Go Back   DodgeBoard.com - Forums > Special Interests > Computers & Technology
Home Forums Register Search Today's Posts Mark Forums Read

Computers & Technology Computer talk for the nerdy or the needy. Post your technology related topics or tech questions here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-28-2005, 12:55 PM
Detector's Avatar
DodgeBoard Sheriff
 
Join Date: Oct 2005
Posts: 2,314
Casino Cash: $95867
Rep Power: 2109
Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!
Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!Detector Is off the scale!
Randex-Y 10-28-2005

Source: eSecurityplanet.com

10/28: Randex-Y a Network Worm
October 28, 2005

<!--content_start-->W32/Randex-Y is a network worm with backdoor capabilities that allows a remote intruder to access and control the computer via IRC channels.

W32/Randex-Y chooses IP addresses at random and tries to connect to the IPC$ share using simple passwords. If the connection is successful the worm copies itself to the following remote locations:
\ADMIN$\system32\msnv32.exe
\C$\WINNT\system32\msnv32.exe

W32/Randex-Y then schedules a job to execute the remotely created files. Each time the worm is run it tries to connect to a remote IRC server and join a specific channel. The worm then runs in the background as a server process listening for commands to execute.

When first run the worm copies itself to the Windows system folder as IRBMe.exe and adds the following registry entries to point to this copy of the worm to ensure it is run at system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run \IRBMe Sucks!!
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\IRBMe Sucks!!

W32/Randex-Y may also create the file remove.bat in the Windows temp folder. This file is not malicious and can simply be deleted.
__________________
The real treasure is in the hunt...
Digg this Post!Add Post to del.icio.usBookmark Post in Technorati
Reply With Quote
Reply

Bookmarks



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On






Add to Technorati Favorites

All times are GMT -6. The time now is 09:48 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5
Copyright DodgeBoard.com