Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2007 (4.19) |
| Protection available since | 28 May 2007 07:11:26 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/IRCBot-WA is a worm with IRC backdoor functionality for the Windows platform.
W32/IRCBot-WA runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/IRCBot-WA spreads to other network computers using AOL Instant Messenger.
When run W32/IRCBot-WA attempts to spread by sending messages to AOL with any of the following messages:
"found this on google its hilarious <URL>"
"haha this is a funny ass clip <URL>"
"this is tight, check it out <URL>"
When first run W32/IRCBot-WA copies itself to C:\limewirepro.exe. The following registry entries are created to run W32/IRCBot-WA on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
limewirepro.exe
C:\limewirepro.exe
