Sophos

Troj/IRCBot-HH

Aliases
  • Generic
  • BackDoor.k
  • Backdoor.Win32.VB.asg
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 20 April 2006 04:59:31 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/IRCBot-HH is an IRC backdoor Trojan for the Windows platform.

When Troj/IRCBot-HH is installed the following files are created:

<System>\Mswinsck.ocx - this file can be safely deleted
<System>\fedisk.com - also detected as Troj/IRCBot-HH
<System>\mccm.exe - also detected as Troj/IRCBot-HH

The following registry entries are set to run the Trojan on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FixError
<System>\fedisk.com

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Winammp
<System>\mccm.exe

Registry entries are created under:

HKCR\MSWinsock.Winsock\
HKCR\MSWinsock.Winsock.1\

The file <System>\Mswinsck.ocx is also registered as a COM object creating registry entries under:

HKCR\(248DD896-BB45-11CF-9ABC-0080C7E7B78D)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer