Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | November 2004 (3.87) |
| Protection available since | 27 September 2004 08:38:54 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-KU is an IRC backdoor worm.
W32/Rbot-KU may spread to remote network shares. The worm also contains backdoor functionality, allowing unauthorised remote access to the infected computer via IRC channels while running in the background as a service process.
W32/Rbot-KU copies itself to the Windows system folder and creates the following registry entries so as to run itself on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Locals 332
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Locals 332
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Locals 332
W32/Rbot-KU may delete network shares.
W32/Rbot-KU may also attempt to log keypresses, capture webcam images, scan other computers for exploitable vulnerabilities, participate in DDOS attacks and steal registration details for various games.
