Sophos

W32/IRCBot-XG

Aliases
  • Backdoor.Win32.IRCBot.acd
  • W32/IRCbot.worm.gen
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 9 August 2007 19:09:24 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/IRCBot-XG is a worm for the Windows platform.

W32/IRCBot-XG includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/IRCBot-XG copies itself to <System>\msninet.exe and creates the following files:

<User>\aria.txt
<System>\libmsns.dll

The following registry entry is created to run code exported by {BED56B71-F844-4A27-82A5-56AF62D49FF4} on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
printers
{BED56B71-F844-4A27-82A5-56AF62D49FF4}

The file libmsns.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\{BED56B71-F844-4A27-82A5-56AF62D49FF4}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer