









 |
W32/Rbot.Gss.Backdoor Trojan
| Name |
W32/Rbot.Gss.Backdoor Trojan |
| Aliases |
Worm/SdBot.807936, Win32:Rbot-FKC, Win32.Worm.SdBot.KWB, Backdoor.Rbot.hhw, Win32/Rbot.ILM, Agent.GJT!tr, W32/Spybot.QYE, Backdoor.Win32.Rbot.gss, Backdoor.Win32.Agent.aou, W32/Sdbot.worm.gen.ax, |
| Discovered on |
February 20, 2008 |
Virus Information - W32/Rbot.Gss.Backdoor Trojan:
W32/Rbot.Gss.Backdoor is a trojan. The trojan will infect Windows systems.
The trojan will arrive as a dropped file of another malware or may be downloaded from the Internet.
Upon execution, it drops as nod64.exe in the Windows System folder.
It modifies the registry at the following location to ensure its automatic execution at every system startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

|