E_N4
Loading...