Backdoor.Win32.IRCBot is a backdoor computer worm that spreads through MSN Messenger and Windows Live Messenger. Once installed on a PC the worm copies itself into a Windows system folder, creates a new file displayed as "Windows Genuine Advantage Validation Notification" and becomes part of the computer's automatic startup. In addition, it attempts to send itself to all of the user's MSN contacts via and attachment named 'photos.zip'. Executing this file will install the worm onto the local PC. The Win32.IRCBot worm provides a backdoor server and allows a remote intruder to gain access and control over the computer via an Internet Relay Chat channel. This allows for confidential information to be transmitted to a hacker. Because of a lack of standard naming conventions and also because of
Attributes | Values |
---|---|
rdfs:label |
|
rdfs:comment |
|
dcterms:subject | |
dbkwik:malware/pro...iPageUsesTemplate | |
abstract |
|