backdoor.ircbot.ayi


Avast free edition did not found this virus into the system: Backdoor.ircbot.ayi

Tecnical information:

Copies itself as usnserv.exe in the Windows System folder.
Drops the file NewYear2008.ZIP in the %Temp% folder.
This .zip contains the file Image027.JPEG_VirusScannedBy-Msn.com, which is a copy of the backdoor.
Adds the value
“Userfile Sharing Server” = usnserv.exe

under the key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

in the Windows registry to hook system startup.

May connect to a specific IRC channel on a certain IRC server to await remote commands.

Please update avast.
Regards.

Have you sent the related file to Avast ?