Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 26 October 2004 19:48:10 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-OA is a worm and backdoor for the Windows platform.
The backdoor component allows a remote attacker access to and control of the
infected computer.
The worm spreads by exploiting operating system vulnerabilities and shared
folders with weak passwords.
When run the worm copies itself to the Windows system folder as svchost32.exe
and adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CRC Value Verifier = "svchost32.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
CRC Value Verifier = "svchost32.exe"
HKCU\Software\Microsoft\OLE
CRC Value Verifier = "svchost32.exe"
W32/Rbot-OA connects to a predefined IRC server and waits for instructions from
a remote attacker.
