Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | June 2007 (4.18) |
| Protection available since | 20 October 2006 00:02:22 (GMT) |
| Last updated | 4 May 2007 03:07:03 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/RJump-F is a worm for the Windows platform.
W32/RJump-F spreads by coping itself to the available mapped drives and creating create an "autorun.inf" file which will attempt to load the worm automatically when the infected drive is accessed.
W32/RJump-F also creates a backdoor, enabling a remote user control over the infected computer.
W32/RJump-F may copy itself to the following filename:
<Windows>\RavMonE.exe
When installed, W32/RJump-F may create the following registry entry, enabling it to run automatically on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavAV
<Windows>\RavMonE.exe
