Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | September 2007 (4.21) |
| Protection available since | 9 August 2007 11:10:46 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/IRCBot-XF is a worm for the Windows platform.
W32/IRCBot-XF contains functionality to spread via MSN Messenger.
W32/IRCBot-XF runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/IRCBot-XF is installed the following files are created:
<User>\new.txt - May be safely deleted.
<Windows>\pictures07-01.zip - Also detected as W32/IRCBot-XF.
<System>\systesrt32.dll - Also detected as W32/IRCBot-XF.
The file systesrt32.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\{478DFE97-ED1E-47E4-8BFC-8F09F9F89812
The following registry entry is created to run systesrt32.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
syshelps
{478DFE97-ED1E-47E4-8BFC-8F09F9F89812}
