Sophos

W32/Rbot-AKV

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 18 August 2005 14:40:23 (GMT)
Last updated 6 October 2005 18:20:26 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-AKV is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-AKV spreads to other network computers by exploiting common buffer overflow vulnerabilites, including: PnP (MS05-039), RPC-DCOM (MS04-012).

W32/Rbot-AKV runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Rbot-AKV includes functionality to:

- carry out DDoS flooder attacks
- access the internet and communicate with a remote server via HTTP
- steal confidential information
- perform port scanning

When first run W32/Rbot-AKV moves itself to <System>\cmmon.pif.

The following registry entries are created to run the worm on startup:

HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Microsoft Connection Manager Monitor
cmmon.pif

HKCU\Software\Microsoft\OLE
Microsoft Connection Manager Monitor
cmmon.pif

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Connection Manager Monitor
cmmon.pif

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Connection Manager Monitor
cmmon.pif

HKLM\SOFTWARE\Microsoft\Ole
Microsoft Connection Manager Monitor
cmmon.pif

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Connection Manager Monitor
cmmon.pif

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Connection Manager Monitor
cmmon.pif

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Microsoft Connection Manager Monitor
cmmon.pif

The following patches for the operating system vulnerabilities exploited by W32/Rbot-AKV can be obtained from the Microsoft website:

MS05-039
MS04-012

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer