W32/Rbot-CGC

Category: Viruses and Spyware Protection available since:20 Feb 2006 00:00:00 (GMT)
Type: Win32 executable file virus Last Updated:20 Feb 2006 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Rbot-CGC is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-CGC spreads to other network computers infected with: Troj/Kuang,
Troj/Sub7, Troj/NetDevil, W32/MyDoom, W32/Bagle and Troj/Optix and to other
network computers by exploiting common buffer overflow vulnerabilities,
including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049)
(CAN-2003-0812), WebDav (MS03-007), IIS5SSL (ms04-011) (CAN-2003-0719), UPNP
(MS01-059), Veritas (CAN-2004-1172), Dameware (CAN-2003-1030) and ASN.1
(MS04-007).

W32/Rbot-CGC runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

When first run W32/Rbot-CGC copies itself to <System>\msupdate33e.exe.

The following registry entries are created to run secsvc.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Intec Services Drivers
msupdate22e.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Intec Services Drivers
msupdate22e.exe

Registry entries are set as follows:

HKCU\Software\Microsoft\OLE
Intec Services Drivers
msupdate22e.exe

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

The following patches for the operating system vulnerabilities exploited by
W32/Rbot-CGC can be obtained from the Microsoft website:

<a href=
"http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"
target="_blank">MS04-011</a>
<a href=
"http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx"
target="_blank">MS04-012</a>
<a href=
"http://www.microsoft.com/technet/security/bulletin/MS03-049.mspx"
target="_blank">MS03-049</a>
<a href=
"http://www.microsoft.com/technet/security/bulletin/MS03-007.mspx"
target="_blank">MS03-007</a>
<a href=
"http://www.microsoft.com/technet/security/bulletin/MS04-007.mspx"
target="_blank">MS04-007</a>
<a href=
"http://www.microsoft.com/technet/security/bulletin/MS01-059.mspx"
target="_blank">MS01-059</a>

download Try Sophos products for free
Download now