Sophos

W32/Rbot-AJO

Aliases
  • WORM_RBOT.BVE
  • Backdoor.Win32.Rbot.vi
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 3 August 2005 07:29:19 (GMT)
Last updated 6 November 2005 04:15:04 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-AJO is a Windows network worm which attempts to spread via network shares. The worm contains backdoor functions that allows unauthorized remote access to the infected computer via IRC channels while running in the background.

The worm spreads to network shares with weak passwords and also by using the following security exploits:

LSASS (MS04-011)
RPC-DCOM (MS04-012)
WKS (MS03-049) (CAN-2003-0812)
MSSQL (MS02-039) (CAN-2002-0649)

The following patches for the operating system vulnerabilities exploited by W32/Rbot-AJO can be obtained from the Microsoft website:

MS04-011
MS04-012
MS03-049
MS02-039 W32/Rbot-AJO is a Windows network worm which attempts to spread via network shares. The worm contains backdoor functions that allows unauthorized remote access to the infected computer via IRC channels while running in the background.

The worm spreads to network shares with weak passwords and also by using the following security exploits:

LSASS (MS04-011)
RPC-DCOM (MS04-012)
WKS (MS03-049) (CAN-2003-0812)
MSSQL (MS02-039) (CAN-2002-0649)

W32/Rbot-AJO is a worm and IRC backdoor Trojan for the Windows platform.

When first run W32/Rbot-AJO copies itself to <System>\<random filename>.

The following registry entries are created to run W32/Rbot-AJO on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Symantec Autoscan
<random filename>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Symantec Autoscan
<random filename>

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Symantec Autoscan
<random filename>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Symantec Autoscan
<random filename>

Registry entries are set as follows:

HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Symantec Autoscan
<random filename>

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Symantec Autoscan
<random filename>

HKCU\Software\Microsoft\OLE
Symantec Autoscan
<random filename>

HKLM\SOFTWARE\Microsoft\Ole
Symantec Autoscan
<random filename>

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

Once installed, W32/Rbot-AJO will attempt to perform the following actions when instructed to do so by a remote attacker:

capture keystrokes
terminate threads and processes
perform port scanning on IP addresses
steal computer system hardware information
copy itself to network shared folders
download files from the Internet and run them
participate in denial of service (DoS) attacks
perform DCC file transfers over IRC channels
act as a HTTP proxy
setup a SOCKS4 server

The following patches for the operating system vulnerabilities exploited by W32/Rbot-AJO can be obtained from the Microsoft website:

MS04-011
MS04-012
MS03-049
MS02-039

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer