Sophos

Troj/IRCBot-FP

Aliases
  • Backdoor.Win32.IRCBot.nw
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from May 2006 (4.05)
Protection available since 14 March 2006 04:54:14 (GMT)
Detected by All Sophos products

Action

More Information

Troj/IRCBot-FP is a backdoor Trojan for the Windows platform.

Troj/IRCBot-FP has the functionalities to:

- disable Anti-Virus applications
- access the internet and communicate with a remote server via HTTP
- allow unauthorized access to the infected computer via IRC
- hide processes Troj/IRCBot-FP is a backdoor Trojan for the Windows platform.

Troj/IRCBot-FP has the functionalities to:

- disable Anti-Virus applications
- access the internet and communicate with a remote server via HTTP
- allow unauthorized access to the infected computer via IRC
- hide processes

When run Troj/IRCBot-FP copies itself to <System>\smss.exe and creates the following files:

<System>\netf.dll
<System>\nvsvcd.exe

The file netf.dll and nvsvcd.exe is detected as Troj/IRCBot-FP.

Troj/IRCBot-FP sets the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
.nvsvc
<System>\smss.exe /w

Troj/IRCBot-FP creates a service named "Windows Log" and sets registry entries under:

HKLM\System\CurrentControlSet\Services\Windows Log

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer