Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2005 (3.94) |
| Protection available since | 23 October 2004 11:26:23 (GMT) |
| Last updated | 13 May 2005 09:34:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-NW is a worm which attempts to spread to remote network shares and allows unauthorised remote access to the computer via IRC channels.
W32/Rbot-NW spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
W32/Rbot-NW copies itself to the file winortho.exe in the Windows system folder and creates entries at the following locations in the registry so that the worm is run when a user logs on to Windows:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Update Machine = winortho.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Update Machine = winortho.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Update Machine = winortho.exe
