Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Backdoors >> CodeRed version X detection


Vulnerability Assessment Details

CodeRed version X detection

Vulnerability Assessment Summary
CodeRed version X detection

Detailed Explanation for this Vulnerability Assessment
Your machine is infected with the 'Code Red' worm. Your Windows system seems to be compromised.

Solution:
1) Remove the file root.exe from both directories:
\inetpub\scripts

and

\program files\common files\system\msadc

2) Install an updated antivirus program (this will remove the Explorer.exe Trojan)
3) Set SFCDisable in hklm\software\microsoft\windows nt\currentversion\winlogon to: 0
4) Remove the two newly created virtual directories: C and D (Created by the Trojan)
5) Make sure no other files have been modified.

It is recommended that hosts that have been compromised by Code Red X would reinstall the operating system from scratch and patch it accordingly.

Network Security Threat Level: High

Additional information:
http://www.securiteam.com/securitynews/5GP0V004UQ.html
http://www.securiteam.com/windowsntfocus/5WP0L004US.html
http://www.cert.org/advisories/CA-2001-11.html
http://www.microsoft.com/technet/itsolutions/security/tools/redfix.asp



Networks Security ID: 2880

Vulnerability Assessment Copyright: This script is Copyright (C) 2001 SecuriTeam

Cables, Connectors


VINTAGE APPLE MACINTOSH POWERBOOK G3 UNTESTED NO POWER CORD picture

VINTAGE APPLE MACINTOSH POWERBOOK G3 UNTESTED NO POWER CORD

$57.40



APPLE MACINTOSH CLASSIC VINTAGE MAC Full Recap Restored Working picture

APPLE MACINTOSH CLASSIC VINTAGE MAC Full Recap Restored Working

$225.00



Vintage Apple Macintosh IIci Computer + Monitor (DEAD BATTERY, READ DESCRIPTION) picture

Vintage Apple Macintosh IIci Computer + Monitor (DEAD BATTERY, READ DESCRIPTION)

$125.00



Apple Mac Powerbook Duo 230 Vintage Laptop picture

Apple Mac Powerbook Duo 230 Vintage Laptop

$60.00



Vintage Apple Macintosh Plus 1MB Desktop Computer - M0001A No HDD EL4284 picture

Vintage Apple Macintosh Plus 1MB Desktop Computer - M0001A No HDD EL4284

$49.99



Vintage Apple Macintosh SE Model M5011 *Powers ON picture

Vintage Apple Macintosh SE Model M5011 *Powers ON

$89.99



Vintage APPLE MACINTOSH SE/30 EMPTY CASE w/DISK DRIVE Compact Plus Housing picture

Vintage APPLE MACINTOSH SE/30 EMPTY CASE w/DISK DRIVE Compact Plus Housing

$75.00



Vintage Apple Macintosh Plus 1Mb 60W 120VAC Desktop Computer SET M0001A Tested picture

Vintage Apple Macintosh Plus 1Mb 60W 120VAC Desktop Computer SET M0001A Tested

$399.99



Apple Macintosh LC Desktop Vintage Computer | Macintosh LC with 12

Apple Macintosh LC Desktop Vintage Computer | Macintosh LC with 12" RGB Display

$199.95



Working Vintage Apple Macintosh PowerBook 520 w/ AC Adapter Turns On Parts/ Rep picture

Working Vintage Apple Macintosh PowerBook 520 w/ AC Adapter Turns On Parts/ Rep

$129.99



Discussions

No Discussions have been posted on this vulnerability.