Re: W32/Delbot-AK



In article <1176894469.489878.283310
@b75g2000hsg.googlegroups.com>, paulcarr@xxxxxxxxxxxxxxx
says...
Has anybody experience a virus referenced as W32/Delbot-AK by sopho's.

We have attempted to clear using sophos across servers.

We think the following files have some thing to do with infection.
cnen.exe & ntoepad.exe.

Does anyone have experience of this and recommendations to removal.


http://www.sophos.com/virusinfo/analyses/w32delbotak.html says this:

W32/Delbot-AK is a worm with backdoor functionality for the Windows platform.

W32/Delbot-AK spreads to other network computers by:
- Scanning network shares for weak passwords
- Exploiting common buffer overflow vulnerabilities
- Symantec (SYM06-010)
- Microsoft Security Advisory (935964): Vulnerability in RPC on Windows DNS Server Could
Allow Remote Code Execution.

When first run W32/Delbot-AK copies itself to <System>\ntoepad.exe and attempts to
download and execute a file from a remote location to <Root>\radi.exe. At the time of
writing, this file was unavailable for download

The following registry entry is created to run ntoepad.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Notepad
<System>\ntoepad.exe



So it looks simple enough to clean.
Boot to Safe Mode, delete that file and registry entry - or just scan with Sophos.
Password all usernames, including Guest even if it shows as
disabled.
Re-boot.
Password any shares
Get up to date with MS patches.

--
If you don't want the whelks don't muck 'em about
If you don't want them someone else may
.



Relevant Pages

  • Re: W32/Delbot-AK
    ... We have attempted to clear using sophos across servers. ... delete that file and registry entry - or just scan with Sophos. ... process claiming to be notepad with Task Manager ...
    (alt.comp.anti-virus)
  • Re: Cant update AdAWare,SpyBot,AVG
    ... I disabled the Windows Firewall, ... When I went to Safe Mode, ... Sophos, and I had to D/L again in Normal Mode. ... > FireWall to allow it to download the needed AV vendor related files. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Memory Read Error.
    ... Sophos big enough and reputable enough in the market to not do such a thing ... Download Avast Cleaner from here: ... Look in the right Pane/window for error message with red or Yellow ... View and Manage Event Logs in Event Viewer in Windows XP ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Update just quits with no errors (continued)
    ... to download in background and notify me when they're ready. ... >> throttled and happened to be too busy to handle the download request. ... >> "Servers are busy, download will continue in the background and you ...
    (microsoft.public.windowsupdate)
  • Re: Update just quits with no errors (continued)
    ... "Servers are busy, download will continue in the background and you will be notified when complete. ... > In the log there's this message repeated "Update not allowed> due to regulation". ...
    (microsoft.public.windowsupdate)