W32/Rbot-FWV is a worm with IRC backdoor functionality for the Windows platform.
W32/Rbot-FWV spreads to other network computers by exploiting common buffer overflow vulnerabilities, including WKS (MS03-049) (CAN-2003-0812), and by copying itself to network shares protected by weak passwords.
W32/Rbot-FWV modifies the system HOSTS file, preventing access to certain anti-virus websites.
W32/Rbot-FWV runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
When first run W32/Rbot-FWV copies itself to <System>\cflmon.exe.
The following registry entries are created to run cflmon.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Micrcsoft Certificate Services
cflmon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Micrcsoft Certificate Services
cflmon.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Micrcsoft Certificate Services
cflmon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Micrcsoft Certificate Services
cflmon.exe
Registry entries are set as follows:
HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Micrcsoft Certificate Services
cflmon.exe
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Micrcsoft Certificate Services
cflmon.exe
HKCU\Software\Microsoft\OLE
Micrcsoft Certificate Services
cflmon.exe
HKLM\SOFTWARE\Microsoft\Ole
Micrcsoft Certificate Services
cflmon.exe