Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2008 (4.31) |
| Protection available since | 16 May 2008 18:23:25 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Zapchas-EA is a backdoor IRC Trojan.
Troj/Zapchas-EA drops the following files:
<Windows>\system\script.ini
<Windows>\system\svchost.exe
The file script.ini is detected as Troj/Zapchas-EA. The file svchost.exe is the mIRC application executable. The following files are also dropped and are harmless data files mostly associated with mIRC:
<Windows>\system\aliases.ini
<Windows>\system\control.ini
<Windows>\system\fullname.txt
<Windows>\system\heart.jpg
<Windows>\system\ident.txt
<Windows>\system\mirc.ico
<Windows>\system\mirc.ini
<Windows>\system\nicks.txt
<Windows>\system\remote.ini
<Windows>\system\servers.ini
<Windows>\system\sup.bat
<Windows>\system\sup.reg
<Windows>\system\users.ini
When run Troj/Zapchas-EA installs itself in the registry at the following location so that it autoruns at startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
GNP Generic Host Process
<Windows>\system\svchost.exe
