Sophos

Troj/IRCBot-AO

Aliases
  • Backdoor.Win32.IRCBot.v
  • BKDR_BREPLIBOT.G
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 27 November 2005 16:19:08 (GMT)
Last updated 27 November 2005 21:42:04 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/IRCBot-AO is an IRC backdoor Trojan for the Windows platform.

Troj/IRCBot-AO has functionality to connect to IRC channels and to download and execute EXE files from remote URLs.

Samples of Troj/IRCBot-AO appear to have been massmailed out. Troj/IRCBot-AO is an IRC backdoor Trojan for the Windows platform.

Troj/IRCBot-AO has functionality to connect to IRC channels via port 8080 and to download and execute EXE files from remote URLs.

Samples of Troj/IRCBot-AO appear to have been massmailed out.

Troj/IRCBot-AO moves itself to <System>\smschk.exe.

The following registry entries are created to run smschk.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EventApplicationCmd
smschk.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
EventApplicationCmd
smschk.exe

Troj/IRCBot-AO attempts to terminate the following security-related processes:

Ad-watch.exe
ccApp.exe
ccEvtMgr.exe
gcasDTServ.exe
gcasServ.exe
kpf4gui.exe
kpf4ss.exe
mcshield.exe
mcupdate.exe
mcvsrte.exe
mcvsshld.exe
MRT.exe
NAVW32.exe
nmain.exe
SAVSCAN.EXE
SNDSrvc.exe
SymWSC.exe
TeaTimer.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer