Sophos

W32/RJump-G

Aliases
  • Worm.Win32.RJump.a
  • Win32/RJump.A
  • WORM_SIWEOL.A
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Protection available since 7 November 2006 09:12:32 (GMT)
Last updated 10 May 2007 05:55:31 (GMT)
Detected by All Sophos products

Action

More Information

W32/RJump-G is a worm for the Windows platform.

W32/RJump-G may attempt to copy itself to usb disk devices and create an "autorun.inf" file which will attempt to load the worm automatically when the infected drive is accessed. W32/RJump-G is a worm for the Windows platform.

W32/RJump-G may attempt to copy itself to usb disk devices and create an "autorun.inf" file which will attempt to load the worm automatically when the infected drive is accessed.

W32/RJump-G also creates a backdoor on a random port between 12000 and 19000, enabling a remote user control over the infected computer.

W32/RJump-G may copy itself to the following filename:

<Windows>\ravmone.exe

When installed, W32/RJump-G may create the following registry entry, enabling it to run automatically on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavAV
<Windows>\ravmone.exe

W32/RJump-G may also attempt to modify the Windows Firewall permissions to allow traffic to the backdoor.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer