Antivirus and Security Software from Sophos

Sophos blogs

Troj/Zapchas-DN

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 19 July 2007 12:37:26 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Zapchas-DN is a mIRC-based backdoor Trojan for the Windows platform.

When first run, Troj/Zapchas-DN creates the following files in <System>\ShellExt:

greet.ini
aliases.ini
away.txt
channels.txt
conn.ini
control.ini
czvhost.exe
engine.ini
flood.txt
fullname.txt
add.txt
ident.txt
injuraturi.txt
IRC.ICO
kick.txt
mirc.ini
nick.txt
operator.ini
partmsg.ini
perform.ini
remote.ini
scr.ini
servers.ini
updater.ini

czvhost.exe is the legitimate mIRC IRC application. operator.ini and scr.ini are also detected as Troj/Zapchas-DN. The remaining files are harmless and can be deleted safely.

Troj/Zapchas-DN allows a remote user to control the infected computer via IRC channels.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer