Troj/Litebot-E

Category: Viruses and Spyware
Type: Trojan
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Litebot-E is an IRC backdoor Trojan for the Windows platform.

Troj/Litebot-E runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

Troj/Litebot-E contains functionality to download and run further malicious code.

When first run the Trojan copies itself to the Windows system folder and creates the following registry entry in order to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Connectivity Tool
<path to Trojan>

Troj/Litebot-E creates the following registry entry in order to allow it to bypass the Windows firewall:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\List
<path to Trojan>
<path to Trojan>:*:Enabled:Connectivity Tool

download Try Sophos products for free
Download now