Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 15 March 2005 21:13:08 (GMT) |
| Last updated | 23 March 2005 09:55:39 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions for removing W32/Rbot-YA.
More Information
Sophos's anti-virus products include proactive detection technology, which can proactively protect against new threats without requiring an update.
W32/Rbot-YA is a worm which attempts to spread to remote network shares. It also contains backdoor functionality, allowing unauthorised remote access to the infected computer while running in the background as a service process.
W32/Rbot-YA spreads to network shares with weak passwords as a result of the Trojan element receiving the appropriate command from a remote user.
W32/Rbot-YA moves itself to the Windows system folder as wmpa36d.exe and creates entries in the registry at the following locations to run on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows Media Player 3.6d
wmpa36d.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Windows Media Player 3.6
wmpa36d.exe
HKCU\Software\Microsoft\OLE\
Windows Media Player 3.6d
wmpa36d.exe
