Sophos

W32/Rbot-JE

Aliases
  • Backdoor.Rbot.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 9 September 2004 21:29:50 (GMT)
Last updated 16 September 2004 09:34:48 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-JE is a worm and backdoor for the Windows platform.
W32/Rbot-JE spreads to network shares and Microsoft SQL servers with weak passwords as well as by exploiting operating system vulnerabilities and backdoors opened by other worms.

The operating system vulnerabilities exploited by this worm are addressed by
Microsoft security bulletins MS04-012, MS04-011, MS03-007 and MS01-059.

W32/Rbot-JE creates a copy of itself in the Windows system folder as systemupdate.exe and adds the following registry entries to ensure that the copy is run each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Update Service 2004/2005 = "systemupdate.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Windows Update Service 2004/2005 = "systemupdate.exe"
HKCU\Software\Microsoft\OLE
Windows Update Service 2004/2005 = "systemupdate.exe"

The backdoor component of W32/Rbot-JE contacts an IRC server and waits for commands from a remote attacker.

The functions available through the backdoor include:

Distributed denial of service attack
Proxy servers
Packet sniffing
Keystroke logging
Remote shell
Video capture
File upload and download

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer