Know Your Malware; Ixbot Removal

Ixbot is an Internet worm, which spreads through instant messages sent using AIM, AOL Triton or MSN Messenger programs. Such messages contain a certain text and a malicious link pointing to an infected file. Once the user clicks on a link, the worm silently installs itself to the system and runs a spreading routine. The worm includes an integrated IRC-controlled backdoor, which provides the attacker with unauthorized remote access to a compromised computer. The intruder can download and execute arbitrary files. Ixbot creates a lot of infected files with meaningful names in several shared folders found in the system. It also terminates some antivirus programs and prevents them from running on system startup. Ixbot runs every time Windows loads.

Ixbot properties:
Allows remote user connection
Connects itself to the internet
Hides from the user
Stays resident in background
Remove Ixbot, removal instructions

Linked by shanmuga Monday, 12th December 2005 9:31PM