Sophos

Troj/IRCBot-XD

Aliases
  • Backdoor.Win32.IRCBot.acd
  • BKDR_IRCBOT.AIH
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2007 (4.21)
Protection available since 6 August 2007 21:30:23 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IRCBot-XD is a Trojan for the Windows platform.

When first run Troj/IRCBot-XD copies itself to <System>\libcinet.exe and creates the file <System>\libwinets.dll. This file is also detected as Troj/IRCBot-XD. The Trojan also creates the file egos.txt, where information taken from the clipboard and from the keylogging component is stored. This file may be safely deleted.

The following registry entry is created to run code exported by a random CLSID linked to the file libwinets.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
printers
<random CLSID>

The file libwinets.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\<random CLSID>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer