Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | November 2004 (3.87) |
| Protection available since | 23 September 2004 09:40:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-KQ is a worm and backdoor for the Windows platform.
The worm spreads by exploiting shared folder and SQL servers with weak passwords, operating system vulnerabilities and backdoors opened by other worms. The operating system vulnerabilities exploited by W32/Rbot-KQ are addressed in Microsoft security bulletins MS04-012 and MS03-007.
The backdoor component of W32/Rbot-KQ connects to a predefined IRC server and waits for commands from a remote attacker.
When run W32/Rbot-KQ creates a copy of itself named systmesy.exe in the Windows system folder and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Systmesy = "Systmesy.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Systmesy = "Systmesy.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Systmesy = "Systmesy.exe"
The backdoor component allows a remote attacker to control the infected computer and includes functions such as:
HTTP server
proxy servers
keystroke logging
screen and video capture
network packet sniffing
password stealing
distributed denial of service attack
