Sophos

W32/Rbot-OA

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 26 October 2004 19:48:10 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Rbot-OA is a worm and backdoor for the Windows platform.
The backdoor component allows a remote attacker access to and control of the
infected computer.

The worm spreads by exploiting operating system vulnerabilities and shared
folders with weak passwords.

When run the worm copies itself to the Windows system folder as svchost32.exe
and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CRC Value Verifier = "svchost32.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
CRC Value Verifier = "svchost32.exe"
HKCU\Software\Microsoft\OLE
CRC Value Verifier = "svchost32.exe"

W32/Rbot-OA connects to a predefined IRC server and waits for instructions from
a remote attacker.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer