Troj/IRCBot-G

Category: Viruses and Spyware Protection available since:04 Aug 2003 00:00:00 (GMT)
Type: Trojan Last Updated:04 Aug 2003 00:00:00 (GMT)
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/IRCBot-G is an IRC backdoor Trojan which runs in the background as a service process and allows unauthorised remote access to the computer via IRC channels.

The Trojan copies itself to the root folder on drive C: as LOLX.EXE and to the Windows system folder as DCOMX.EXE and attempts to ensure that it is run when Windows starts by adding registry entries to:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

Troj/IRCBot-G may send a confirmation email message to an external address.

download Try Sophos products for free
Download now