Home Malware Programs Worms W32/IRCbot.gen.d

W32/IRCbot.gen.d

Posted: October 3, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 40
First Seen: October 3, 2011
Last Seen: February 10, 2022
OS(es) Affected: Windows

W32/IRCbot.gen.d is a malicious worm that spreads by sending spam emails with an attachment of its copy, which might be named "photos.zip". Once the malicious zip file is opened, W32/IRCbot.gen.d installs itself on a compromised machine. "photos.zip" is a bogus zip file because no program is needed to open it. The spam email including a copy of W32/IRCbot.gen.d spreads by sending a message with a body typical for such type of mass-circulation messages. W32/IRCbot.gen.d also creates a file called "Windows Genuine Advantage Validation Notification", and its name is used to bypass possible W32/IRCbot.gen.d removal tool. W32/IRCbot.gen.d also uses an Internet Relay Chat (IRC) vulnerability to allow attackers remotely monitor the infected computer. Uninstall W32/IRCbot.gen.d before it harms your PC system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%FontsDir%\java.exe File name: %FontsDir%\java.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%System%\LNKnell.exe File name: %System%\LNKnell.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Windows Update = "%FontsDir%\java.exe"
Loading...