Threat Description

Bozori.C

Details

Aliases:Bozori.C, Backdoor.Win32.IRCBot.fb, Net-Worm.Win32.Bozori.C
Category: Malware
Type:
Platform: W32

Summary



Bozori.C is IRC-based backdoor-worm that was found on August 17th, 2005.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.

Eliminating a Local Network Outbreak

If the infection is in a local network, please follow the instructions on this webpage:



Technical Details



The backdoor provides unauthorized access to an infected computer and also has the capability to spread to remote computers using the PNP exploit (MS05-039).

This variant is functionally identical to Bozori.A but it is repacked. For more information please read the description of Bozori.A






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More