| Win32/Rbot.IMR |
|
| Added:Antiviruses123.com Update:2010-7-30 16:07:36 |
Win32/Rbot.IMR
Win32/Rbot.IMR
Date Published:
30 Jul 2010
Last Updated:
30 Jul 2010
Threat Assessment
Overall Risk:
Low
Wild:
Low
Destructiveness:
Low
Pervasiveness:
Low
Characteristics
Type
: Worm
Category
: Win32
Also known as:
SignatureProductRemoval 35.1.____ 35.2.____ CA Internet Security Suite 2007/2008/2009, ITM 8.x , eAV 7.x
Tools
Description
Description
Win32/Rbot is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants. Most instances of Rbot are compressed and/or encrypted with one or more run-time executable packers. Examples include Morphine, UPX, ASPack, PESpin, EZIP, PEShield, PECompact, FSG, EXEStealth, PEX, MoleBox and PEtite.
Read times:
|