Home Malware Programs Worms W32.Randex.J

W32.Randex.J

Posted: March 28, 2006

W32.Randex.J is a network-aware worm that will copy itself as c$winntcomputer32spolds.exe
The worm receives instructions from an IRC channel on a specific IRC server. One such command will trigger it to spread itself across the network.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}Browsetothekey:Deletethevaluehelpmanager=%System%spoler.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunServices
Loading...