Sophos

W32/Rbot-NT

Aliases
  • Backdoor.Win32.Rbot.gen
  • W32/Sdbot.worm.gen.j
  • WORM_RBOT.RY
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 26 October 2004 09:12:51 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-NT is a member of the Rbot family of worms which attempt to spread to remote network shares with the backdoor functionality for the Windows platforms.

W32/Rbot-NT spreads by coping itself to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user while running in the background and allowing unauthorised remote access to the infected computer via IRC channels.

When executed W32/Rbot-NT copies itself to the Windows system folder with the filename winvc32.exe and in order to be able to run when Windows starts up sets the following registry entries with the path to the copy:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Network Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
\Windows Network Service
HKCU\Software\Microsoft\OLE\Windows Network Service

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer