TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
BKDR_IRCBOT.BGY
Overview

Malware type: Backdoor

Aliases: Backdoor.Win32.IRCBot.djh (Kaspersky),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

Low

Description: 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

BKDR_IRCBOT.BGY Behavior Diagram

Malware Overview

This backdoor may be dropped by other malware. It may be downloaded from remote site(s) by other malware. It may be downloaded unknowingly by a user when visiting malicious Web site(s).

It drops copy(ies) of itself.

Upon execution, it displays a fake message box to trick users into thinking that the malware did not execute.

It creates registry entry(ies) to enable its automatic execution at every system startup.

It opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes certain commands on the affected system. This routine effectively compromises the affected system.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 7, 2008 1:57:54 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.