W32.IRCBot

By ESGI Advisor in Backdoors

W32.IRCBot is a backdoor trojan that is typically spread via an infected email attachment. Unsuspecting users opening this attachment will find themselves immediately infected with this virus. Once active, W32.IRCBot attempts to connect to an IRC server and await commands from an unauthorized remote user, who will inevitably seek to take control of the infected computer.

File System Details

W32.IRCBot may create the following file(s):
# File Name Detections
1. updt.exe

Registry Details

W32.IRCBot may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Related Posts

Trending

Most Viewed

Loading...