Troj/SpyBot-AB is an IRC backdoor Trojan. The Trojan copies itself to the Windows system folder with the filename updt32v5.exe and sets the following registry entries with the path to the copy:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run\ Internet Explorer Auto-Update
HKCU\Software\Microsoft\Windows\CurrentVersion\
RunOnce\ Internet Explorer Auto-Update
Troj/SpyBot-AB then logs on to predefined IRC servers and waits for backdoor commands. The Trojan also terminates the applications regedit.exe, msconfig.exe, taskmgr.exe and netstat.exe.