Sophos

W32/Rbot-OZ

Aliases
  • Backdoor.Win32.Rbot.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 4 November 2004 21:51:35 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-OZ is a network worm and IRC backdoor Trojan.

W32/Rbot-OZ is capable of spreading to computers on the local network protected by weak passwords after receiving the appropriate backdoor command.

The backdoor component connects to a predefined IRC server and waits for commands from a remote attacker.

W32/Rbot-OZ may also spread by exploiting the following vulnerabilities:

LSASS (MS04-011)
DCOM (MS04-012)

When first run, W32/Rbot-OZ copies itself to the Windows system folder as svchost32.exe. In order to run each time Windows is started, W32/Rbot-OZ creates the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows Help Manager = "svchost32.exe"
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Windows Help Manager = "svchost32.exe"
HKCU\Software\Microsoft\OLE\
Windows Help Manager = "svchost32.exe"

The worm runs continuously in the background providing backdoor access to the infected computer.

The backdoor component of W32/Rbot-OZ can be used to:

Initiate distributed denial-of-service (DDoS) attacks.
Redirect TCP and SOCKS4 traffic.
Provide a remote login shell.
Download, upload, delete and execute files.
Set up an HTTP, TFTP and FTP file server.
Steal passwords (including PayPal account information).
Log key presses.
Capture screenshots.
Capture webcam pictures and videos.
List and kill processes.
Stop, start and pause services.
Open and close vulnerabilities.
Port scan for vulnerabilities on other remote computers.
Send emails as specified by the remote user.
Flush the DNS and ARP caches.
Shut down and reboot the computer.
Add and delete network shares and users.
Sniff network traffic for passwords.

W32/Rbot-OZ may be used to steal registration and key details from several computer games and applications.

W32/Rbot-OZ may add and delete network shares and users on the infected computer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer