Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Dec 07, 2006 | Updated Sep 15, 2017

Trojan:IRC/WinBot

Detected by Microsoft Defender Antivirus

Aliases: Backdoor.IRC.Zapchat (Kaspersky) Troj/Zapchas-CN (Sophos) TROJ_ZAPCHAS.CN (Trend Micro)

Summary

Trojan:IRC/WinBot opens a backdoor on TCP port 113 and UDP port 30167, connects to an IRC channel, and downloads and installs other files. Trojan:IRC/WinBot also includes keylogger capabilities. Some variants of Trojan:IRC/WinBot include the Win32/Parite virus, possibly as a result of cross-infection. Win32/Parite infects portable executable files on local drives and accessible network shares.
Follow us