









 |
W32/Zapchas.BD Trojan
| Name |
W32/Zapchas.BD Trojan |
| Aliases |
TROJ_ZAPCHAST.BD |
| Discovered on |
December 12, 2005 |
Virus Information - W32/Zapchas.BD Trojan:
W32/Zapchas.BD is an email worm. The worm will infect Windows systems and spreads through email.
Upon execution, the trojan copies following files in the Windows System folder.
aliases.ini
explorer.exe
control.ini
mirc.ico
nicks.txt
mirc.ini
remote.ini
servers.ini
script.ini
sup.bat
users.ini
sup.reg
The trojan modifies registry at the following location to load itself during each startup.
HKEY_LOCAL_MACHINE\Software\Microsoft\ Windows\CurrentVersion\Run
The trojan has the backdoor capabilities. It connects to the Internet Relay Chat (IRC) server. After the connection is established, it joins an IRC channel and listens for commands coming from a remote malicious user.

|