Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2004 (3.88) |
| Protection available since | 21 October 2004 11:14:09 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-NH is a worm and backdoor for the Windows platform.
The worm spreads to network shares protected by weak passwords and to computers with unpatched operating system vulnerabilities or backdoors opened by other worms and Trojans.
The backdoor component connects to a predefined IRC server and waits for commands from a remote attacker.
W32/Rbot-NH copies itself to the Windows system folder as instantmsgrs.exe and adds the following registry entries to ensure that the copy is run each time Windows is started:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Hyper Start = instantmsgrs.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Hyper Start = instantmsgrs.exe
The backdoor component allows an attacker to control the infected computer and offers functions such as:
Keystroke logging
Distributed denial of service attacks
Packet sniffing
Remote login
Video capture
File transfer
Proxy server
The vulnerabitilies exploited by W32/Rbot-NH are addressed by Microsoft security bulletins MS04-012 and MS03-007.
