It exploits the following vulnerabilities... In many cases, it adds a value to one or more of the following registry keys: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices   This change causes the Trojan to run whenever Windows starts. Methods of Infection Viruses are self-replicating. Indication of Infection This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section. weblink

On windows XP: Insert the Windows XP CD into the CD-ROM drive and restart the computer.When the "Welcome to Setup" screen appears, press R to start the Recovery Console.Select the Windows

To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). Top Threat behavior Backdoor:Win32/Rbot.CU is a backdoor Trojan that connects to an IRC server to receive commands from remote attackers.

It may be dropped by other... Conducting denial of service (DoS) attacks.   Upon receiving IRC commands, the Trojan can spread to remote computers by exploiting one or more Windows vulnerabilities. Top Threat behavior Backdoor:Win32/Rbot is a family of backdoor Trojans that allows attackers to control infected computers.

Commands can instruct the Trojan to spread to other computers by scanning for network shares with weak passwords, exploiting Windows vulnerabilities, and spreading through backdoor ports opened by other families of malicious software.

Commands can include actions such as: Scanning for unpatched computers on the network.

Runs this copy of itself and deletes the original Trojan file Modifies the registry to load this copy of itself when Windows is started:Adds value: blah serviceWith data: win32exec.exeTo subkeys: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run No comments. Top Follow:I want to...Get helpRemove difficult malwareAvoid tech support phone scamsSee and search the latest threatsFind answers to other problemsFix my softwareFix updates and solve other problemsSee common error codesDownload and http://internetbusinessdaily.net/general/backdoor-rbot-gen.html Sending e-mail.

The function to detect(repair) 2876 type(s) of spywares has been added. After a computer is infected, the Trojan connects to a specific IRC server and joins a specific channel to receive commands from attackers. Engine version Details 4857049 2016.01.06.01 Updated-Viruses(1,684 types), Spywares(2,876 types), Malicious programs(1 types) 1.

Compressed file Inner file SHA256: b874630b1006532551ba7e4ceff08237eb63b3c80bf66a4b059de1c00026ab25 File name: 003434940 Detection ratio: 51 / 56 Analysis date: 2015-07-27 14:49:36 UTC ( 1 year, 6 months ago ) Analysis File detail Relationships Additional

The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file. Commands could include instructions to spread to other computers via open network shares or by exploit of a security vulnerability, or to launch a denial of service (DoS) attack against specified Runtime DLLs kernel32.dll (successful) ntdll.dll (successful)

More specifically, it is a Win32 EXE file for the Windows GUI subsystem. Downloading and executing remote files. The Trojan can also allow attackers to perform other backdoor functions, such as launching denial of service (DoS) attacks and retrieving system information from infected computers.

