Re: irc backdoor trojan



From: "KRK" <trebor@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx>

| Hello,

| I have had a message from Norton (on 3 recent occasions) reporting that it
| has blocked an attack by the irc.backdoor.trojan.

| At the same time I found my irc software (Mirc 6.16) suddenly stopped
| working, the exe file disappeared. (I have managed to get it going again by
| re-installing)

| I have googled this virus, it seems to be very old ?? circa 2006 ?

| Has there been a new version developed. ?

| Any advice / info warmly welcomed

| Thanks

| KK


The name "irc.backdoor.trojan" is a generic name so there can be many variants.

Additionally the name implies it is a trojan and not a virus and 2006 is NOT "very old".
In this case consider this dectection to be part of a family and thus the date means
little.

The question then is what is the file(s) that were deemed infected. Suppliying a sample
to Virus Total may gleem more specific information on this trojan.

As for new versions... sure. New variants in a family are always being created and/or
derived and that's why you have a generic detection name.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


.



Relevant Pages

  • Re: AVG update 03/12/2008 (270.9.13/1827) 2nd today
    ... Added detection of new variants of trojans Generic12.UBE, ... I also have Spybot S & D Teatimer and Trojan Hunter Trojan guard running ... used was one that is in the XP software butd not W98. ... say I changed all my passwords just in case. ...
    (uk.telecom.broadband)
  • Re: W32/IRCbot.gen.b makes svchost.exe crash on remote (uninfected) computers
    ... Symantec told us that so many variants of Fake AV are created every ... fall under family names or generic detection names. ... So it is a Win32 type, of the family IRCBot, of the GENERIC class of variant B ...
    (microsoft.public.security.virus)
  • Re: new fast-spreading trojan
    ... | phil typed: ... >> Hi .got a warning this morning from a friend, for a new fast spreading ... In fact, I had got an email earlier, with the trojan ... Basically about new variants of the Bagle/Mitgleider being mass mailed. ...
    (microsoft.public.security.virus)
  • Re: Dump The System
    ... "Backdoor.Trojan is a generic detection for a group of Backdoor Trojan ... machine as per normal and see if the error message comes up again. ...
    (microsoft.public.windowsxp.basics)
  • Re: windows cannot find ? C:/program files/
    ... This will insure that the Trojan's DLL and other variants aren't present as well as correct ... the Registry setting calling this Trojan and generating the "windows cannot find...." ...
    (microsoft.public.windowsxp.help_and_support)