Sophos

W32/Rbot-IC

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2004 (3.86)
Protection available since 3 September 2004 13:18:24 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-IC is a worm which attempts to spread to remote network shares and allows unauthorised remote access to the computer via IRC channels.

W32/Rbot-IC spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

W32/Rbot-IC moves itself to the Windows system folder as a randomly-named (composed of six letters) file and creates entries at the following locations in the registry so that the worm is run when a user logs on to Windows:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BIOS XP Loader = <path to file>

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
BIOS XP Loader = <path to file>

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
BIOS XP Loader = <path to file>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer