Sophos

Troj/Digarix-D

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 1 October 2005 15:54:09 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Digarix-D is an IRC backdoor Trojan.

The Trojan usually arrives as a self extracting EXE archive that drops several files, the majority of which are legitimate utilities.

The file CODER.SUS contains most of the functionality of the Trojan.

Troj/Digarix-D uses a standard mIRC client to connect to a remote IRC server and listen for the commands from the Trojan writer.

The Trojan may create the following registry value:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NTupdater
to point to the renamed mIRC client.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer