Sophos

W32/IRCBot-WA

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 May 2007 07:11:26 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/IRCBot-WA is a worm with IRC backdoor functionality for the Windows platform.

W32/IRCBot-WA runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/IRCBot-WA spreads to other network computers using AOL Instant Messenger.

When run W32/IRCBot-WA attempts to spread by sending messages to AOL with any of the following messages:

"found this on google its hilarious <URL>"

"haha this is a funny ass clip <URL>"

"this is tight, check it out <URL>"

When first run W32/IRCBot-WA copies itself to C:\limewirepro.exe. The following registry entries are created to run W32/IRCBot-WA on startup:
            
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
limewirepro.exe
C:\limewirepro.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer