Troj/Rybot-A is a backdoor Trojan that allows an attacker remote access to the computer via the IRC network.
In order to run automatically when Windows starts up the Trojan copies itself to a user configurable filename and adds a registry run entry below
HKLM\Software\Microsoft\Windows\CurrentVersion\Run.
The Trojan also drops the files rplib.dll and rtm.dat in the Windows system folder.
Troj/Rybot-A has the ability to log keystrokes and to send the logged data to a configurable FTP server.