W32/IRCBot-YJ

Category: Viruses and Spyware Protection available since:09 Oct 2007 23:55:39 (GMT)
Type: Win32 worm Last Updated:09 Oct 2007 23:55:39 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/IRCBot-YJ is a backdoor irc worm which allows a remote intruder to gain access and control over the computer.

W32/IRCBot-YJ includes functionality to:
- communicate with a remote server via HTTP
- communicate and accept commands via IRC
- download, install and run new software

When first run W32/IRCBot-YJ copies itself to <System>\rckit.exe and creates the following files:

<Root>\gfccx.exe
<Root>\sp2.exe

The following registry entry is created to run rckit.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LTCISI
<System>\rckit.exe

download Try Sophos products for free
Download now