Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2007 (4.18) |
| Protection available since | 7 November 2006 09:12:32 (GMT) |
| Last updated | 10 May 2007 05:55:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/RJump-G is a worm for the Windows platform.
W32/RJump-G may attempt to copy itself to usb disk devices and create an "autorun.inf" file which will attempt to load the worm automatically when the infected drive is accessed. W32/RJump-G is a worm for the Windows platform.
W32/RJump-G may attempt to copy itself to usb disk devices and create an "autorun.inf" file which will attempt to load the worm automatically when the infected drive is accessed.
W32/RJump-G also creates a backdoor on a random port between 12000 and 19000, enabling a remote user control over the infected computer.
W32/RJump-G may copy itself to the following filename:
<Windows>\ravmone.exe
When installed, W32/RJump-G may create the following registry entry, enabling it to run automatically on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavAV
<Windows>\ravmone.exe
W32/RJump-G may also attempt to modify the Windows Firewall permissions to allow traffic to the backdoor.
