Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2007 (4.20) |
| Protection available since | 1 July 2007 22:49:55 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/IRCBot-WV is a worm for the Windows platform that also includes backdoor functionality.
W32/IRCBot-WV is a worm for the Windows platform that also includes backdoor functionality.W32/IRCBot-WV includes functionality to access the internet and communicate with a remote server via HTTP.
When W32/IRCBot-WV is installed the following files are created:
<User>\new.txt
<Windows>\myalbum2007.zip
<System>\sysprinters.dll
The following registry entry is created to run code exported by B0F684D7-B19D-47B2-BD49-F77F13EB482A on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
system32
B0F684D7-B19D-47B2-BD49-F77F13EB482A
The file sysprinters.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\B0F684D7-B19D-47B2-BD49-F77F13EB482A
