Sophos

W32/Rbot-KT

Aliases
  • Backdoor.Rbot.gen
  • W32/Sdbot.worm.gen.j
  • virus
  • Win32/Rbot.CE
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 27 September 2004 11:39:00 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-KT is a member of the W32/Rbot family of worms with backdoor capabilities.

In order to run automatically when Windows starts up the worm copies itself to a randomly named file in the Windows system folder and adds the following registry entries pointing to this file:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Update V6

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Windows Update V6

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Update V6

When run the worm attempts to connect to a remote IRC server. This connection is used as a control channel that allows a malicious user access to the infected computer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer