W32/Rbot-GWX is a network worm with backdoor Trojan functionality for the Windows platform.
The worm copies itself to <System>\nvdsc.exe and creates the following registry entries:
HKCU\Software\Microsoft\OLE
NvidiaDisplayService
<System>\nvdsc.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NvidiaDisplayService
<System>\nvdsc.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
NvidiaDisplayService
<System>\nvdsc.exe
W32/Rbot-GWX spreads to other network computers by Software vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), IIS5SSL (ms04-011) (CAN-2003-0719) and by copying itself to network shares and MSSQL server protected by weak passwords.
W32/Rbot-GWX can be controlled by a remote attacker over specified IRC channels. The backdoor component of W32/Rbot-GWX can be instructed by a remote user to perform the following functions:
- start a FTP server
- start a Proxy server
- start a web server
- DDoS
- record clipboard data
- port scanning
- download/run arbitrary files
- start a remote shell
- steal information
- reduce system security
W32/Rbot-GWX creates "C:\del.bat" which is detected as Troj/Batten-A.