W32/Rbot-ALI is a worm and IRC backdoor Trojan for the Windows platform. It spreads by copying itself to network shares protected by weak passwords.

W32/Rbot-ALI runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Rbot-ALI includes functionality to:


  • add/delete network shared folders
  • steal confidential information
  • carry out DDoS flooder attacks
  • provide a proxy server
  • access the internet and communicate with a remote server via HTTP
  • More information can be found at this Sophos page.