Skip to main content
Skip to main content
Published Sep 14, 2007 | Updated Sep 15, 2017

Backdoor:Win32/IRCbot.OV

Detected by Microsoft Defender Antivirus

Aliases: Win32/Pushbot.P (CA) Backdoor.Win32.IRCBot.adi (Kaspersky) W32/Sdbot.worm (McAfee) Mal/Generic-A (Sophos) W32.Spybot.Worm (Symantec) WORM_AGENT.YKR (Trend Micro)

Summary

Backdoor:Win32/IRCBot.OV is a Windows Messenger worm with backdoor Trojan functionality. The worm sends message to random Messenger contacts with a link to a remote Web site hosting a copy of the worm. If IRCBot.BA is run, it connects to an IRC server and waits to receive commands, such as to self-update, remove itself, download various programs and malware, or terminate running processes.
Backdoor:Win32/IRCbot.OV may download and install additional malicious software, thus manual removal is not recommended. To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us