TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_RBOT.CW
Overview

Malware type: Worm

Aliases: Backdoor.Win32.Rbot.bfs (Kaspersky), W32/Sdbot.worm.gen.z (McAfee), W32.IRCBot (Symantec), Worm/Rbot.86256 (Avira), W32/Rbot-FJB (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 95, 98, NT, ME, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm spreads via network shares, and takes advantage of the following Windows vulnerabilities to propagate across networks:

  • Remote Procedure Call (RPC) Distributed Component Object Model (DCOM) vulnerability
  • RPC Locator vulnerability
  • IIS5/WEBDAV buffer overrun vulnerability
  • LSASS vulnerability

For more information about these Windows vulnerabilities, please refer to the following Microsoft Web pages:

It attempts to log into systems using a list of passwords hardcoded in its body. It then drops a copy of itself in the accessed machines.

It also steals CD keys of certain game applications. It also has backdoor capabilities and may execute commands issued by a remote user.

This worm runs on Windows 95, 98, ME, NT, 2000 and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jul. 11, 2004 11:11:54 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.