Skip to main content
Skip to main content
Published Aug 27, 2007 | Updated Apr 16, 2011

Backdoor:Win32/IRCbot!5320

Detected by Microsoft Defender Antivirus

Aliases: Win32/Checkout.G (CA) Backdoor.Win32.IRCBot.acu (Kaspersky) W32/Nirbot.worm (McAfee) Backdoor:Win32/IRCBot.OU (Microsoft) W32/IRCBot.VUO (Norman) Troj/Agent.FZN (Sophos) W32.Mubla.B (Symantec) TROJ_AGENT.XSL (Trend Micro)

Summary

Backdoor:Win32/IRCBot!5320 is a backdoor Trojans that targets computers running Microsoft Windows. The Trojan drops other malicious software and opens a backdoor on the infected computer to connect to IRC servers. The Trojan can maintain multiple IRC server connections simultaneously to receive commands from attackers.
 
Backdoor:Win32/IRCBot!5320 may be detected as Backdoor:Win32/IRCbot.OU.
Backdoor:Win32/IRCBot!5320 may download and install additional malicious software, thus manual removal is not recommended. To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us