Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2004 (3.88) |
| Protection available since | 22 October 2004 07:52:32 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-NN is a worm which attempts to spread to remote network shares and allows unauthorised remote access to the computer via IRC channels.
W32/Rbot-NN spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
W32/Rbot-NN copies itself to the file USBhardware.exe in the Windows system folder and may create entries at the following locations in the registry so that the worm is run when a user logs on to Windows:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
USB Hardware Monitoring = USBhardware.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
USB Hardware Monitoring = USBhardware.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
USB Hardware Monitoring = USBhardware.exe
