Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 17 October 2005 05:18:33 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-ARY is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-ARY spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012) and WKS (MS03-049) (CAN-2003-0812) and by copying itself to network shares protected by weak passwords.
W32/Rbot-ARY runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
When first run W32/Rbot-ARY copies itself to <System>\mswinsdq.exe.
The following registry entries are created to run mswinsdq.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft SDKP3
mswinsdq.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft SDKP3
mswinsdq.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft SDKP3
mswinsdq.exe
Registry entries are set as follows:
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
W32/Rbot-ARY includes functionality to:
- access the internet and communicate with a remote server via HTTP
- steal information
- carry out DDoS attacks
- log keystrokes
- capture screenshots
- terminates anti-virus and security related processes
W32/Rbot-ARY terminates the following applications and security-related processes:
regedit.exe
msconfig.exe
netstat.exe
msblast.exe
zapro.exe
navw32.exe
navapw32.exe
zonealarm.exe
wincfg32.exe
taskmon.exe
PandaAVEngine.exe
sysinfo.exe
mscvb32.exe
MSBLAST.exe
teekids.exe
Penis32.exe
bbeagle.exe
SysMonXP.exe
winupd.exe
winsys.exe
ssate.exe
rate.exe
d3dupdate.exe
irun4.exe
i11r54n4.exe
The following patches for the operating system vulnerabilities exploited by W32/Rbot-ARY can be obtained from the Microsoft website:
Sophos's anti-virus products include Genotype™ detection technology, which can proactively protect against new threats without requiring an update. Sophos customers have been protected against W32/Rbot-ARY (detected as W32/Rbot-Fam) since version 3.98.
