W32/Rbot-GWX

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Rbot-GWX is a network worm with backdoor Trojan functionality for the Windows platform.

The worm copies itself to <System>\nvdsc.exe and creates the following registry entries:

HKCU\Software\Microsoft\OLE
NvidiaDisplayService
<System>\nvdsc.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NvidiaDisplayService
<System>\nvdsc.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
NvidiaDisplayService
<System>\nvdsc.exe

W32/Rbot-GWX spreads to other network computers by Software vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), IIS5SSL (ms04-011) (CAN-2003-0719) and by copying itself to network shares and MSSQL server protected by weak passwords.

W32/Rbot-GWX can be controlled by a remote attacker over specified IRC channels. The backdoor component of W32/Rbot-GWX can be instructed by a remote user to perform the following functions:
- start a FTP server
- start a Proxy server
- start a web server
- DDoS
- record clipboard data
- port scanning
- download/run arbitrary files
- start a remote shell
- steal information
- reduce system security

W32/Rbot-GWX creates "C:\del.bat" which is detected as Troj/Batten-A.

download Try Sophos products for free
Download now