Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 7 December 2004 09:10:06 (GMT) |
| Last updated | 19 May 2005 12:25:58 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows DLL Loader
%SYSTEM%\defragfat32abc.exe
and delete it if it exists.
Close the registry editor.
More Information
W32/Rbot-RG is a network worm which attempts to spread via network shares. The worm contains backdoor functions that allow unauthorised remote access to the infected computer via IRC channels while running in the background.
The worm spreads to network shares with weak passwords and also by using the LSASS security exploit (MS04-011) and the RPC-DCOM security exploit (MS03-039).
When run W32/Rbot-RG moves itself to the Windows System folder as a hidden file named defragfat32abc.exe.
The worm then creates the following registry entry so as to run itself on computer logon:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows DLL Loader
%SYSTEM%\defragfat32abc.exe
Once installed, W32/Rbot-RG will attempt to setup a HTTPD server and download and run files from the internet when instructed to do so by a remote attacker.
W32/Rbot-RG may try to exploit backdoors and vulnerabilites used by the MyDoom family of worms.
