Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Please follow the instructions for removing Trojans.
More Information
Troj/IRCBot-B is a backdoor Trojan which allows remote access and control over the computer via IRC channels.
When first run, the Trojan moves itself to the Windows System folder as api32.exe and creates the following registry entry so that api32.exe is run automatically each time Windows is started:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\API32
= %SYSTEM%\api32.exe
