Posted 20 May 2005 - 06:25 PM
Description: Added by the W32/Tirbot-E worm. This infection sits on an IRC channel and typically can harvest information from the system registry, perform denial of service (DDoS) attacks, serve as a proxy server, upload/download and execute files, report file system information, detect security software or list processes upon command.
File Location: %System%
Startup Type: This startup entry is started automatically from a Run, RunOnce, RunServices, or RunServicesOnce entry in the registry.
Note: %System% is a variable that refers to the Windows System folder. By default this is C:\Windows\System for Windows 95/98/ME, C:\Winnt\System32 for Windows NT/2000, or C:\Windows\System32 for Windows XP.
Removal Instructions: How to remove a Trojan, Virus, Worm, or other Malware
Spike's advice: Backup your data routinely.