Sophos

W32/Rbot-KS

Aliases
  • WORM_SPYBOT.ET
  • Backdoor.Rbot.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 24 September 2004 07:56:34 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-KS copies itself to the Windows system folder as Bakw.exe and creates entries in the registry at the following locations to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Personal Firewalls

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Personal Firewalls

When triggered, W32/Rbot-KS tries to set the following registry entry to disable DCOM:

HKLM\Software\Microsoft\OLE\EnableDCOM = "N"

W32/Rbot-KS tries to set the following registry entry to restrict access to the IPC$ share on the infected computer:

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"

Sophos anti-virus products since version 3.86 have been capable of detecting this worm as W32/Rbot-Fam without requiring an update

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer