Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 4 July 2005 18:59:42 (GMT) |
| Last updated | 26 July 2005 15:03:25 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AERVICESN
<Windows folder>\Abero\winp\AERVICESN.exe
and delete it if it exists.
Close the registry editor.
More Information
W32/Randon-AO is a multi-component network worm.
W32/Randon-AO contains an IRC backdoor that allows a remote intruder to gain access to and control over the computer.
W32/Randon-AO may attempt to spread to network shares and through the LSASS (MS04-011) vulnerability. W32/Randon-AO is a multi-component network worm.
W32/Randon-AO contains an IRC backdoor that allows a remote intruder to gain access to and control over the computer.
W32/Randon-AO may attempt to spread to network shares and through the LSASS (MS04-011) vulnerability.
When W32/Randon-AO is installed the following files are created:
<Windows folder>\Abero\Winp\AERVICESN.DAT - data file
<Windows folder>\Abero\Winp\AERVICESN.exe - Troj/Glitch-J
<Windows folder>\Abero\Winp\AERVICESNA.exe - mIRC application
<Windows folder>\Abero\Winp\X-ScanCfg.ini - data file
<Windows folder>\Abero\Winp\calcu.exe - process viewer application
<Windows folder>\Abero\Winp\dat\config.ini - data file
<Windows folder>\Abero\Winp\dat\language.ini - data file
<Windows folder>\Abero\Winp\dat\nt_pass.dic - data file
<Windows folder>\Abero\Winp\dat\nt_user.dic - data file
<Windows folder>\Abero\Winp\dat\os.finger - data file
<Windows folder>\Abero\Winp\dat\port.ini - data file
<Windows folder>\Abero\Winp\dat\rpc.ini - data file
<Windows folder>\Abero\Winp\dl.exe - Troj/RpcLsa-A
<Windows folder>\Abero\Winp\eoputr.exe - application used to hide display windows
<Windows folder>\Abero\Winp\h1.bat - batch file used to modify file attributes
<Windows folder>\Abero\Winp\h2.bat - batch file used to modify file attributes
<Windows folder>\Abero\Winp\ipcfg.exe - FTP server application
<Windows folder>\Abero\Winp\mirc.ini - data file
<Windows folder>\Abero\Winp\plugin\090-ntpass.xpn - network scanning application
<Windows folder>\Abero\Winp\psexec.exe - process launching application
<Windows folder>\Abero\Winp\rconnect.conf - data file
<Windows folder>\Abero\Winp\roudSTID.EXE - network scanning application
<Windows folder>\Abero\Winp\rty.ini - data file
<Windows folder>\Abero\Winp\skerr.dll - W32/Randon-AO
<Windows folder>\Abero\Winp\van32.eXe - application used to hide display windows
<Windows folder>\Abero\Winp\xpxp.exe - Troj/Apher-Q
The following registry entry is created to run AERVICESN.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AERVICESN
<Windows folder>\Abero\winp\AERVICESN.exe
The following patches for the operating system vulnerabilities exploited by W32/Randon-AO can be obtained from the Microsoft website:
