Sophos

W32/Tilebot-EQ

Aliases
  • WORM_MYTOB.QA
  • Backdoor.Win32.IRCBot.rh
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 2 May 2006 20:07:39 (GMT)
Last updated 29 May 2006 22:16:27 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Tilebot-EQ is a netowrk worm and IRC based backdoor Trojan for the Windows platform.

The worm attempts to spread by copying itself to remote network shares or by exploiting any of the following vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), ASN.1 (MS04-007).

W32/Tilebot-EQ runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Tilebot-EQ includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Tilebot-EQ copies itself to <System>\smss.exe.

The file symsec.exe is registered as a new system driver service named "SMSS", with a display name of "Windows NT Session Manager" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\SMSS\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer