Sophos

W32/IRCBot-ABK

Aliases
  • Backdoor.Win32.IRCBot.clk
  • Worm/IrcBot.39424.17
  • Worm:Win32/Pushbot.CY
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 14 April 2008 07:06:20 (GMT)
Detected by All Sophos products

Action

More Information

W32/IRCBot-ABK is a worm and IRC backdoor Trojan for the Windows platform.

When run W32/IRCBot-ABK copies itself to <Current Folder>\msn.com and <Windows>\msn.com and sets the following registry entry to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows live Messenger
msn.com

W32/IRCBot-ABK spreads via network shares and MSN Messenger and includes functionality to:
- download code from the internet
- steal information

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer