W32/Poebot-E

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Poebot-E is a worm which attempts to spread to remote network shares with weak passwords. It also contains backdoor Trojan functionality allowing unauthorised remote access to the infected computer via IRC channels.

W32/Poebot-E moves itself to radeonfx.exe in the %WINDOWS%\system32 folder and creates the following registry entry to ensure it is run at system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows DLL Loader
%WINDOWS%\system32\radeonfx.exe

W32/Poebot-E can also download and execute remote files on the infected computer, flood other computers with network packets, retrieve system information and execute arbitrary commands.

download Try Sophos products for free
Download now