|
|
RBot.iexplorerrs Worm Information
| Name: |
RBot.iexplorerrs |
| Category: |
Worm |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
Rbot is the name of a family of remote access tools, also known as backdoors or worms, used by hackers to control a machine without the owner's knowledge.
RBot.iexplorerrs is a network worm with IRC backdoor functionality. RBot.iexplorerrs may spread to remote network shares protected by weak passwords and computers vulnerable to common exploits. The worm also opens up a backdoor, allowing unauthorised remote access to infected computers via the IRC network, while running in the background as a service process.
RBot.iexplorerrs can receive commands from a remote intruder to:
delete network shares
log keypresses
participate in DDoS attacks
scan other computers for vulnerabilities
steal passwords
steal registration keys for computer games
create administrator accounts
terminate firewall and anti-virus processes
capture video from webcameras attached to the computer
|
| Signatures:
|
process: iexplorerrs.exe: MD5 Hash: 32a1f38e7141de50823...
process: iexporer.exe: MD5 Hash: 9b06221fa08edf86ce2...
process: iexplore.exe: MD5 Hash: 145c2ec31590fae6a6f...
process: iexplore.exe: MD5 Hash: 6dab17df10b2f761bee.. |
| Type: |
Worm - A worm is program that propagates by attacking other computers and copying itself to them. Worms may replace files, but do not insert themselves into files (as viruses do). |
Top Worm Visited Pages:
Wukill.mstray - Alias: Win32/HLLW.Wukill - 288 visits
Rbot - Alias: Backdoor.Rbot.Gen - 275 visits
SDBot - Alias: Wootbot.gen, Wootbot, Donk, spybot, Agobot - 228 visits
Trojan.Downloader.winstall - 181 visits
Worm.Brit.e - Alias: VBS/Chick.e@M virus - 89 visits
Worm.P2P.SpyBot.gen - 56 visits
Gaobot - 43 visits
Win32/Darby.O - 42 visits
Worm.Trilissa.e - 42 visits
JS.Lame - Alias: HTML.Lame - 40 visits
Random Worm Pages:
Worm.Fix2001 - Alias: W32/Backdoor.Fix2001, W32/Fix
IRC.Worm.Readme.1077
Virus.Spybot Worm
Worm.P2P.Herpes
Magic Eye Worm
ShitC Worm
Win95.Matit.b - Alias: W95/Matit.worm
Worm.Fog.c
Rbot.MShelp
Worm.Merlin
|
|