Threat Database Worms W32/IRCbot.gen.d

W32/IRCbot.gen.d

By SpideyMan in Worms

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 17
First Seen: October 3, 2011
Last Seen: February 10, 2022
OS(es) Affected: Windows

W32/IRCbot.gen.d is a malignant network-aware worm that uses known exploits in order to copy itself across vulnerable networks. W32/IRCbot.gen.d can also replicate through spam email messages, network shares and IRC channels to other computers. Once executed, W32/IRCbot.gen.d can connect to an IRC channel and listen for instructions from attackers to remotely monitor the affected PC. Then, W32/IRCbot.gen.d can update itself or replicate to other IRC channels. W32/IRCbot.gen.d can download and install some files and additional malware threats. W32/IRCbot.gen.d can also execute Denial of Service (DoS) attacks against a corrupted machine. To protect your computer from damage, remove W32/IRCbot.gen.d as soon as possible.

File System Details

W32/IRCbot.gen.d may create the following file(s):
# File Name Detections
1. %System%\LNKnell.exe
2. %FontsDir%\java.exe

Registry Details

W32/IRCbot.gen.d may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Windows Update = "%FontsDir%\java.exe"

Trending

Most Viewed

Loading...