Daily Virus Report (Aug 24, 2008) - Backdoor.Win32.IRCbot.dtd
-
RISING
Aug 24, 2008 one virus needs your attention. It is DTD (Backdoor.Win32.IRCbot. dtd). The virus is a backdoor program via IRC, and hackers can control the infected computer via IRC, and attack other computers.
Name: DTD (Backdoor.Win32.IRCbot. dtd)
Warning level: Dangerous
Category: Backdoor
Affected System: Windows NT/2000/XP/2003
Description:
This is a Backdoor virus and spreads through Internet. After startup, the virus will be copied down to driver directory by own, named itself as “wmiadapi.exe”; adds “AutoDiscovery/AutoPurge (ADAP) Service” to registry, to achieve startup with system. In addition, the virus will set a backdoor at infected computers, and automatically connect with cftp.dawn****.info for remote instruction. Hackers can control infected computer via IRC, and take malicious action through Internet. It is a big threat to computer security safe. Also, the virus can modify registry key to disrupt some normal web function.
Anti-virus experts suggest that computer users take the following measures to protect against this virus:
1. Install Rising Anti-virus, personal firewall, update in time, and at least 3 times per day for updating Rising.
2. Use Rising Vulnerability Check, patch your computer system in a timely manner as many viruses spread by taking advantage of the system exploits or vulnerabilities.
3. Do not browse suspicious websites, and suspicious inserter; turn off or delete unnecessary system services.
4. Do not receive the suspicious file from QQ, MSN, Email, etc.
5. Open auto-protect and auto-monitor function when accessing to the internet.
6. Put your account information of networks bank, networks game, MSN, QQ, Yahoo Messenger etc, into Rising Application Protection, Rising Application Protection can protect specified applications from attack by malicious programs. A user can apply rules to game software, instant messenger, etc. to customize protection.