| Visit Threat Expert web site | | | Close Report |
| What's been found | Severity Level |
| A network-aware worm that uses known exploit(s) in order to replicate across vulnerable networks. | ![]() |
| MS05-039: RPC Plug and Play Vulnerability - Remote Code Execution and Local Elevation of Privilege (common for Zotob, Mytob). | ![]() |
| MS04-012: DCOM RPC Overflow exploit - replication across TCP 135/139/445/593 (common for Blaster, Welchia, Spybot, Randex, other IRC Bots). | ![]() |
| MS04-011: LSASS Overflow exploit - replication across TCP 445 (common for Sasser, Bobax, Kibuv, Korgo, Gaobot, Spybot, Randex, other IRC Bots). | ![]() |
| Capability to perform DoS attacks against other computers. | ![]() |
| Backdoor functionality: connected remote users are able to perform multiple actions on the compromised system. | ![]() |
| Capability to join IRC channels and communicate with the remote computers (e.g. with the purpose of notification or remote administration). | ![]() |
| Capability to terminate Antivirus, Firewall and other security related processes. | ![]() |
| Replication across networks by exploiting weekly restricted shares (common for Randex family of worms). | ![]() |
| Creates a startup registry entry. | ![]() |
| Contains characteristics of a known security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
| Backdoor.Rbot | Backdoor.Rbot will open ports on an infected computer and connect to a remote server which will subsequently steal user information including but not limited to application and CD registration keys. |
![]() | File System Modifications |
| # | Filename(s) | Filename Size | Filename MD5 | Alias |
| 1 | %System%\lxlfsprrj.exe | 205,824 bytes | 0x020FEF328FDB7385875085F5F9317AF4 | Backdoor.Rbot [PCTools]Backdoor.Win32.Rbot.bdz [Kaspersky Lab]W32.Spybot.Worm [Symantec]WORM_Generic [Trend Micro] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| lxlfsprrj.exe | %System%\lxlfsprrj.exe | 671,744 bytes |
| [filename of the sample #1] | [file and pathname of the sample #1] | 671,744 bytes |
![]() | Registry Modifications |
![]() | Other details |
![]() | Heuristics Analysis |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("Threat Expert") and may not be copied without the express permission of Threat Expert.
The Information is provided on an "as is" basis. Threat Expert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, Threat Expert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2007 Threat Expert. All rights reserved.