Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 3 August 2005 07:29:19 (GMT) |
| Last updated | 6 November 2005 04:15:04 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-AJO is a Windows network worm which attempts to spread via network shares. The worm contains backdoor functions that allows unauthorized remote access to the infected computer via IRC channels while running in the background.
The worm spreads to network shares with weak passwords and also by using the following security exploits:
LSASS (MS04-011)
RPC-DCOM (MS04-012)
WKS (MS03-049) (CAN-2003-0812)
MSSQL (MS02-039) (CAN-2002-0649)
The following patches for the operating system vulnerabilities exploited by W32/Rbot-AJO can be obtained from the Microsoft website:
MS04-011
MS04-012
MS03-049
MS02-039
W32/Rbot-AJO is a Windows network worm which attempts to spread via network shares. The worm contains backdoor functions that allows unauthorized remote access to the infected computer via IRC channels while running in the background.
The worm spreads to network shares with weak passwords and also by using the following security exploits:
LSASS (MS04-011)
RPC-DCOM (MS04-012)
WKS (MS03-049) (CAN-2003-0812)
MSSQL (MS02-039) (CAN-2002-0649)
W32/Rbot-AJO is a worm and IRC backdoor Trojan for the Windows platform.
When first run W32/Rbot-AJO copies itself to <System>\<random filename>.
The following registry entries are created to run W32/Rbot-AJO on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Symantec Autoscan
<random filename>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Symantec Autoscan
<random filename>
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Symantec Autoscan
<random filename>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Symantec Autoscan
<random filename>
Registry entries are set as follows:
HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Symantec Autoscan
<random filename>
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Symantec Autoscan
<random filename>
HKCU\Software\Microsoft\OLE
Symantec Autoscan
<random filename>
HKLM\SOFTWARE\Microsoft\Ole
Symantec Autoscan
<random filename>
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
Once installed, W32/Rbot-AJO will attempt to perform the following actions when instructed to do so by a remote attacker:
capture keystrokes
terminate threads and processes
perform port scanning on IP addresses
steal computer system hardware information
copy itself to network shared folders
download files from the Internet and run them
participate in denial of service (DoS) attacks
perform DCC file transfers over IRC channels
act as a HTTP proxy
setup a SOCKS4 server
The following patches for the operating system vulnerabilities exploited by W32/Rbot-AJO can be obtained from the Microsoft website:
