|W32/Rbot-DL is a network worm and backdoor Trojan for the Windows platform.
Allows a malicious user remote access to an infected computer.
W32/Rbot-DL spreads using a variety of techniques including exploiting weak passwords on computers and SQL servers, exploiting operating system vulnerabilities (including DCOM-RPC, LSASS, WebDAV and UPNP) and using backdoors opened by other worms or Trojans.
W32/Rbot-DL can be controlled by a remote attacker over IRC channels.
Go to the HKEY_LOCAL_MACHINE entries:
and delete the value:
Microsoft Update = winsyst.exe