Sophos

W32/Rbot-ARY

Aliases
  • Backdoor.Win32.Rbot.adf
  • W32/Sdbot.worm.gen.bs
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Protection available since 17 October 2005 05:18:33 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Rbot-ARY is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-ARY spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012) and WKS (MS03-049) (CAN-2003-0812) and by copying itself to network shares protected by weak passwords.

W32/Rbot-ARY runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When first run W32/Rbot-ARY copies itself to <System>\mswinsdq.exe.

The following registry entries are created to run mswinsdq.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft SDKP3
mswinsdq.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft SDKP3
mswinsdq.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft SDKP3
mswinsdq.exe

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

W32/Rbot-ARY includes functionality to:

- access the internet and communicate with a remote server via HTTP
- steal information
- carry out DDoS attacks
- log keystrokes
- capture screenshots
- terminates anti-virus and security related processes

W32/Rbot-ARY terminates the following applications and security-related processes:

regedit.exe
msconfig.exe
netstat.exe
msblast.exe
zapro.exe
navw32.exe
navapw32.exe
zonealarm.exe
wincfg32.exe
taskmon.exe
PandaAVEngine.exe
sysinfo.exe
mscvb32.exe
MSBLAST.exe
teekids.exe
Penis32.exe
bbeagle.exe
SysMonXP.exe
winupd.exe
winsys.exe
ssate.exe
rate.exe
d3dupdate.exe
irun4.exe
i11r54n4.exe

The following patches for the operating system vulnerabilities exploited by W32/Rbot-ARY can be obtained from the Microsoft website:

MS03-049
MS04-011
MS04-012

Sophos's anti-virus products include Genotype™ detection technology, which can proactively protect against new threats without requiring an update. Sophos customers have been protected against W32/Rbot-ARY (detected as W32/Rbot-Fam) since version 3.98.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer