Sophos

W32/Rbot-NW

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2005 (3.94)
Protection available since 23 October 2004 11:26:23 (GMT)
Last updated 13 May 2005 09:34:31 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-NW is a worm which attempts to spread to remote network shares and allows unauthorised remote access to the computer via IRC channels.

W32/Rbot-NW spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

W32/Rbot-NW copies itself to the file winortho.exe in the Windows system folder and creates entries at the following locations in the registry so that the worm is run when a user logs on to Windows:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Update Machine = winortho.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Update Machine = winortho.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Update Machine = winortho.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer