Sophos

W32/Rbot-NH

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 21 October 2004 11:14:09 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-NH is a worm and backdoor for the Windows platform.

The worm spreads to network shares protected by weak passwords and to computers with unpatched operating system vulnerabilities or backdoors opened by other worms and Trojans.

The backdoor component connects to a predefined IRC server and waits for commands from a remote attacker.

W32/Rbot-NH copies itself to the Windows system folder as instantmsgrs.exe and adds the following registry entries to ensure that the copy is run each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Hyper Start = instantmsgrs.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Hyper Start = instantmsgrs.exe

The backdoor component allows an attacker to control the infected computer and offers functions such as:

Keystroke logging
Distributed denial of service attacks
Packet sniffing
Remote login
Video capture
File transfer
Proxy server

The vulnerabitilies exploited by W32/Rbot-NH are addressed by Microsoft security bulletins MS04-012 and MS03-007.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer