W32/IRCBot-ADS is a worm with a backdoor component that spreads via weakly protected network shares and the IRC network.
In order to run automatically when Windows boots up the worm copies itself to the Windows system folder as the file wmisys.exe and creates several registry entry(s).
More information can be found at this Sophos page.
Loading Comments...