Sophos

Troj/Wisdoor-K

Aliases
  • BackDoor-AOZ
  • Backdoor.Wisdoor.k
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 16 September 2004 18:56:29 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Wisdoor-K is a backdoor Trojan which allows a remote intruder to access and control the computer via IRC channels.

When first run Troj/Wisdoor-K copies itself to the Windows folder as syscfg16.exe and creates the following registry entries, so that syscfg16.exe is run automatically on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows System Configuration = "<Windows folder>\SYSCFG16.EXE"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows DLL Loader = "<Windows folder>\SYSCFG16.EXE"

Each time the Trojan is run it tries to connect to a remote IRC server on port 6667 using a random nickname and join a specific channel. The Trojan then listens on the channel for instructions specified by a remote intruder.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer