Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | October 2004 (3.86) |
| Protection available since | 3 September 2004 13:18:24 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please read the instructions for removing W32/Rbot-IC.
More Information
W32/Rbot-IC is a worm which attempts to spread to remote network shares and allows unauthorised remote access to the computer via IRC channels.
W32/Rbot-IC spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
W32/Rbot-IC moves itself to the Windows system folder as a randomly-named (composed of six letters) file and creates entries at the following locations in the registry so that the worm is run when a user logs on to Windows:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BIOS XP Loader = <path to file>
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
BIOS XP Loader = <path to file>
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
BIOS XP Loader = <path to file>
