Sophos

W32/Rbot-AVZ

Aliases
  • Backdoor.Win32.Rbot.agi
  • WORM_RBOT.CON
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 7 November 2005 04:01:32 (GMT)
Last updated 22 December 2005 19:10:39 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Rbot-AVZ is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-AVZ spreads:

- to other network computers infected with Troj/Kuang
- to other network computers by exploiting common buffer overflow vulnerabilities, including LSASS (MS04-011), RPC-DCOM (MS04-012) and PNP (MS05-039)
- by copying itself to network shares protected by weak passwords
and by copying itself to network shares protected by weak passwords.

W32/Rbot-AVZ runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When W32/Rbot-AVZ is installed it creates the file <System>\svkp.sys.

The file SVKP.sys is registered as a new system driver service named "SVKP", with a display name of "SVKP" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\SVKP\

This file may be deleted.

W32/Rbot-AVZ includes functionality to:

- carry out DDoS flooder attacks
- silently download, install and run new software
- access the internet and communicate with a remote server via HTTP

When first run W32/Rbot-AVZ copies itself to <System>\msnsmgs.exe.

The following registry entries are created to run msnsmgs.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
msn upddate
mesenger.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
msn upddate
mesenger.exe

Registry entries are set as follows:

HKCU\Software\Microsoft\OLE
msn upddate
mesenger.exe

The following patches for the operating system vulnerabilities exploited by W32/Rbot-AVZ can be obtained from the Microsoft website:

MS04-011
MS04-012
MS05-039

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer