Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 12 January 2005 21:52:42 (GMT) |
| Last updated | 11 February 2005 10:00:12 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Change any data that may have become compromised.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Center
scvhost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Security Center
scvhost.exe
and delete them if they exist.
Close the registry editor.
More Information
W32/Rbot-TG is a network worm with IRC backdoor functionality.
The worm copies itself to the file scvhost.exe in the Windows system folder and create the following registry entries in order to be run automatically on log-on:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Security Center
scvhost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Security Center
scvhost.exe
W32/Rbot-TG connects to a preconfigured IRC channel and awaits commands from a remote intruder. These include commands to:
start a TFTP, FTP or HTTP server offering the contents of local drives
scan other machines for exploitable vulnerabilities
secure the infected machine against known vulnerabilities
list or modify network shares
list or terminate processes
execute arbitrary commands
upload or download files
install an updated version of the worm
perform network floods on remote IP addresses
steal product keys of popular software
search for passwords in local settings and network traffic
record keypresses
show the contents of the clipboard
capture images from the screen or any available webcam devices
start a SOCKS4 proxy
redirect TCP connections
join another IRC server/channel
send emails
The worm attempts to spread by exploiting known vulnerabilities, using backdoors installed by other malware and using network services protected by weak passwords.
Vulnerabilities:
RPC/DCOM (MS03-026,MS03-039)
Lsass (MS04-011)
IIS5SSL (MS04-011)
WebDav (MS03-007)
Universal Plug-n-play (MS01-059)
DameWare Mini Remote Control (CAN-2003-1030)
Backdoors:
W32/MyDoom
W32/Bagel
Troj/Optix
Troj/Sub7
Troj/Kuang
Troj/NetDevil
Network shares/services:
IPC
NetBios
MS SQL
