Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 2 May 2006 20:07:39 (GMT) |
| Last updated | 29 May 2006 22:16:27 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Tilebot-EQ is a netowrk worm and IRC based backdoor Trojan for the Windows platform.
The worm attempts to spread by copying itself to remote network shares or by exploiting any of the following vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), ASN.1 (MS04-007).
W32/Tilebot-EQ runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Tilebot-EQ includes functionality to access the internet and communicate with a remote server via HTTP.
When first run W32/Tilebot-EQ copies itself to <System>\smss.exe.
The file symsec.exe is registered as a new system driver service named "SMSS", with a display name of "Windows NT Session Manager" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\SMSS\
