Troj/SpyBot-AB

Category: Viruses and Spyware Protection available since:19 Jan 2004 00:00:00 (GMT)
Type: Trojan Last Updated:19 Jan 2004 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/SpyBot-AB is an IRC backdoor Trojan. The Trojan copies itself to the Windows system folder with the filename updt32v5.exe and sets the following registry entries with the path to the copy:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run\ Internet Explorer Auto-Update

HKCU\Software\Microsoft\Windows\CurrentVersion\
RunOnce\ Internet Explorer Auto-Update

Troj/SpyBot-AB then logs on to predefined IRC servers and waits for backdoor commands. The Trojan also terminates the applications regedit.exe, msconfig.exe, taskmgr.exe and netstat.exe.

download Try Sophos products for free
Download now