Selected viruses, spyware, and other threats: sorted alphabetically
Short description
Win32/IRCBot.AGP is an IRC controlled backdoor.
Installation
When executed, the backdoor copies itself in the %windir% folder
using the following name:
In order to be executed on every system start, the backdoor sets the following Registry entry:
winrofl32.exe (64000 B)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows UDP Control Center" = "winrofl32.exe"
The backdoor displays a fake error message:
Spreading via IM networks
The backdoor sends links to AIM (AOL Instant Messenger), AOL Triton, MSN Messenger users.
If the link is clicked
a copy of the backdoor is retrieved from the Internet.
Other information
Win32/IRCBot.AGP is an IRC controlled backdoor.
The backdoor is sent data and commands from a remote computer or the Internet.
The backdoor connects to the following address:
It can execute the following operations:
zenaz.dalnetirc.net
The backdoor may create copies of itself using the following filenames:
- download files from a remote computer and/or Internet
- update itself to a newer version
- spread via IM networks
%windir%\winrofl32.exe_ (64000 B)
