Sophos

Troj/Zapchas-EA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 16 May 2008 18:23:25 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Zapchas-EA is a backdoor IRC Trojan.

Troj/Zapchas-EA drops the following files:

<Windows>\system\script.ini
<Windows>\system\svchost.exe

The file script.ini is detected as Troj/Zapchas-EA. The file svchost.exe is the mIRC application executable. The following files are also dropped and are harmless data files mostly associated with mIRC:

<Windows>\system\aliases.ini
<Windows>\system\control.ini
<Windows>\system\fullname.txt
<Windows>\system\heart.jpg
<Windows>\system\ident.txt
<Windows>\system\mirc.ico
<Windows>\system\mirc.ini
<Windows>\system\nicks.txt
<Windows>\system\remote.ini
<Windows>\system\servers.ini
<Windows>\system\sup.bat
<Windows>\system\sup.reg
<Windows>\system\users.ini

When run Troj/Zapchas-EA installs itself in the registry at the following location so that it autoruns at startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
GNP Generic Host Process
<Windows>\system\svchost.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer