Summary

Summary
Action
More Information
| Protection available since | 21 June 2004 14:48:51 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-BK is a worm which attempts to spread to remote network shares.
It also contains backdoor functionality, allowing unauthorised remote access
to the infected computer via IRC channels.
W32/Rbot-BK spreads to network shares as a result of the backdoor element
receiving the appropriate command from a remote user.
W32/Rbot-BK moves itself to the Windows system folder as LSRV.EXE and
creates the following entries in the registry so as to run itself on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Services= lsrv.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Services= lsrv.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Services= lsrv.exe
W32/Rbot-BK sets the following registry entries at regular intervals:
HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\ControlSet001\Control\Lsa\restrictanonymous = 1
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = 1
W32/Rbot-BK may delete C$, D$, E$, IPC$ and ADMIN$ network shares on the
host computer. The worm may also attempt to steal keys for various games.
