Sophos

W32/Raleka-A

Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Download and install the Microsoft patch for the vulnerability exploited by this worm, which is available from http://www.microsoft.com/technet/security/bulletin/MS03-026.asp.

More Information

W32/Raleka-A is a network worm which uses the Microsoft DCOM RPC vulnerability to propagate across a network.

The worm attempts to download the files ntrootkit.exe and ntrootkit.reg from the internet and also a copy of itself with the filename svchost32.exe, however the files are no longer available for download.

W32/Raleka-A will attempt to download and install the Microsoft patch for the DCOM RPC vulnerability.

W32/Raleka-A includes backdoor functionality. The worm will attempt to contact IRC servers and await instructions from a remote attacker.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer