Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 14 April 2008 07:06:20 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/IRCBot-ABK is a worm and IRC backdoor Trojan for the Windows platform.
When run W32/IRCBot-ABK copies itself to <Current Folder>\msn.com and <Windows>\msn.com and sets the following registry entry to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows live Messenger
msn.com
W32/IRCBot-ABK spreads via network shares and MSN Messenger and includes functionality to:
- download code from the internet
- steal information
