Sophos

W32/Rbot-KQ

Aliases
  • Backdoor.Rbot.gen
  • W32/Sdbot.worm.gen.i
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 23 September 2004 09:40:14 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-KQ is a worm and backdoor for the Windows platform.

The worm spreads by exploiting shared folder and SQL servers with weak passwords, operating system vulnerabilities and backdoors opened by other worms. The operating system vulnerabilities exploited by W32/Rbot-KQ are addressed in Microsoft security bulletins MS04-012 and MS03-007.

The backdoor component of W32/Rbot-KQ connects to a predefined IRC server and waits for commands from a remote attacker.

When run W32/Rbot-KQ creates a copy of itself named systmesy.exe in the Windows system folder and adds the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Systmesy = "Systmesy.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Systmesy = "Systmesy.exe"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Systmesy = "Systmesy.exe"

The backdoor component allows a remote attacker to control the infected computer and includes functions such as:

HTTP server
proxy servers
keystroke logging
screen and video capture
network packet sniffing
password stealing
distributed denial of service attack

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer