Sophos

W32/Rbot-AWC

Aliases
  • Backdoor.Win32.Rbot.agf
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 7 November 2005 04:01:32 (GMT)
Last updated 22 December 2005 19:10:39 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/Rbot-AWC is a Network worm for the Windows platform.

When W32/Rbot-AWC is installed it moves itself to <System>\wupdate.exe and creates the file <System>\svkp.sys.

The file SVKP.sys is a non-malicious application.

W32/Rbot-AWC creates the following registry entries so as to auto-start:

HKCU\Software\Microsoft\OLE
Microsoft Generic Update Manager
wupdate.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Generic Update Manager
wupdate.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Generic Update Manager
wupdate.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer