RBot.cassl
Category: Trojan
Risk:
Severe Risk
* Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine.
Description: RBot is a memory resident Trojan worm that propagates through network shares and provides various backdoor capabilities to the attacker.
Alias: RBot.winservit
Signatures:
process: cassl.exe: MD5 Hash: 51ded33912383feb0bd
process: cassl.exe: MD5 Hash: 901eff156c1a5dea302
process: cassl.exe: MD5 Hash: fac213748a47fe63766
process: cassl.exe: MD5 Hash: cd757181d2abfca55c4..
Copyright @2006 THR Computer Solutions: RBot.cassl