Rohbot details

  • Description

    Rohbot is a worm that spreads through weakly protected network shares. Once executed, the parasite secretly installs itself to the system, runs a spreading routine and a payload. Rohbot opens a back door providing the attacker with unauthorized remote access to the compromised computer. It allows the intruder to terminate active processes, log user keystrokes, steal user sensitive information and shutdown the infected PC. Furthermore, some Rohbot variants include the functionality to run a hidden FTP server. The worm runs as a service on every Windows startup.