Skip to main content

Randon

Classification

Category:

Malware

Aliases:

  • Randon
  • Worm.Win32.Randon
  • Q8Hell

Summary

Randon is a Virus-Worm distributed via IRC-channels and LANs with shared resources.

Removal

Technical Details

When executed this worm installs its components into the subdirectory zxz and/or zx in the Windows system directory and registers its main file and the mIRC client in the Windows registry auto-run key (below):

HKLM\\Software\Microsoft\Windows\CurrentVersion\Run\updateWins

Randon then executes the above key and hides the process via the HideWIndows utility. Randon connects to the IRC-server and executes its scripts. In addition to DDoS attacks and IRC channel flooding, Randon scans port 445 of other IRC clients.

Distribution

Upon detection of an open port (445) the worm runs the batch files sencs.bat and incs.bat which try to locate open resources on the remote computer and connect to them using one of the following passwords:

"admin", "administrator", "root", "admin", "test", "test123", "temp", "temp123", "pass", "password", "changeme"

If a connection is successful the worm opens a socket on port 445, transfers the trojan horse TrojanDownloader.WIn32.APher.gen and runs it. This trojan downloads a self-extracting archive of the worm's 'full' version from "www.q8kiss.net" and installs it in the system.

Additional information

The Randon worm consists of the following components:

Deta.exe - HideWindows utility (WIn32 exe file) fControl.a - an IRC script (port scanning and infection remote computers) IfCOntrol.a - an IRC script (IRC-channels flooding and DDoS attacks (pinging different addresses) ) incs.bat - BATCH file (lan resources password cracker) Libparse.exe is "PrcView" utility (Win32 EXE file) psexec.exe is "PsExec" utility (Win32 EXE file) rcfg.ini - IRC INI file (loading other scripts) rconnect.conf - configuration file reader.w - list of nicknames used by worm to establish connection with IRC-channels Sa.exe - TrojanDOwnloader.Win32.Apher scontrol.a - helper IRC script. sencs.bat - BAT file (this file is transfered to the remote computer to perform TrojanDownloader execution) systrey.exe - renamed mIRC client (Wind32 EXE file).

F-Secure Anti-Virus detects all Randon conmponents as:

Worm.Win32.Randon, TrojanDownloader.Win32.Apher.gen, Backdoor.IRC.mIRC-based, Backdoor.ServU-based, virus dropper, security risk or a "backdoor", BAT/Ircmkac.setup.A, IRC/Q8.backdoor.A, BAT/Q8.backdoor.A, IRC/Mkap.component.

[Kaspersky Lab and F-Secure Corp.; March 4th, 2003]

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.