Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 24 January 2005 21:31:26 (GMT) |
| Last updated | 27 May 2005 21:55:13 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Change any data that may have become compromised.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
and remove any reference to any file you deleted.
Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entry:
HKU\[code number]\Software\Microsoft\Windows\
CurrentVersion\Run\
and remove any reference to any file you deleted.
Close the registry editor.
Check the following items
- To renable DCOM you can edit the registry, but it's better to use Dcomcnfg.exe. See Microsoft article 825750 for details.
- The HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1" setting does not allow enumeration of SAM accounts and names. The default is "0". It can be changed in Local Security Policy. See Microsoft article 246261 for details.
- Check your administrator passwords and review network security.
More Information
W32/Rbot-UH is a worm with backdoor functionality.
W32/Rbot-UH is capable of spreading to computers on the local network protected by weak passwords after receiving the appropriate backdoor command.
W32/Rbot-UH will attempt to spread by exploiting the DCOM (MS04-012) and LSASS (MS04-011) software vulnerabilities and to computers running Microsoft SQL servers with weak passwords W32/Rbot-UH is a worm with backdoor functionality.
W32/Rbot-UH is capable of spreading to computers on the local network protected by weak passwords after receiving the appropriate backdoor command.
W32/Rbot-UH will attempt to spread by exploiting the following vulnerabilities:
DCOM (MS04-012)
LSASS (MS04-011)
Microsoft SQL servers with weak passwords.
When first run, W32/Rbot-UH copies itself to the Windows system folder as MCAFESHIELD.EXE and runs this copy of the worm. The copy will then attempt to delete the original file. In order to run each time a user logs in, W32/Rbot-UH will set the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Mcafee Auto Protect
mcafeshield.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Mcafee Auto Protect
mcafeshield.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Mcafee Auto Protect
mcafeshield.exe
The worm runs continuously in the background providing backdoor access to
the infected computer.
The backdoor component of W32/Rbot-UH can be used to:
Initiate Distributed Denial-of-Service (DDoS) attacks.
Redirect TCP and SOCKS4 traffic.
Provide a remote login command shell.
Download, upload, delete and execute files.
Set up an HTTP, TFTP and FTP file server.
Steal passwords (including PayPal account information).
Log key presses and clipboard data.
Capture screenshots, webcam pictures and videos.
List and kill processes.
Stop, start, pause and delete services.
Open and close vulnerabilities.
Port scan for vulnerabilities on other remote computers.
Send emails as specified by the remote user.
Flush the DNS and ARP caches.
Shut down and reboot the computer.
Add and delete network shares, groups and users.
Sniff network traffic for passwords.
Send Net Messages.
W32/Rbot-UH can be used to steal registration and key details from several computer games and applications including:
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlefield Vietnam
Black and White
Chrome
Command and Conquer: Generals
Command and Conquer: Generals (Zero Hour)
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Command and Conquer: Tiberian Sun
Counter-Strike
Far Cry
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Ground Control II
Gunman Chronicles
Half-Life
Hidden & Dangerous 2
IGI 2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Joint Operations: Typhoon Rising
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Microsoft Windows Product ID
Nascar Racing 2002
Nascar Racing 2003
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
Neverwinter Nights (Hordes of the Underdark)
Neverwinter Nights (Shadows of Undrentide)
NHL 2002
NHL 2003
NOX
Rainbow Six III RavenShield
Shogun: Total War: Warlord Edition
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
W32/Rbot-UH will alter the following registry entries in order to enable/disable DCOM and open/close restrictions on IPC$ shares:
HKLM\Software\Microsoft\Ole\EnableDCOM
HKLM\System\CurrentControlSet\Control\Lsa\restrictanonymous
W32/Rbot-UH is capable of altering the following registry entry to restrict anonymous enumeration of SAM accounts:
HKLM\System\CurrentControlSet\Control\Lsa\restrictanonymousSAM
W32/Rbot-UH can add and delete network shares and users on the infected computer. The worm can also change the network logon rights of accounts in the local system policy.
