Home Malware Programs Backdoors W32.IRCBot

W32.IRCBot

Posted: July 16, 2009

W32.IRCBot is a backdoor trojan that attempts to connect to an IRC server and await commands from the cybercriminal who initiated the original attack. This trojan is typically spread via infected email attachment.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 updt.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ RunServicesHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Related Posts

Loading...