Sophos

W32/Rbot-BK

Aliases
  • Backdoor.Rbot.gen
  • W32/Sdbot.worm.gen.i
  • W32.Spybot.Worm
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 21 June 2004 14:48:51 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Rbot-BK is a worm which attempts to spread to remote network shares.
It also contains backdoor functionality, allowing unauthorised remote access
to the infected computer via IRC channels.

W32/Rbot-BK spreads to network shares as a result of the backdoor element
receiving the appropriate command from a remote user.

W32/Rbot-BK moves itself to the Windows system folder as LSRV.EXE and
creates the following entries in the registry so as to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Services= lsrv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Services= lsrv.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Services= lsrv.exe

W32/Rbot-BK sets the following registry entries at regular intervals:

HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\ControlSet001\Control\Lsa\restrictanonymous = 1
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = 1

W32/Rbot-BK may delete C$, D$, E$, IPC$ and ADMIN$ network shares on the
host computer. The worm may also attempt to steal keys for various games.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer