Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2007 (4.22) |
| Protection available since | 24 August 2007 12:35:31 (GMT) |
| Cleanup available since | August 2007 |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/IRCBot-XN is an IRC backdoor worm for the Windows platform.
When first run W32/IRCBot-XN copies itself to <System>\msnfix.exe and creates the file <System>\syspoints.dll.
The following registry entry is created to run code exported by {1002A855-3682-4FB3-B0FC-677B30CFEED5} on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Version1
{1002A855-3682-4FB3-B0FC-677B30CFEED5}
The file syspoints.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\{1002A855-3682-4FB3-B0FC-677B30CFEED5}
