Sophos

Sophos blogs

W32/Rbot-GXL

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 15 February 2009 04:17:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Rbot-GXL is a worm and IRC backdoor Trojan for the Windows platform.

When run W32/Rbot-GXL copies itself to <System>\vghhost.exe and creates the files:
<System>\packet.dll - this file can be safely removed
<System>\wpcap.dll - this file can be safely removed
<System>\drivers\npf.sys - this file can be safely removed

W32/Rbot-GXL spreads via networks shares encrypted with weak passwords as well as using the LSASS (MS04-011) vulnerability exploit.

W32/Rbot-GXL sets the following registry entries:

HKCU\Software\Microsoft\OLE
Visual Graphic
vghhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Visual Graphic
vghhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Visual Graphic
vghhost.exe

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer