- Discovered:
- June 4, 2003
- Updated:
- February 13, 2007 12:25:39 PM
- Type:
- Worm
- Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
W32.Randex is a detection for a family of worms that spreads through file-sharing.
W32.Randex can perform different backdoor-type functions, by connecting to a configurable IRC server and joining a specific channel to listen for instructions.
Newer variants may also spread by exploiting the following vulnerabilities:
- The DCOM RPC Vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
- The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011).
- The vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
- The WebDav Vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80.
- The UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS01-059).
- The Workstation Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if the patch in Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply the patch in Microsoft Security Bulletin MS03-049.
Antivirus Protection Dates
- Initial Rapid Release version June 5, 2003
- Latest Rapid Release version May 9, 2012 revision 034
- Initial Daily Certified version June 5, 2003 revision 003
- Latest Daily Certified version May 10, 2012 revision 002
- Initial Weekly Certified release date June 5, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Medium
- Number of Infections: 50 - 999
- Number of Sites: More than 10
- Geographical Distribution: Medium
- Threat Containment: Moderate
- Removal: Easy
Damage
- Damage Level: Medium
Distribution
- Distribution Level: Medium
Writeup By: Kaoru Hayashi



