Sophos

Troj/IRCBot-AY

Aliases
  • Backdoor.Win32.IRCBot.kk
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 16 December 2005 03:43:27 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IRCBot-AY is a IRC backdoor Trojan for the Windows platform.

Troj/IRCBot-AY has the functionality to allow a remote intruder to gain access and control.

When run, Troj/IRCBot-AY copies itself to:

<Windows>\4DFlowerBox.scr
<Windows>\fontstyles.exe
<System>\iexplore.exe
<Windows>\webdav\bslogitech.exe

When run, Troj/IRCBot-AY sets the following registry entries:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
run
iexplore.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed

Components\(2bf41072-b2b1-21c1-b5c1-0305f4155515)
StubPath
<System>\iexplore.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ShellRun32
<System>\iexplore.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices
Shell32
<System>\iexplore.exe

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
iexplore.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe 4DFlowerBox.scr

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
<Windows>\fontstyles.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer