Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Download and install the Microsoft patch for the vulnerability exploited by this worm, which is available from http://www.microsoft.com/technet/security/bulletin/MS03-026.asp.
More Information
W32/Raleka-A is a network worm which uses the Microsoft DCOM RPC vulnerability to propagate across a network.
The worm attempts to download the files ntrootkit.exe and ntrootkit.reg from the internet and also a copy of itself with the filename svchost32.exe, however the files are no longer available for download.
W32/Raleka-A will attempt to download and install the Microsoft patch for the DCOM RPC vulnerability.
W32/Raleka-A includes backdoor functionality. The worm will attempt to contact IRC servers and await instructions from a remote attacker.
