Sophos

W32/Rbot-VF

Aliases
  • Backdoor.Win32.SdBot.gen
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 2 February 2005 21:34:09 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/Rbot-VF is a network worm and IRC backdoor for the Windows platform.

W32/Rbot-VF spreads to network shares with weak passwords as a result of the backdoor element receiving the appropriate command from a remote user.

Once executed W32/Rbot-VF copies itself to the Windows system folder with the filename scsrs.exe, and in order to be able to run automatically when Windows starts up sets the regsitry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
scsrs
scsrs.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
scsrs
scsrs.exe

Also W32/Rbot-VF sets the registry entry:

HKCU\Software\Microsoft\OLE\
scsrs
scsrs.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer