Troj/SpyBot-AA is an IRC backdoor Trojan which allows unauthorised remote access to the computer via IRC channels.
The Trojan copies itself to the Windows system folder as UPDT32V2.EXE and adds the following registry entries to run itself on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Configuration Update
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\Configuration Update
Troj/SpyBot-AA then logs on to a predefined IRC server and waits for backdoor commands. The Trojan also terminates the following processes:
REGEDIT.EXE
MSCONFIG.EXE
TASKMGR.EXE
NETSTAT.EXE