|
|||||||||||
|
Re: TCP 445 Scan?
From: Brian McWilliams <brian(at)pc-radio.com>
Date: Tue Mar 04 2003 - 14:59:33 EST
http://www.viruslist.com/eng/viruslist.html?id=59741 Worm.Win32.Randon Randon is a Virus-Worm distributed via IRC-channels and LANs with shared resources. When executed this worm installs its components into the subdirectory zxz and/or zx in the Windows system directory and registers its main file and the mIRC client in the Windows registry auto-run key (below): HKLM\\Software\Microsoft\Windows\CurrentVersion\Run\updateWins Randon then executes the above key and hides the process via the HideWIndows utility. Randon connects to the IRC-server and executes its scripts. In addition to DDoS attacks and IRC channel flooding, Randon scans port 445 of other IRC clients. [snip] At 01:25 PM 2/27/2003, Charles Hamby wrote:
<Pre>Lose another weekend managing your IDS?
Take back your personal time.
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:59 EDT |
||||||||||
|
|||||||||||