Home Malware Programs Backdoors Backdoor.Win32.Rbot.acky

Backdoor.Win32.Rbot.acky

Posted: March 9, 2011

Backdoor.Win32.Rbot.acky is a backdoor Trojan and worm that can spread to new computers via network access and is a serious security breach for any PC infected by Backdoor.Win32.Rbot.acky. Because this Trojan-worm uses rootkit techniques, Backdoor.Win32.Rbot.acky may be very difficult to detect and delete; Backdoor.Win32.Rbot.acky removal should be left to security applications designed for the duty. Backdoor.Win32.Rbot.acky may block websites, show unwanted advertisements or modify files without permission to avoid deletion. Deleting Backdoor.Win32.Rbot.acky should be on top of anyone's list of things to do should they be unfortunate enough to find themselves attacked by this malware threat.

Keeping Backdoor.Win32.Rbot.acky out of Your PC

Computers in large networks are most vulnerable to Backdoor.Win32.Rbot.acky, since this malware will spread through network-shared files by copying itself and sending the copies to network-linked machines. This process doesn't require any action on the part of the users of the various computers, and strict network security settings are required to help shut Backdoor.Win32.Rbot.acky out.

Backdoor.Win32.Rbot.acky may also circumvent any outdated security programs trying to detect Backdoor.Win32.Rbot.acky, since it's a relatively recent threat (and not to be confused with the 2008 Rbot.acky worm). Having the latest updates for all your anti-malware scanners and using different types of scanners to back each other up will keep the possibility of Backdoor.Win32.Rbot.acky slipping in relatively low.

Some version of Backdoor.Win32.Rbot.acky can create ad-based pop-ups or download adware to do the same. This is actually somewhat beneficial, since it lets users detect the infection more easily and gives them warning to react with appropriate security measures. Not deleting Backdoor.Win32.Rbot.acky is a grave mistake, as can be seen from the information of Backdoor.Win32.Rbot.acky's attacks on PCs below.

Your Backdoor.Win32.Rbot.acky-Related System Damage Tally

Backdoor.Win32.Rbot.acky can be responsible for any or all of the following, in addition to mere advertisement pop-ups:

  • Blocked security websites and otherwise restricted browsing capabilities. Backdoor.Win32.Rbot.acky may prevent you from visiting websites based on anti-malware products or other PC safety measures. Backdoor.Win32.Rbot.acky can do this through the display of fake messages such as the popular fake 'unsafe website' error or redirect you away from the site with no excuses.
  • The unauthorized modification of other files or programs. Backdoor.Win32.Rbot.acky has been noted to alter system settings and tools to allow itself to more easily skirt underneath detection measures and avoid being removed.
  • Generally reduced security for the purpose of allowing anonymous third parties to attack the system remotely. Remote attacks aren't limited save by the resources and ingenuity of the hacker, and can control or destroy a PC utterly, or simply use it to assist in illegal actions. DDoS attacks are only one popular option and in many cases are less dangerous than the far more obtuse keylogging and other spy-based activities.

Removing Backdoor.Win32.Rbot.acky manually is an unrealistic goal in most cases, since Backdoor.Win32.Rbot.acky uses well-developed rootkit techniques to conceal and protect itself. Rely on known anti-malware solutions and assistance from professional and your system is likely to come out of the scuffle with Backdoor.Win32.Rbot.acky completely intact. Keep in mind that backdoor infections like Backdoor.Win32.Rbot.acky are often damaging far out of proportion to the visibility of their behavior before you delay on necessary malware-cleaning!

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %FontsDir%\uinstall_/exe
    2 %PROGRAM_FILES%\Backdoor.Win32.Rbot.acky
    3 c:\Documents and Settings\All Users\Start Menu\Backdoor.Win32.Rbot.acky\ c:\Documents and Settings\All Users\Backdoor.Win32.Rbot.acky\

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRTHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Windows File ProtectionHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdateHKEY_LOCAL_MACHINE\Software\Backdoor.Win32.Rbot.acky[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRT]DontReportInfectionInformation = 0x00000001HKEY..\..\..\..{RegistryKeys}DoNotAllowXPSP2 = 0x00000001HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Hosts Controller\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_HOSTS_CONTROLLERHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_HOSTS_CONTROLLER\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Hosts Controller\EnumSFCDisable = 0xFFFFFF9DSFCScan = 0x00000000WaitToKillServiceT = "5000"[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control]
Loading...