Sophos

W32/Rbot-KW

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 26 September 2004 16:17:32 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-KW is a worm which attempts to spread to remote network shares.
W32/Rbot-KW also contains backdoor Trojan functionality, allowing unauthorised remote access to the infected computer via IRC channels while running in the background.

W32/Rbot-KW spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

W32/Rbot-KW copies itself to the Windows system folder as xpsp2.exe or with a random name and creates entries in the registry at the following locations to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\xp service pack 2
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\xp service pack 2

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer