Troj/IRCBot-B

Category: Viruses and SpywareProtection available since:11 Apr 2003 00:00:00 (GMT)
Type: TrojanLast Updated:11 Apr 2003 00:00:00 (GMT)
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/IRCBot-B is a backdoor Trojan which allows remote access and control over the computer via IRC channels.

When first run, the Trojan moves itself to the Windows System folder as api32.exe and creates the following registry entry so that api32.exe is run automatically each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\API32
= %SYSTEM%\api32.exe