Sophos

Troj/Zapchas-AC

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2006 (4.11)
Protection available since 6 December 2005 18:10:05 (GMT)
Last updated 5 October 2006 13:10:24 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Zapchas-AC is a Trojan for the Windows platform.

Troj/Zapchas-AC runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

When Troj/Zapchas-AC is installed the following files are created:

<System>\aliases.ini
<System>\control.ini
<System>\explorer.exe
<System>\mirc.ico
<System>\mirc.ini
<System>\nicks.txt
<System>\postcard.gif.exe
<System>\remote.ini
<System>\script.ini
<System>\servers.ini
<System>\sup.bat
<System>\sup.reg
<System>\users.ini

The files script.ini and postcard.gif.exe are also detected as Troj/Zapchas-AC. The file svchost.exe is a version of the mIRC chat application. The other files are not inherently dangerous but may be safely deleted.

The following registry entries may be created in order to start the mIRC chat application when an infected system starts:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
taskmgr
<System>\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IExplorer
<System>\explorer.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer