Sophos

Troj/IRCBot-AA

Aliases
  • Backdoor.Win32.Agent.ic
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from May 2005 (3.93)
Protection available since 12 March 2005 18:04:49 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IRCBot-AA is a backdoor Trojan for the Windows platform.

When first run, Troj/IRCBot-AA copies itself to the Windows system folder as iisinfo.exe and wupdata.exe and then drops two helper files as shdocl.dll and smtp.dll. The Trojan sets the following registry entry in order to run each time a user logs on:

HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
UpData
"wupdata.exe"

The Trojan logs onto an Internet Relay Chat (IRC) server and joins a predetermined channel where it awaits commands from a remote user.

The Trojan can perform the following tasks:

log keypresses
report filesystem and hardware information
send email

The Trojan may set additional registry entries under:

HKLM\Software\Microsoft\mmbestbot

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer