Sophos

Troj/IRCBot-AAK

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 19 February 2008 21:30:18 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IRCBot-AAK is a Trojan for the Windows platform which allows unauthorized remote access to the computer over a network.

The Trojan copies itself <System>\mdm.exe and creates the following registry entries to run itself on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Update
<System>\mdm.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Update
<System>\mdm.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer