Threat Description

Riskware:​W32/mIRC

Details

Aliases: Client-irc.win32.mirc
Category: Riskware
Type: Riskware
Platform: W32

Summary


Useful, legitimate software which could possibly be misused for malicious purposes.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.



Technical Details


Riskware:W32/mIRC is an Internet Relay Chat (IRC) client that can be silently subverted by malware to become a backdoor. By itself, the program is not malicious.

Activity

Malware such asBackdoor:W32/Zapchast and its variants can use malicious configuration files to turn the mIRC-client into a backdoor. The malicious configuration files are detected as Backdoor.IRC.Zapchast.

In addition to subverting the mIRC client, these files will also contain the name of an IRC channel which the mIRC-client will automatically try to join on each startup.

Sometimes, Zapchast variants will use additional batch files which provide added functionality, such as performing registry changes to create a launchpoint for the backdoor. These auxiliary batch files are detected as Trojan.BAT.Zapchast.



SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More