Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: TCP 445 Scan?

From: Brian McWilliams <brian(at)pc-radio.com>
Date: Tue Mar 04 2003 - 14:59:33 EST


Maybe it's this new worm?

http://www.viruslist.com/eng/viruslist.html?id=59741

Worm.Win32.Randon

Randon is a Virus-Worm distributed via IRC-channels and LANs with shared resources.

When executed this worm installs its components into the subdirectory zxz and/or zx in the Windows system directory and registers its main file and the mIRC client in the Windows registry auto-run key (below):

HKLM\\Software\Microsoft\Windows\CurrentVersion\Run\updateWins

Randon then executes the above key and hides the process via the HideWIndows utility. Randon connects to the IRC-server and executes its scripts. In addition to DDoS attacks and IRC channel flooding, Randon scans port 445 of other IRC clients.

[snip]

Do you need help?X

At 01:25 PM 2/27/2003, Charles Hamby wrote:

>Morning/Afternoon All,


<Pre>Lose another weekend managing your IDS? Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre> <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A> Received on Wed Mar 5 11:29:01 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:59 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library