Sophos

W32/Rbot-KU

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 27 September 2004 08:38:54 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-KU is an IRC backdoor worm.

W32/Rbot-KU may spread to remote network shares. The worm also contains backdoor functionality, allowing unauthorised remote access to the infected computer via IRC channels while running in the background as a service process.

W32/Rbot-KU copies itself to the Windows system folder and creates the following registry entries so as to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Locals 332

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Locals 332

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Locals 332

W32/Rbot-KU may delete network shares.

W32/Rbot-KU may also attempt to log keypresses, capture webcam images, scan other computers for exploitable vulnerabilities, participate in DDOS attacks and steal registration details for various games.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer