W32/IRCBot.BHW.Backdoor is a Trojan that will infect Windows systems.

Upon execution, it drops ctuqhg.exe in Windows System folder.

The Trojan modifies registry at the following location to load itself during each startup:


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ctuqhg It registers ctuqhg.exe as "Print Spooler Service."

More information can be found at this Proland Software page.