Sophos

W32/Rbot-FUL

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2007 (4.16)
Protection available since 1 November 2006 11:51:06 (GMT)
Last updated 12 February 2007 18:44:38 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-FUL is a worm for the Windows platform.

W32/Rbot-FUL runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels. W32/Rbot-FUL is a worm for the Windows platform.

W32/Rbot-FUL runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Rbot-FUL includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Rbot-FUL copies itself to <System>\<random 8 letters>.exe.

The following registry entries are created to run <random 8 letters>.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hdlpscom
<random 8 letters>.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
hdlpscom
<random 8 letters>.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer