Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | May 2007 (4.17) |
| Protection available since | 27 March 2007 09:30:57 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/IrcWorm-A is an IRC worm for the Windows platform.
When W32/IrcWorm-A is installed the following files are created:
<Windows>\photo album.zip
<System>\rdfhost.dll
The worm will then attempt to connect to an IRC channel and begin sending messages enticing other users to accept the file transfer of zip file.
The following registry entry is created to run code exported by {5344BB88-3DE1-409F-8307-C85923A1F4DD} on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
rdshost
{5344BB88-3DE1-409F-8307-C85923A1F4DD}
The file rdfhost.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\{5344BB88-3DE1-409F-8307-C85923A1F4DD}
