Summary

Summary
Action
More Information
| Protection available since | 30 June 2004 09:18:35 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Psybot-A is an IRC backdoor Trojan and network worm which establishes
an IRC channel to a remote server in order to grant an intruder access to the compromised machine.
This worm may create the following registry entries so that it can execute
automatically on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Windows DLL host = "<full file path>"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Windows DLL host = "<full file path>"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Windows DLL host = "<full file path>"
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices\
Windows DLL host = "<full file path>"
W32/Psybot-A may replace or append some data to the HOSTS and SERVICES
files in the C:\<Windows system>\Drivers\etc\ folder.
