Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | October 2004 (3.86) |
| Protection available since | 9 September 2004 11:04:27 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-IX is a worm and backdoor for the Windows platform.
W32/Rbot-IX spreads to network shares and Microsoft SQL servers with weak passwords as well as by exploiting operating system vulnerabilities and backdoors opened by other worms. The operating system vulnerabilities exploited by this worm are addresses by Microsoft Security Bulletins MS04-012, MS04-011, MS03-007 and MS01-059.
W32/Rbot-IX creates a copy of itself in the Windows system folder as msi332.exe and adds the following registry entries to ensure that the copy is run each time Windows is started:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
WindowsRegKey%$ update = "msi332.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
WindowsRegKey%$ update = "msi332.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
WindowsRegKey%$ update = "msi332.exe"
The backdoor component of W32/Rbot-IX contacts an IRC server and waits for commands from a remote attacker.
The functions available throught the backdoor include:
Distributed denial of service attack
Proxy servers
Packet sniffing
Keystroke logging
Remote shell
Video capture
File upload and download.
