View Full Version : Win32.Ircobus
Snook
September 10th, 2003, 11:13 PM
How come TDS3 does not detect Win32.Ircobus (defined a Trojan at Symantec USA)?
(Pest Patrol did find it).
Comments/suggestions?
Snook,
Licensed Operator. :) ;D
Gavin - DiamondCS
September 11th, 2003, 12:08 AM
Hi,
If you ever have a detection on something that TDS doesnt detect, please send it in for verification/analysis
I'm not sure about this one, or what possible aliases it uses ?
Jooske
September 11th, 2003, 01:05 AM
I didn't see aliases yet Gavin, see F-secure's description here (http://www.f-secure.com/v-descs/ircobus.shtml) more a mIRC script worm, not a trojan.
Pieter_Arntz
September 11th, 2003, 02:43 AM
Hi Jooske,
http://www.wilderssecurity.com/showthread.php?t=13604
From that Symantec link:
Backdoor.IRC.Aladinz.C is an IRC Trojan Horse that gives its creator full control over a compromised system. The Trojan may be downloaded by the Trojan.Downloader.Aphe from the Web site, w3.ircx-vanguard.com. The existence of the file uqir.exe is an indication of a possible infection.
Also Known As:
Worm.Win32.Ircobus [KAV], Worm.Win32.Randon.p [KAV]
Worm, Trojan, Backdoor?
Three for the price of one?
HTH,
Pieter
disabled link
Gavin - DiamondCS
September 11th, 2003, 11:27 PM
Ahh ok THOSE things ;D
GT Bots.. mIRC based script worm/backdoors.. if you have one that is not detected please do send it in for analysis. Im thinking of a generic GT Bot detector for TDS-4 which shouldn't be too hard :)
DolfTraanberg
September 12th, 2003, 11:56 AM
TDS-4.01 I hope
Dolf
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums