Sophos

W32/Rbot-NN

Aliases
  • Backdoor.Win32.Rbot.gen
  • W32/Sdbot.worm.gen.j
  • virus
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 22 October 2004 07:52:32 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-NN is a worm which attempts to spread to remote network shares and allows unauthorised remote access to the computer via IRC channels.

W32/Rbot-NN spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

W32/Rbot-NN copies itself to the file USBhardware.exe in the Windows system folder and may create entries at the following locations in the registry so that the worm is run when a user logs on to Windows:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
USB Hardware Monitoring = USBhardware.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
USB Hardware Monitoring = USBhardware.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
USB Hardware Monitoring = USBhardware.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer