Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | September 2005 (3.97) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-AII is a network worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-AII runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Rbot-AII can spread to remote network shares protected by weak passwords.
When first run W32/Rbot-AII copies itself to <System>\MS-DOS.PIF.
The following registry entries are created to run explorer.pif on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MS-DOS Service
MS-DOS.pif
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
MS-DOS Service
MS-DOS.pif
