W32/Rbot-GR is a worm with backdoor Trojan functionality.
W32/Rbot-GR is capable of spreading to computers on the local network protected by weak passwords after receiving the appropriate backdoor command. The worm may also spread by exploiting a number of vulnerabilities.
W32/Rbot-GR may be used to steal passwords and product keys from a number of games and applications.
W32/Rbot-GR is a worm with backdoor Trojan functionality.
W32/Rbot-GR is capable of spreading to computers on the local network protected by weak passwords after receiving the appropriate backdoor command.
W32/Rbot-GR may also spread by exploiting the following vulnerabilities:
WebDav (MS03-007)
DCOM (MS03-039, MS04-012)
UPNP (MS01-059)
Microsoft SQL servers with weak passwords.
Buffer overflow in certain versions of DameWare (CAN-2003-1030)
Backdoors left open by other worms and Trojans such as W32/MyDoom, Troj/Optix,
Troj/Kuang and Troj/NetDevil.
When first run, W32/Rbot-GR copies itself to the Windows system folder as SYSTEMC32.EXE and runs this copy of the worm. The copy will then attempt to delete the original file. In order to run each time Windows is started, W32/Rbot-GR will set the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Updates = systemc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Updates = systemc32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Updates = systemc32.exe
The worm runs continuously in the background providing backdoor access to the infected computer.
The backdoor component of W32/Rbot-GR may be used to:
- Initiate distributed denial-of-service (DDOS) attacks using ICMP, SYN and UDP.
- Redirect TCP and SOCKS4 traffic.
- Provide a remote login shell.
- Download, upload, delete and execute files.
- Set up an HTTP and TFTP file server.
- Steal passwords (including PayPal account information).
- Log key presses.
- Capture screenshots.
- Capture webcam screenshots and videos.
- List and kill processes.
- Open and close vulnerabilities.
- Port scan for vulnerabilities on other remote machines.
- Send emails as specified by the remote user.
- Flush the DNS and ARP caches.
- Shut down the machine.
W32/Rbot-GR may be used to steal registration and key details from several computer games including:
Counter-Strike
The Gladiators
Gunman Chronicles
Half-Life
Industry Giant 2
Legends of Might and Magic
Soldiers Of Anarchy
Microsoft Windows Product ID
Unreal Tournament 2003
Unreal Tournament 2004
IGI 2: Covert Strike
Freedom Force
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlefield Vietnam
Black and White
Command and Conquer: Generals (Zero Hour)
James Bond 007: Nightfire
Command and Conquer: Generals
Global Operations
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Shogun: Total War: Warlord Edition
FIFA 2002
FIFA 2003
NHL 2002
NHL 2003
Nascar Racing 2002
Nascar Racing 2003
Rainbow Six III RavenShield
Command and Conquer: Tiberian Sun
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Chrome
NOX
Hidden & Dangerous 2
Soldier of Fortune II - Double Helix
Neverwinter Nights
Neverwinter Nights (Shadows of Undrentide)
Neverwinter Nights (Hordes of the Underdark)
W32/Rbot-GR may alter the following registry entries:
HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = 1
W32/Rbot-GR may create and delete network shares on the infected computer.