W32/Rbot-ALI is a worm and IRC backdoor Trojan for the Windows platform. It spreads by copying itself to network shares protected by weak passwords.
W32/Rbot-ALI runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Rbot-ALI includes functionality to:
add/delete network shared folders
steal confidential information
carry out DDoS flooder attacks
provide a proxy server
access the internet and communicate with a remote server via HTTP
More information can be found at this Sophos page.
Loading Comments...