W32/Rbot-GLO is a worm for the Windows platform which has functionality to allow unauthorized remote access to the computer via IRC channels.
When first run W32/Rbot-GLO copies itself to <System>\igfkishc.exe.
The following registry entries are created to run igfkishc.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Values
igfkishc.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Values
igfkishc.exe
The following registry entry is set:
HKCU\Software\Microsoft\OLE
Microsoft Values
igfkishc.exe