This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
|
Minimum DAT
4245 (2003-01-29) Updated DAT4401 (2004-10-27) |
Minimum Engine
5.1.00 File Length48,448 bytes |
Description Added
2003-01-27 Description Modified2003-01-29 |
The main executable, WIN32LOAD.EXE, is an IRC Bot trojan and downloader. When run, it copies itself to the WINDOWS SYSTEM (%SysDir%) directory and creates a registry run keys to load itself at startup:
When an active Internet connection is found, the trojan downloads a plugin file, lcp_netbios.dll. This plugin contains the PSEXEC utility and a batch file containing the instructions to connect to remote systems and PSEXEC commands, which are used to carry out the infection. The trojan also connect to a hardcoded IRC channel for the purpose of "broadcasting" the infected user's system information: CPU, IP, hostname, total memory, memory available, OS version, uptime, system variables, etc. It listens for instructions, such as download/execute locations and UDP and SYN flood attack targets An additional registry key is created:
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).