W32.Randex.AAS is a network-aware worm, which copies itself to, as the following,
to the computers that have weak administrator passwords: \Admin$\system32\GT.exe; \c$\winnt\system32\GT.exe
The worm receives instructions from an IRC channel on a predetermined IRC server.
Copies itself as %System%\LanNSvc.exe.
Calculates a random IP address for a computer that it will try to infect.
Attempts to authenticate itself to the randomly generated IP addresses.
The worm will try connecting as everyone in the list of users who exist on the remote computer, until it successfully connects or runs out of accounts.
This action results in accounts being locked out due to unsuccessful log-on attempts.
Remotely schedules a task to run the worm on a newly infected computer.
Adds the following value:
"TCP Monitoring"="LanNSvc.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Connects to a specific IRC channel on a specific IRC server to receive remote instructions.
Steals the CD key of some games.
Automatic removal:
Use RegRun Startup Optimizer.
Removal: LanNSvc.exe is removed by RegRun.
Read more... Removal instructions...
Recommended software:
UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com
RegRun Security Suite - removal and protection.
http://www.regrun.com
RegRun Reanimator - free removal tool.
greatis.com/reanimator
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
May 12 2008
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?