Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | November 2004 (3.87) |
| Protection available since | 24 September 2004 07:56:34 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-KS copies itself to the Windows system folder as Bakw.exe and creates entries in the registry at the following locations to run itself on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Personal Firewalls
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Personal Firewalls
When triggered, W32/Rbot-KS tries to set the following registry entry to disable DCOM:
HKLM\Software\Microsoft\OLE\EnableDCOM = "N"
W32/Rbot-KS tries to set the following registry entry to restrict access to the IPC$ share on the infected computer:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"
Sophos anti-virus products since version 3.86 have been capable of detecting this worm as W32/Rbot-Fam without requiring an update
