Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2004 (3.88) |
| Protection available since | 26 October 2004 09:12:51 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-NT is a member of the Rbot family of worms which attempt to spread to remote network shares with the backdoor functionality for the Windows platforms.
W32/Rbot-NT spreads by coping itself to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user while running in the background and allowing unauthorised remote access to the infected computer via IRC channels.
When executed W32/Rbot-NT copies itself to the Windows system folder with the filename winvc32.exe and in order to be able to run when Windows starts up sets the following registry entries with the path to the copy:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Network Service
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
\Windows Network Service
HKCU\Software\Microsoft\OLE\Windows Network Service
