TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_RBOT.AQT
Overview

Malware type: Worm

Aliases: Backdoor.Win32.Rbot.biz (Kaspersky), W32/Sdbot.worm.gen.y (McAfee), W32.Spybot.Worm (Symantec), Worm/Rbot.154112.24 (Avira), Mal/Packer (Sophos), Backdoor:Win32/Rbot (Microsoft)

In the wild: Yes

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via network shares


Description: 

This worm spreads through network shares. It searches for certain shares, where it drops a copy of itself. It uses a list of user names and passwords to gain access to password-protected shares.

It has backdoor capabilities. It opens a random port, which allows a remote user to perform malicious commands on the affected machine, thus compromising system security.

For additional information about this threat, see:
Solution
Technical Details

Description created: Mar. 9, 2005 6:51:58 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.