Sophos

W32/Randon-AO

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 4 July 2005 18:59:42 (GMT)
Last updated 26 July 2005 15:03:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AERVICESN
<Windows folder>\Abero\winp\AERVICESN.exe

and delete it if it exists.

Close the registry editor.

More Information

W32/Randon-AO is a multi-component network worm.

W32/Randon-AO contains an IRC backdoor that allows a remote intruder to gain access to and control over the computer.

W32/Randon-AO may attempt to spread to network shares and through the LSASS (MS04-011) vulnerability. W32/Randon-AO is a multi-component network worm.

W32/Randon-AO contains an IRC backdoor that allows a remote intruder to gain access to and control over the computer.

W32/Randon-AO may attempt to spread to network shares and through the LSASS (MS04-011) vulnerability.

When W32/Randon-AO is installed the following files are created:

<Windows folder>\Abero\Winp\AERVICESN.DAT - data file
<Windows folder>\Abero\Winp\AERVICESN.exe - Troj/Glitch-J
<Windows folder>\Abero\Winp\AERVICESNA.exe - mIRC application
<Windows folder>\Abero\Winp\X-ScanCfg.ini - data file
<Windows folder>\Abero\Winp\calcu.exe - process viewer application
<Windows folder>\Abero\Winp\dat\config.ini - data file
<Windows folder>\Abero\Winp\dat\language.ini - data file
<Windows folder>\Abero\Winp\dat\nt_pass.dic - data file
<Windows folder>\Abero\Winp\dat\nt_user.dic - data file
<Windows folder>\Abero\Winp\dat\os.finger - data file
<Windows folder>\Abero\Winp\dat\port.ini - data file
<Windows folder>\Abero\Winp\dat\rpc.ini - data file
<Windows folder>\Abero\Winp\dl.exe - Troj/RpcLsa-A
<Windows folder>\Abero\Winp\eoputr.exe - application used to hide display windows
<Windows folder>\Abero\Winp\h1.bat - batch file used to modify file attributes
<Windows folder>\Abero\Winp\h2.bat - batch file used to modify file attributes
<Windows folder>\Abero\Winp\ipcfg.exe - FTP server application
<Windows folder>\Abero\Winp\mirc.ini - data file
<Windows folder>\Abero\Winp\plugin\090-ntpass.xpn - network scanning application
<Windows folder>\Abero\Winp\psexec.exe - process launching application
<Windows folder>\Abero\Winp\rconnect.conf - data file
<Windows folder>\Abero\Winp\roudSTID.EXE - network scanning application
<Windows folder>\Abero\Winp\rty.ini - data file
<Windows folder>\Abero\Winp\skerr.dll - W32/Randon-AO
<Windows folder>\Abero\Winp\van32.eXe - application used to hide display windows
<Windows folder>\Abero\Winp\xpxp.exe - Troj/Apher-Q

The following registry entry is created to run AERVICESN.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AERVICESN
<Windows folder>\Abero\winp\AERVICESN.exe

The following patches for the operating system vulnerabilities exploited by W32/Randon-AO can be obtained from the Microsoft website:

MS04-011.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer