Troj/SpyBot-AA

Category: Viruses and Spyware Protection available since:23 Dec 2003 00:00:00 (GMT)
Type: Trojan Last Updated:23 Dec 2003 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/SpyBot-AA is an IRC backdoor Trojan which allows unauthorised remote access to the computer via IRC channels.

The Trojan copies itself to the Windows system folder as UPDT32V2.EXE and adds the following registry entries to run itself on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Configuration Update

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\Configuration Update

Troj/SpyBot-AA then logs on to a predefined IRC server and waits for backdoor commands. The Trojan also terminates the following processes:

REGEDIT.EXE
MSCONFIG.EXE
TASKMGR.EXE
NETSTAT.EXE

download Try Sophos products for free
Download now