K.J. Zijlstra, Groningen
Get this message
Norton Antivirus has detected the W32.Randex.gen virus in:
File Name: C:Windowssystem32wuamgrd.exe
Domain Name: MSHOME
Systhem Name: ..............
Username: ......................
To delete this Virus I give you the follow solution;
WORM_SDBOT.ZY
Overview Technical Details
QUICK LINKS Solution | Critical Update
--------------------------------------------------------------------------------
Virus type: Worm
Destructive: No
Aliases: Backdoor/SdBot.Server, W32.Randex.gen
Pattern file needed: 1.937.19
Scan engine needed: 6.500
Overall risk rating: Low
--------------------------------------------------------------------------------
Reported infections: Low
Damage Potential: High
Distribution Potential: High
--------------------------------------------------------------------------------
Description:
This SDBOT worm variant propagates into machines on the same network
by exploiting three known vulnerabilities. These are the RPC-DCOM, RPC
Locator Service, and the WebDAV Buffer Overrun vulnerabilities. More
information on these vulnerabilites are provided by Microsoft in the following
pages:
Microsoft Security Bulletin MS03-026
Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
This network worm also propagates into default administrative shares. It
accesses these shares using a long list of passwords.
This worm has backdoor capabilities. It joins Internet Relay Chat (IRC) and
awaits commands sent in by remote users through the chat system. It can
do the following in response to received commands:
Retrieve system information such as:
CPU speed
Free/Total RAM
Windows version and build
Malware uptime
Currently logged on user
Download files/Update itself
Search for files
Send private message
Act as packet sniffer
Launch a denial of service attack against an IRC target
Log keystrokes
Capture video
Execute shell command
Redirect TCP traffic
List threads
This worm runs on Windows 95, 98, NT, ME, 2000, and XP.
Solution:
AUTOMATIC REMOVAL INSTRUCTIONS
To automatically remove this malware from your system, please refer to the
Trend Micro Damage Cleanup Services.
MANUAL REMOVAL INSTRUCTIONS
Restarting in Safe Mode
» On Windows 95
Restart your computer.
Press F8 at the Starting Windows 95 message.
Choose Safe Mode from the Windows 95 Startup Menu then press Enter.
» On Windows 98 and ME
Restart your computer.
Press the CTRL key until the startup menu appears.
Choose the Safe Mode option then press Enter.
» On Windows NT (VGA mode)
Click Start>Settings>Control Panel.
Double-click the System icon.
Click the Startup/Shutdown tab.
Set the Show List field to 10 seconds and click OK to save this change.
Shut down and restart your computer.
Select VGA mode from the startup menu.
» On Windows 2000
Restart your computer.
Press the F8 key, when you see the Starting Windows bar at the bottom of
the screen.
Choose the Safe Mode option from the Windows Advanced Options Menu
then press Enter.
» On Windows XP
Restart your computer.
Press F8 after the Power-On Self Test (POST) is done. If the Windows
Advanced Options Menu does not appear, try restarting and then pressing F8
several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu
then press Enter.
Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware from
executing during startup.
Open Registry Editor. To do this, click Start>Run, type Regedit, then press
Enter.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
In the right panel, locate and delete the entry:
Microsoft Update = "WUAMGRD.EXE"
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>RunServices
In the right panel, locate and delete the entry:
Microsoft Update = "WUAMGRD.EXE"
In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>
Windows>CurrentVersion>Run
In the right panel, locate and delete the entry:
Microsoft Update = "WUAMGRD.EXE"
Close Registry Editor.
Additional Windows ME/XP Cleaning Instructions
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files detected as
WORM_SDBOT.ZY. To do this, Trend Micro customers must download the
latest pattern file and scan their system. Other Internet users can use
HouseCall, Trend Micro’s free online virus scanner.
Applying Patches
This malware exploits known vulnerabilities on certain platforms. Download
and install the critical pathes from the following links:
Microsoft Security Bulletin MS03-026
Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
Trend Micro offers best-of-breed antivirus and content-security solutions for
your corporate network, small and medium business or home PC.
For additional information about this threat, see Technical Details.