Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | May 2005 (3.93) |
| Protection available since | 12 March 2005 18:04:49 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/IRCBot-AA is a backdoor Trojan for the Windows platform.
When first run, Troj/IRCBot-AA copies itself to the Windows system folder as iisinfo.exe and wupdata.exe and then drops two helper files as shdocl.dll and smtp.dll. The Trojan sets the following registry entry in order to run each time a user logs on:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
UpData
"wupdata.exe"
The Trojan logs onto an Internet Relay Chat (IRC) server and joins a predetermined channel where it awaits commands from a remote user.
The Trojan can perform the following tasks:
log keypresses
report filesystem and hardware information
send email
The Trojan may set additional registry entries under:
HKLM\Software\Microsoft\mmbestbot
