Sophos

W32/IRCBot-ADA

Aliases
  • Backdoor.Win32.IRCBot.eyk
  • W32/Sdbot.worm
  • Worm:Win32/Pushbot.IF
  • W32.SillyIM
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2009 (4.37)
Protection available since 22 November 2008 05:32:32 (GMT)
Detected by All Sophos products

Action

More Information

W32/IRCBot-ADA is a worm for the Windows platform that attempts to spread via MSN Messenger.

When first run W32/IRCBot-ADA copies itself to <Windows>\isys32.exe.

The following registry entry is created to run isys32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internet Explorer Sys32
isys32.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer