Sophos

Troj/Monad-A

Aliases
  • Backdoor.Win32.IRCBot.iz
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2006 (4.01)
Protection available since 20 November 2005 07:26:25 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Monad-A is a backdoor Trojan for the Windows paltform.

Troj/Monad-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When first run, Troj/Monad-A copies itself to <System>\webcam.exe, and creates the following registry entry so that it is automatically started when an infected computer starts:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<Default>
<System>\webcam.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer