Sophos

W32/IRCBot-XF

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2007 (4.21)
Protection available since 9 August 2007 11:10:46 (GMT)
Detected by All Sophos products

Action

More Information

W32/IRCBot-XF is a worm for the Windows platform.

W32/IRCBot-XF contains functionality to spread via MSN Messenger.

W32/IRCBot-XF runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/IRCBot-XF is installed the following files are created:

<User>\new.txt - May be safely deleted.
<Windows>\pictures07-01.zip - Also detected as W32/IRCBot-XF.
<System>\systesrt32.dll - Also detected as W32/IRCBot-XF.

The file systesrt32.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\{478DFE97-ED1E-47E4-8BFC-8F09F9F89812

The following registry entry is created to run systesrt32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
syshelps
{478DFE97-ED1E-47E4-8BFC-8F09F9F89812}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer